// the archive
Blog
Detections, teardowns, and onboarding notes from running Microsoft security tooling in production. No fluff — the stuff I wish someone had written down first.
Field notes: building a Sentinel CCF connector
What actually matters when you move a connector to the Codeless Connector Framework.
Legacy vs Unified RBAC when onboarding Defender XDR
The one early decision that shapes every permission you assign afterwards.
Why I started writing these notes
A short intro to what this blog is for and who it is for.