the archive
All Posts
Detections, teardowns, and onboarding notes from securing Microsoft cloud environments in production. No fluff — the stuff I wish someone had written down first.
Detection-as-Code for Microsoft Sentinel and Defender XDR: A Technical Deep Dive
Microsoft's July 2026 Preview lets you manage Defender XDR custom detections as code — through the Microsoft Security Bicep extension, Microsoft.Security/detectionRules, and Sentinel Repositories. A technical walkthrough from KQL research to a deployable Bicep detection, validation, match-volume tuning, and CI/CD deployment.
What your DCR transform actually does to untrusted data (and why it matters now)
A CCF-authoring deep-dive: ingestion-time transform design quietly decides what your detections — and now your AI readers — actually see. What a transform really does to attacker-controlled text, the restricted-KQL gotchas that bite, and a non-destructive trust-tagging pattern you can adopt today.
Project Perception: Microsoft's agentic security moves from alerting to acting
Microsoft's Project Perception coordinates red, blue, and green AI agents on a new cyber stack powered by MAI-Cyber-1-Flash. What shipped in the public preview, what's gated behind human approval, how the architecture fits together, and the questions worth testing before you rely on it.
Once a prompt injection reaches the AI, does it obey? I tested that too
Part 2 of a defensive-research series: once a planted instruction reaches an AI SOC-triage assistant, how often does it obey? Measured across two models and four defence conditions — with the finding that instructing the reader beats fancy ingestion tags, and that tags can backfire on cheap models.
Do prompt injections survive the Microsoft Sentinel pipeline? I measured it.
A defensive-research experiment: if an attacker hides an instruction inside a log field, does it survive a real Microsoft Sentinel ingestion pipeline all the way to where an AI assistant would read it? The answer — and why the connector's transform is the real control surface.
Campaign-Centric Hunting with Microsoft Defender XDR and Microsoft Sentinel
Moving from a single suspicious email to full campaign impact — using Defender for Office 365 Campaign Views and the CampaignInfo table with EmailEvents, UrlClickEvents, and post-delivery data to see who was targeted, who clicked, and what to prioritize.
Operational Notes on Microsoft Security Copilot Agents in Defender XDR and Microsoft Entra ID
Practical SOC observations on Security Copilot agents — how they're deployed, how they consume Security Compute Units, the agentic identities and Unified RBAC roles they create, where to monitor usage, and KQL for reviewing agent activity.
Identity Attack Graph in Microsoft Sentinel
How Sentinel's Identity Attack Graph exposes hidden access paths between identities, permissions, groups, and Azure resources — use cases, onboarding prerequisites (including the Azure Resource Graph connector), and how graph-based investigation complements KQL.
Microsoft Sentinel MCP Entity Analyzer: Explainable Risk Analysis for URLs and Identities
How Sentinel's Entity Analyzer changes the enrichment and triage model — a single explainable verdict for URLs and identities via the Sentinel MCP tools, with the prerequisites, concurrency limits, cost model, and rollout pattern that make it work in production.
What's New in Microsoft Sentinel and XDR: AI Automation, Data Lake Innovation, and Unified SecOps
The engineering shift to unified security operations in the Defender portal — Azure portal sunset timeline, the AI playbook generator, CCF Push, data lake tier ingestion, and the migration implications that actually change how you build detections.
Endpoint and EDR Ecosystem Connectors in Microsoft Sentinel
An engineering-first approach to multi-EDR SOCs — ingesting Cisco Secure Endpoint, WithSecure, Samsung Knox, and Lookout into Microsoft Sentinel, then normalizing, correlating, and orchestrating response across vendors.
Threat Intelligence & Identity Ecosystem Connectors in Microsoft Sentinel
Integrating third-party threat-intel feeds (GreyNoise, Team Cymru) with identity logs (OneLogin, PingOne, Keeper) in Microsoft Sentinel — enrichment pipelines, false-positive reduction, and MITRE-mapped detection rules.
SAP & Business-Critical App Security Connectors in Microsoft Sentinel
Making SAP and SAP-adjacent security signals operational in a SOC — reliable ingestion, stable schemas, a normalization layer, and detections for ABAP privilege abuse that survive latency and schema drift.
Integrating Proofpoint and Mimecast Email Security with Microsoft Sentinel
Ingesting Proofpoint POD/TAP and Mimecast Secure Email Gateway telemetry into Microsoft Sentinel, and correlating it with identity, endpoint, and threat-intel signals for end-to-end phishing detection.
Cloud Posture + Attack Surface Signals in Microsoft Sentinel (Prisma Cloud + Cortex Xpanse)
Bringing Palo Alto Prisma Cloud (CSPM/CWPP) and Cortex Xpanse exposure signals into Microsoft Sentinel, plus the KQL correlation recipes that turn posture and attack-surface data into prioritized incidents.
Ingesting Google Cloud Logs into Microsoft Sentinel: Native vs. Custom Architectures
Bringing GCP audit, VPC flow, and DNS logs into Microsoft Sentinel — the native Pub/Sub connector versus a custom ingestion pipeline, with setup steps, trade-offs, and troubleshooting.