Defender for Endpoint - Custom Data Collection Rules

Expand the logging capability of the DFE agent using custom rules

A bit of background on this feature might be needed - and a lot of credit has to be given to Olaf Hartong and FalconForce for this. Through a (now 6) part blog series on MDE internals they outlined some limitations in the MDE agent. I suggest starting at post... [Read More]
Tags: Defender XDR, Advanced Hunting, Detection Engineering, Custom Data Collection Rules, Custom Data Collection

Practical Detection Engineering

A look at detection engineering from inception to completion

The concept of this blogpost is quite simple - we will start with an imaginary company that has identified some threats to their storage accounts and follow the process of detection engineering. The field of detection engineering is in itself quite big and complex, so I will resort to some... [Read More]
Tags: Defender XDR, Advanced Hunting, Custom Detection Rules, Analytic Rules, Detection Engineering