<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>infernux</title><description>Personal blog and portfolio - Security, Cloud, and Technology</description><link>https://infernux.no/</link><language>en</language><item><title>Plan types now show up in the Usage table</title><link>https://infernux.no/blog/microsoftsentinel-usage-plan/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-usage-plan/</guid><description>The Usage table now exposes plan information, making it much easier to break down Microsoft Sentinel ingestion by Analytics, Basic, and Auxiliary with native KQL.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Data and logging</category><category>Log Analytics</category></item><item><title>AADGraphActivityLogs is now available</title><link>https://infernux.no/blog/aadgraphactivitylogs/</link><guid isPermaLink="true">https://infernux.no/blog/aadgraphactivitylogs/</guid><description>Quick notes on the new AADGraphActivityLogs table, sample data generation with AADInternals and ROADtools, and some starter queries.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>Entra ID</category><category>Microsoft Sentinel</category><category>Data and logging</category><category>Detection Engineering</category><category>Log Analytics</category></item><item><title>A Guide to Presenting Stuff, sort of</title><link>https://infernux.no/blog/guidetopresentingstuff/</link><guid isPermaLink="true">https://infernux.no/blog/guidetopresentingstuff/</guid><description>A semi-practical guide to how presenting better helps you learn, whether you&apos;re on stage, in a meeting, or just trying to explain a technical idea clearly.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>Presentation Skills</category><category>Conference Speaking</category><category>Public Speaking</category></item><item><title>How to use Log Horizon to improve Microsoft Sentinel posture</title><link>https://infernux.no/blog/loghorizon-howtouse/</link><guid isPermaLink="true">https://infernux.no/blog/loghorizon-howtouse/</guid><description>A tutorial to using the Log Horizon tool to get an overview of your Microsoft Sentinel deployment, including logs, detection and Defender XDR integration.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>PowerShell</category><category>Data and logging</category><category>Cost Optimization</category><category>Log Horizon</category></item><item><title>Update: Log Horizon</title><link>https://infernux.no/blog/loghorizon-update1/</link><guid isPermaLink="true">https://infernux.no/blog/loghorizon-update1/</guid><description>Log Horizon 0.5.0 adds self-contained HTML export, deeper transform analysis, stronger hardening, and improved CI-friendly reporting for Microsoft Sentinel.</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>PowerShell</category><category>Data and logging</category><category>Cost Optimization</category><category>Log Horizon</category></item><item><title>Building a practical log baseline</title><link>https://infernux.no/blog/buildingapracticallogbaseline/</link><guid isPermaLink="true">https://infernux.no/blog/buildingapracticallogbaseline/</guid><description>How to classify security logs into primary and secondary data, use Sentinel tiers pragmatically, and keep cost aligned with detection value.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Data and logging</category><category>Detection Engineering</category><category>Cost Optimization</category></item><item><title>Tool Release: Log Horizon</title><link>https://infernux.no/blog/loghorizon-toolrelease/</link><guid isPermaLink="true">https://infernux.no/blog/loghorizon-toolrelease/</guid><description>A PowerShell module that connects to your Sentinel workspace and tells you if your logs are earning their keep.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>PowerShell</category><category>Data and logging</category><category>Cost Optimization</category><category>Log Horizon</category></item><item><title>Upcoming Microsoft Sentinel features</title><link>https://infernux.no/blog/sentinel-rsac-2026-takeaways/</link><guid isPermaLink="true">https://infernux.no/blog/sentinel-rsac-2026-takeaways/</guid><description>Diving into some of the recent RSAC announcements</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Data and logging</category><category>MCP</category><category>Detection Engineering</category><category>Codeless Connector Framework</category></item><item><title>Privileged Access 101 in Entra ID</title><link>https://infernux.no/blog/privileged-access-101/</link><guid isPermaLink="true">https://infernux.no/blog/privileged-access-101/</guid><description>My potentially &apos;realistic-ish&apos; take on privileged access in Entra ID, Azure and Microsoft 365. Not perfect, not nothing, maybe just good enough to actually work.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate><category>Entra ID</category><category>Privileged Access</category><category>PIM</category><category>Conditional Access</category><category>Azure RBAC</category><category>Microsoft 365</category></item><item><title>Defender XDR - Custom Detection Rules PowerShell Module</title><link>https://infernux.no/blog/defenderxdr-cdrmodule/</link><guid isPermaLink="true">https://infernux.no/blog/defenderxdr-cdrmodule/</guid><description>A simple PowerShell module for managing custom detection rules via the Graph API, with SPN support</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate><category>Microsoft Defender XDR</category><category>Graph API</category><category>Custom Detection Rules</category><category>PowerShell</category></item><item><title>Tool Release: rustymisp2sentinel</title><link>https://infernux.no/blog/rustymisp2sentinel/</link><guid isPermaLink="true">https://infernux.no/blog/rustymisp2sentinel/</guid><description>From idea to execution, the story of how I&apos;m still trying to learn rust.