Practical Detection Engineering

A look at detection engineering from inception to completion

The concept of this blogpost is quite simple - we will start with an imaginary company that has identified some threats to their storage accounts and follow the process of detection engineering. The field of detection engineering is in itself quite big and complex, so I will resort to some... [Read More]
Tags: Defender XDR, Advanced Hunting, Custom Detection Rules, Analytic Rules, Detection Engineering

Microsoft Sentinel Data Lake - FAQ

Answering some common questions people might have

Data lake is here, rejoice. It also brings up a bunch of questions, like do I still need Microsoft Sentinel? Yes. Is this just auxiliary logging done well without a lot of complications, like not being able to use the “new” Azure Monitoring Agent and instead having to lean on... [Read More]
Tags: Microsoft Sentinel, Defender XDR, Graph API, Azure Lighthouse, Custom Detection Rules