topic
Defender XDR
5 posts tagged “Defender XDR”.
Detection-as-Code for Microsoft Sentinel and Defender XDR: A Technical Deep Dive
Microsoft's July 2026 Preview lets you manage Defender XDR custom detections as code — through the Microsoft Security Bicep extension, Microsoft.Security/detectionRules, and Sentinel Repositories. A technical walkthrough from KQL research to a deployable Bicep detection, validation, match-volume tuning, and CI/CD deployment.
Project Perception: Microsoft's agentic security moves from alerting to acting
Microsoft's Project Perception coordinates red, blue, and green AI agents on a new cyber stack powered by MAI-Cyber-1-Flash. What shipped in the public preview, what's gated behind human approval, how the architecture fits together, and the questions worth testing before you rely on it.
Campaign-Centric Hunting with Microsoft Defender XDR and Microsoft Sentinel
Moving from a single suspicious email to full campaign impact — using Defender for Office 365 Campaign Views and the CampaignInfo table with EmailEvents, UrlClickEvents, and post-delivery data to see who was targeted, who clicked, and what to prioritize.
Operational Notes on Microsoft Security Copilot Agents in Defender XDR and Microsoft Entra ID
Practical SOC observations on Security Copilot agents — how they're deployed, how they consume Security Compute Units, the agentic identities and Unified RBAC roles they create, where to monitor usage, and KQL for reviewing agent activity.
What's New in Microsoft Sentinel and XDR: AI Automation, Data Lake Innovation, and Unified SecOps
The engineering shift to unified security operations in the Defender portal — Azure portal sunset timeline, the AI playbook generator, CCF Push, data lake tier ingestion, and the migration implications that actually change how you build detections.