</description><pubDate>Sat, 24 Jan 2026 00:00:00 GMT</pubDate><category>Analytic Rules</category><category>Microsoft Sentinel</category><category>Powershell</category></item><item><title>Make some noise - a note on detections</title><link>https://infernux.no/blog/makesomenoise/</link><guid isPermaLink="true">https://infernux.no/blog/makesomenoise/</guid><description>Most detection engineers already know this, but based on experience many companies will fail to consider noise in their detection strategy.</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate><category>Detection Engineering</category><category>Security Monitoring</category></item><item><title>Testing the SinkVPN-concept to silence EDRs</title><link>https://infernux.no/blog/sinkvpn/</link><guid isPermaLink="true">https://infernux.no/blog/sinkvpn/</guid><description>Can we silence Defender for Endpoint using a rogue VPN-server?</description><pubDate>Sun, 18 Jan 2026 00:00:00 GMT</pubDate><category>Security Monitoring</category><category>EDR</category><category>Powershell</category><category>Defender for Endpoint</category></item><item><title>Tool Release: misp-filter-builder</title><link>https://infernux.no/blog/mispfilterbuilder/</link><guid isPermaLink="true">https://infernux.no/blog/mispfilterbuilder/</guid><description>A little weekend project to help build filters for MISP and misp2sentinel</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><category>MISP</category><category>Microsoft Sentinel</category><category>Threat Intelligence</category></item><item><title>Could you build a simple C2-framework using World of Warcraft?</title><link>https://infernux.no/blog/wowc2/</link><guid isPermaLink="true">https://infernux.no/blog/wowc2/</guid><description>Yes. Sort of, at least. Join me to explore how we can potentially use WoW and it&apos;s ecosystem as a C2</description><pubDate>Sat, 10 Jan 2026 00:00:00 GMT</pubDate><category>Cyber Security</category><category>C2</category></item><item><title>Disable correlation for Analytic Rules in Microsoft Sentinel</title><link>https://infernux.no/blog/nocorrelation/</link><guid isPermaLink="true">https://infernux.no/blog/nocorrelation/</guid><description>Simple script that automates the job of excluding analytic rules from correlation in Defender XDR.</description><pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate><category>Analytic Rules</category><category>Microsoft Sentinel</category><category>Powershell</category></item><item><title>Migrating Microsoft Sentinel to Microsoft Defender XDR</title><link>https://infernux.no/blog/migratingsentineltodefenderxdr/</link><guid isPermaLink="true">https://infernux.no/blog/migratingsentineltodefenderxdr/</guid><description>An in-depth look at why this change is happening and some things to expect from the migration.</description><pubDate>Sun, 04 Jan 2026 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Security Monitoring</category><category>Microsoft Sentinel</category><category>Microsoft Defender XDR</category><category>Unified Experience</category></item><item><title>Tool Release: DarkLighthouse</title><link>https://infernux.no/blog/toolrelease-darklighthouse/</link><guid isPermaLink="true">https://infernux.no/blog/toolrelease-darklighthouse/</guid><description>DarkLighthouse is a PowerShell module for discovering Azure Lighthouse delegations. Great for security assessments and understanding your multi-tenant attack surface.</description><pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate><category>Cyber Security</category><category>PowerShell</category><category>Azure</category><category>Azure Lighthouse</category><category>Security Assessment</category></item><item><title>This can&apos;t possibly work - building a detection engineering assistant</title><link>https://infernux.no/blog/festivetechcalendar-detectionengineeringagent/</link><guid isPermaLink="true">https://infernux.no/blog/festivetechcalendar-detectionengineeringagent/</guid><description>My entry for this years Festive Tech Calendar 2025 is a little detection engineering assistant</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate><category>SIEM</category><category>XDR</category><category>Custom Detection Rules</category><category>Analytic Rules</category><category>Detection Engineering</category><category>Microsoft Sentinel</category><category>Microsoft Defender XDR</category></item><item><title>Lab - Defender for IoT configuration</title><link>https://infernux.no/blog/lab-defenderforiot/</link><guid isPermaLink="true">https://infernux.no/blog/lab-defenderforiot/</guid><description>My first project on the new lab - setting up Defender for IoT on my IoT network to capture some traffic and see how it works.</description><pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate><category>Lab</category><category>Defender for IoT</category><category>Microsoft Sentinel</category><category>IoT</category></item><item><title>Lab - Setting up Hyper-V host</title><link>https://infernux.no/blog/lab-settingup/</link><guid isPermaLink="true">https://infernux.no/blog/lab-settingup/</guid><description>Getting started on my local lab. This post is mainly me troubleshooting Intel I225/226 network adapters.