Session

You Are Not Prepared: The SQL Server Audit Trail That Goes Nowhere

SQL Server produces thousands of security-relevant events every day: login failures, permission grants, schema changes, privilege escalations, unusual query patterns. Almost none of it reaches the SOC. Security teams assume database teams have the threat covered. Database teams assume the SOC doesn't need the data. The result is a blind spot positioned directly in front of your most sensitive information, and while nobody's watching the threat meter, the boss is already in the room.

This session pulls you out of the fire. We cover what SQL Server actually produces and what's worth collecting; SQL Server Audit, Extended Events, login telemetry, and Agent history each serve a different purpose. From there: structuring data for fast investigation, forwarding it to Azure Monitor, Sentinel, or any syslog-compatible SIEM, and designing alerts that surface real threats without overwhelming the SOC.
The irony is that WoW raiders obsess over log parsers to optimise every raid... Your security team should be doing exactly the same thing.

Danny de Haan

Database Security & Infrastructure Advocate || Solutions Engineer @ Redgate

Roermond, The Netherlands

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top