topic
Microsoft Sentinel
13 posts tagged “Microsoft Sentinel”.
Detection-as-Code for Microsoft Sentinel and Defender XDR: A Technical Deep Dive
Microsoft's July 2026 Preview lets you manage Defender XDR custom detections as code — through the Microsoft Security Bicep extension, Microsoft.Security/detectionRules, and Sentinel Repositories. A technical walkthrough from KQL research to a deployable Bicep detection, validation, match-volume tuning, and CI/CD deployment.
What your DCR transform actually does to untrusted data (and why it matters now)
A CCF-authoring deep-dive: ingestion-time transform design quietly decides what your detections — and now your AI readers — actually see. What a transform really does to attacker-controlled text, the restricted-KQL gotchas that bite, and a non-destructive trust-tagging pattern you can adopt today.
Do prompt injections survive the Microsoft Sentinel pipeline? I measured it.
A defensive-research experiment: if an attacker hides an instruction inside a log field, does it survive a real Microsoft Sentinel ingestion pipeline all the way to where an AI assistant would read it? The answer — and why the connector's transform is the real control surface.
Campaign-Centric Hunting with Microsoft Defender XDR and Microsoft Sentinel
Moving from a single suspicious email to full campaign impact — using Defender for Office 365 Campaign Views and the CampaignInfo table with EmailEvents, UrlClickEvents, and post-delivery data to see who was targeted, who clicked, and what to prioritize.
Identity Attack Graph in Microsoft Sentinel
How Sentinel's Identity Attack Graph exposes hidden access paths between identities, permissions, groups, and Azure resources — use cases, onboarding prerequisites (including the Azure Resource Graph connector), and how graph-based investigation complements KQL.
Microsoft Sentinel MCP Entity Analyzer: Explainable Risk Analysis for URLs and Identities
How Sentinel's Entity Analyzer changes the enrichment and triage model — a single explainable verdict for URLs and identities via the Sentinel MCP tools, with the prerequisites, concurrency limits, cost model, and rollout pattern that make it work in production.
What's New in Microsoft Sentinel and XDR: AI Automation, Data Lake Innovation, and Unified SecOps
The engineering shift to unified security operations in the Defender portal — Azure portal sunset timeline, the AI playbook generator, CCF Push, data lake tier ingestion, and the migration implications that actually change how you build detections.
Endpoint and EDR Ecosystem Connectors in Microsoft Sentinel
An engineering-first approach to multi-EDR SOCs — ingesting Cisco Secure Endpoint, WithSecure, Samsung Knox, and Lookout into Microsoft Sentinel, then normalizing, correlating, and orchestrating response across vendors.
Threat Intelligence & Identity Ecosystem Connectors in Microsoft Sentinel
Integrating third-party threat-intel feeds (GreyNoise, Team Cymru) with identity logs (OneLogin, PingOne, Keeper) in Microsoft Sentinel — enrichment pipelines, false-positive reduction, and MITRE-mapped detection rules.
SAP & Business-Critical App Security Connectors in Microsoft Sentinel
Making SAP and SAP-adjacent security signals operational in a SOC — reliable ingestion, stable schemas, a normalization layer, and detections for ABAP privilege abuse that survive latency and schema drift.
Integrating Proofpoint and Mimecast Email Security with Microsoft Sentinel
Ingesting Proofpoint POD/TAP and Mimecast Secure Email Gateway telemetry into Microsoft Sentinel, and correlating it with identity, endpoint, and threat-intel signals for end-to-end phishing detection.
Cloud Posture + Attack Surface Signals in Microsoft Sentinel (Prisma Cloud + Cortex Xpanse)
Bringing Palo Alto Prisma Cloud (CSPM/CWPP) and Cortex Xpanse exposure signals into Microsoft Sentinel, plus the KQL correlation recipes that turn posture and attack-surface data into prioritized incidents.
Ingesting Google Cloud Logs into Microsoft Sentinel: Native vs. Custom Architectures
Bringing GCP audit, VPC flow, and DNS logs into Microsoft Sentinel — the native Pub/Sub connector versus a custom ingestion pipeline, with setup steps, trade-offs, and troubleshooting.