

Recent

Operational Workbooks Episode 1: Running a Playbook from a Workbook
·1797 words·9 mins
The right Workbook can make a world of difference in how you understand the data you’re bringing into your workspace. I’ve built some pretty crap ones and have borne witness to works of art crafted with mission-driven care by clients. Personally, I think they may be one of the most overlooked features by teams getting into Sentinel, and I think I understand why.

Using KQL to Detect Gaps in your Conditional Access Strategy
·1370 words·7 mins
Conditional Access Policies are the sentry standing at the gateway of your Azure resources. Every organization will have unique rules for the various needs of the business and the logic can get complicated very quickly.

Optimizing the SOC
·2598 words·13 mins
Alright, so you got the blinky boxes and colorful dashboards showing data no one remembers why they wanted to see. You even puts emojis in all your KQL charts because you can. You’re drooling at the sight of that “Enter prompt here..” bar and the budget is burning a hole in your pocket.

Practical Temporal Proximity in KQL
·1442 words·7 mins
Temporal Proximity in Information Security refers to the occurrence of two or more related events, similar or different in nature, within a specified time frame. This concept is essential for identifying patterns, correlations, and potential security incidents based on the timing and sequence of these events.

Simplifying User and Entity Behavior Detection
·2090 words·10 mins
Like Nailing Jell-o to a Wall # In a poll I ran asking the community which detection domains could use more of their attention, User Behavior reigned supreme.

Stack Your Deception: Stacking MDE Deception Rules with Thinkst Canarytokens
··1534 words·8 mins
Updated Changelog: corrected Path for custom lures A relatively new and straight forward feature pushed to client machines through Microsoft Defender for Endpoint as part of Defener XDR is the Deception capability. For those who may not know, Deception tech involves deploying decoy systems, data, or networks to deceive and trap attackers, enhancing threat detection and response capabilities. It helps organizations detect and thwart malicious activities by luring attackers away from their real targets.

Enhancing Your Entity Timelines: Sentinel Activities in the Unified Microsoft Defender XDR Portal
·1201 words·6 mins
With the recent release of the Microsoft unified security operations platform in the Defender portal which is the integration of Microsoft Sentinel and Microsoft Defender XDR, there has been A LOT to take in. Both mentally and technologically. All the new features and settings to take advantage of has been overwhelming in a really good way!