CLOUD SECURITY & CYBERSECURITY

Finding signal in the telemetry.

I secure and defend Microsoft cloud environments Azure, Defender XDR, and Sentinel! And write up what actually works in the field. This is where those notes live.

featured

Detection-as-CodeMicrosoft SentinelDefender XDR

Detection-as-Code for Microsoft Sentinel and Defender XDR: A Technical Deep Dive

Microsoft's July 2026 Preview lets you manage Defender XDR custom detections as code — through the Microsoft Security Bicep extension, Microsoft.Security/detectionRules, and Sentinel Repositories. A technical walkthrough from KQL research to a deployable Bicep detection, validation, match-volume tuning, and CI/CD deployment.

Read the post →

browse by topic

All topics →

what i work on

CLOUD

Cloud Security

Hardening identity, access, and posture across Microsoft Azure and Entra ID.

SIEM

Microsoft Sentinel

Detection engineering, KQL, and connectors that turn raw logs into usable signal.

XDR

Defender XDR

Endpoint and identity coverage, RBAC models, and multi-tenant onboarding done right.

DEVSECOPS

DevSecOps

Baking security into infrastructure, pipelines, and the way things get built.

IR

Incident Response

Triage, hunting, and containment that hold up under a live incident.

COMM

Community & Writing

Sharing knowledge and hard-won experience so the next person moves faster.

latest writing

All posts →