← All posts
meta · detection

Why I started writing these notes

A short intro to what this blog is for and who it is for.

Most of what I learn at work never leaves a ticket. A detection fires, we tune it, we close the incident, and the reasoning behind it evaporates. This blog is my attempt to write some of that down — the why behind detections, onboarding decisions, and the trade-offs that don’t fit neatly into a runbook.

If you run a SOC, engineer detections, or onboard tenants into Microsoft Defender XDR and Sentinel, this is aimed at you. Expect concrete write-ups: what fired, what I changed, and what I’d do differently next time.

This is placeholder content. Replace it with your own first post.

Thanks for reading — more soon.