Skip to main content

Attack the SOC

Recent

Operational Workbooks Episode 1: Running a Playbook from a Workbook

Operational Workbooks Episode 1: Running a Playbook from a Workbook

·1797 words·9 mins
The right Workbook can make a world of difference in how you understand the data you’re bringing into your workspace. I’ve built some pretty crap ones and have borne witness to works of art crafted with mission-driven care by clients. Personally, I think they may be one of the most overlooked features by teams getting into Sentinel, and I think I understand why.
Using KQL to Detect Gaps in your Conditional Access Strategy

Using KQL to Detect Gaps in your Conditional Access Strategy

·1370 words·7 mins
Conditional Access Policies are the sentry standing at the gateway of your Azure resources. Every organization will have unique rules for the various needs of the business and the logic can get complicated very quickly.
Optimizing the SOC

Optimizing the SOC

·2598 words·13 mins
Alright, so you got the blinky boxes and colorful dashboards showing data no one remembers why they wanted to see. You even puts emojis in all your KQL charts because you can. You’re drooling at the sight of that “Enter prompt here..” bar and the budget is burning a hole in your pocket.
Practical Temporal Proximity in KQL

Practical Temporal Proximity in KQL

·1442 words·7 mins
Temporal Proximity in Information Security refers to the occurrence of two or more related events, similar or different in nature, within a specified time frame. This concept is essential for identifying patterns, correlations, and potential security incidents based on the timing and sequence of these events.
Simplifying User and Entity Behavior Detection

Simplifying User and Entity Behavior Detection

·2090 words·10 mins
 Like Nailing Jell-o to a Wall # In a poll I ran asking the community which detection domains could use more of their attention, User Behavior reigned supreme.
Stack Your Deception: Stacking MDE Deception Rules with Thinkst Canarytokens

Stack Your Deception: Stacking MDE Deception Rules with Thinkst Canarytokens

··1534 words·8 mins
Updated Changelog: corrected Path for custom lures A relatively new and straight forward feature pushed to client machines through Microsoft Defender for Endpoint as part of Defener XDR is the Deception capability. For those who may not know, Deception tech involves deploying decoy systems, data, or networks to deceive and trap attackers, enhancing threat detection and response capabilities. It helps organizations detect and thwart malicious activities by luring attackers away from their real targets.