Cloud Security
Hardening identity, access, and posture across Microsoft Azure and Entra ID.
CLOUD SECURITY & CYBERSECURITY
I secure and defend Microsoft cloud environments Azure, Defender XDR, and Sentinel! And write up what actually works in the field. This is where those notes live.
featured
Microsoft's July 2026 Preview lets you manage Defender XDR custom detections as code — through the Microsoft Security Bicep extension, Microsoft.Security/detectionRules, and Sentinel Repositories. A technical walkthrough from KQL research to a deployable Bicep detection, validation, match-volume tuning, and CI/CD deployment.
Read the post →browse by topic
All topics →what i work on
Hardening identity, access, and posture across Microsoft Azure and Entra ID.
Detection engineering, KQL, and connectors that turn raw logs into usable signal.
Endpoint and identity coverage, RBAC models, and multi-tenant onboarding done right.
Baking security into infrastructure, pipelines, and the way things get built.
Triage, hunting, and containment that hold up under a live incident.
Sharing knowledge and hard-won experience so the next person moves faster.
latest writing
All posts →A CCF-authoring deep-dive: ingestion-time transform design quietly decides what your detections — and now your AI readers — actually see. What a transform really does to attacker-controlled text, the restricted-KQL gotchas that bite, and a non-destructive trust-tagging pattern you can adopt today.
Microsoft's Project Perception coordinates red, blue, and green AI agents on a new cyber stack powered by MAI-Cyber-1-Flash. What shipped in the public preview, what's gated behind human approval, how the architecture fits together, and the questions worth testing before you rely on it.
Part 2 of a defensive-research series: once a planted instruction reaches an AI SOC-triage assistant, how often does it obey? Measured across two models and four defence conditions — with the finding that instructing the reader beats fancy ingestion tags, and that tags can backfire on cheap models.
A defensive-research experiment: if an attacker hides an instruction inside a log field, does it survive a real Microsoft Sentinel ingestion pipeline all the way to where an AI assistant would read it? The answer — and why the connector's transform is the real control surface.