Required claims for GitHub flexible federated identity credentials
Microsoft Entra requires GitHub expressions to match sub and compare repository_id or repository_owner_id with eq.
Practical Microsoft Sentinel, Defender XDR, and MISP guides focused on detection engineering, log strategy, and automation.
Browse field-tested walkthroughs on security monitoring architecture, cost optimization, threat intelligence pipelines, and practical detection engineering.
These are currently the most visited posts on the site.
A practical breakdown of the Microsoft Sentinel to Defender XDR migration, including architecture impact, correlation behavior, and planning considerations.
Create and manage Defender XDR custom detection rules through Microsoft Graph API with payload patterns, limits, and caveats.
Manage Defender XDR custom detection rules through Microsoft Graph with entity mappings, automated actions, and service principal authentication.
The three most recent posts from the site.
Microsoft Entra requires GitHub expressions to match sub and compare repository_id or repository_owner_id with eq.
An attempt at distilling why and how to learn from someone who's adept at not knowing stuff
How to set protectionLevel on Azure Monitor Logs tables, grant read access, close the control-plane bypass with DataActionsOnly, and audit changes.
Start here if you want a focused reading path by topic.
Cost control, retention choices, and data-tier planning for real-world Sentinel operations.
Detection design, custom rule operations, and Defender XDR execution patterns.
Threat intel ingestion, pipeline hardening, and MISP-to-Sentinel implementation patterns.
Everything on the blog, with tag filtering if you want to narrow it down.