</description><pubDate>Sun, 30 Nov 2025 00:00:00 GMT</pubDate><category>Lab</category><category>Hyper-V</category></item><item><title>Defender for Endpoint - Custom Data Collection Rules</title><link>https://infernux.no/blog/defenderforendpoint-customdatacollectionrules/</link><guid isPermaLink="true">https://infernux.no/blog/defenderforendpoint-customdatacollectionrules/</guid><description>Expand the logging capability of the DFE agent using custom rules</description><pubDate>Sat, 22 Nov 2025 00:00:00 GMT</pubDate><category>Microsoft Defender XDR</category><category>Advanced Hunting</category><category>Detection Engineering</category><category>Data and logging</category></item><item><title>Practical Detection Engineering</title><link>https://infernux.no/blog/practicaldetectionengineering/</link><guid isPermaLink="true">https://infernux.no/blog/practicaldetectionengineering/</guid><description>A look at detection engineering from inception to completion</description><pubDate>Tue, 11 Nov 2025 00:00:00 GMT</pubDate><category>Microsoft Defender XDR</category><category>Advanced Hunting</category><category>Custom Detection Rules</category><category>Analytic Rules</category><category>Detection Engineering</category></item><item><title>Microsoft Defender XDR - Take action on advanced hunting results</title><link>https://infernux.no/blog/takeactiononadvancedhunting/</link><guid isPermaLink="true">https://infernux.no/blog/takeactiononadvancedhunting/</guid><description>The level below automation and above manual actions per asset</description><pubDate>Fri, 22 Aug 2025 00:00:00 GMT</pubDate><category>Microsoft Defender XDR</category><category>Advanced Hunting</category></item><item><title>Microsoft Sentinel Data Lake - FAQ</title><link>https://infernux.no/blog/microsoftsentinel-thelake/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-thelake/</guid><description>Answering some common questions people might have</description><pubDate>Tue, 29 Jul 2025 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Microsoft Defender XDR</category><category>Graph API</category><category>Azure Lighthouse</category><category>Custom Detection Rules</category></item><item><title>How to not mess up your Microsoft Sentinel deployment</title><link>https://infernux.no/blog/microsoftsentinel-how-to-not-mess-it-up/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-how-to-not-mess-it-up/</guid><description>Looking beyond just the technical details</description><pubDate>Sun, 20 Jul 2025 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Microsoft Defender XDR</category><category>Graph API</category><category>Azure Lighthouse</category><category>Custom Detection Rules</category></item><item><title>Defender XDR - Custom Detection Rules Push/Pull via API</title><link>https://infernux.no/blog/defenderxdr-customdetectionrules/</link><guid isPermaLink="true">https://infernux.no/blog/defenderxdr-customdetectionrules/</guid><description>A little primer to pushing and pulling new content via the graph beta API</description><pubDate>Sun, 01 Jun 2025 00:00:00 GMT</pubDate><category>Microsoft Defender XDR</category><category>Graph API</category><category>Custom Detection Rules</category></item><item><title>Azure Spring Clean - Maestering Azure Tenant Security</title><link>https://infernux.no/blog/azurespringclean/</link><guid isPermaLink="true">https://infernux.no/blog/azurespringclean/</guid><description>A look into how we can utilize Maester to secure our Azure Tenant with a sprinkle of AI on top</description><pubDate>Fri, 28 Feb 2025 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Entra ID</category><category>Maester</category><category>Azure</category><category>Microsoft 365</category></item><item><title>Workspace Transformation Rules in Practice</title><link>https://infernux.no/blog/workspacetransformationrules/</link><guid isPermaLink="true">https://infernux.no/blog/workspacetransformationrules/</guid><description>This post will show you two very useful workspace transformation rules that you can use to save money on your data ingestion in Microsoft Sentinel.</description><pubDate>Mon, 24 Feb 2025 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Microsoft Sentinel</category><category>Azure</category><category>Log Analytics</category><category>Workspace Transformation Rules</category><category>Data and logging</category></item><item><title>Expanding on Cyber Threat Intelligence for Security Monitoring</title><link>https://infernux.no/blog/expanding-on-cti/</link><guid isPermaLink="true">https://infernux.no/blog/expanding-on-cti/</guid><description>Three levels of detection engineering using Threat Intelligence as our guiding light</description><pubDate>Sun, 26 Jan 2025 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Security Monitoring</category><category>Threat Intelligence</category><category>MISP</category><category>Detection Engineering</category></item><item><title>On the use of Threat Intelligence in Detection</title><link>https://infernux.no/blog/ti-detection/</link><guid isPermaLink="true">https://infernux.no/blog/ti-detection/</guid><description>If applied correctly, Threat Intelligence can be a useful tool in your belt. Mostly, however, it might be barking up the wrong tree depending on your maturity level. Let&apos;s explore that!</description><pubDate>Sun, 12 Jan 2025 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Security Monitoring</category><category>Threat Intelligence</category><category>MISP</category><category>Detection Engineering</category></item><item><title>Tool Release: pwshuploadindicatorsapi</title><link>https://infernux.no/blog/toolrelease-pwshuploadindicatorsapi/</link><guid isPermaLink="true">https://infernux.no/blog/toolrelease-pwshuploadindicatorsapi/</guid><description>This module is a wrapper for the Microsoft Sentinel related Upload Indicators API, allowing you to upload indicators of compromise (IOC) to a Microsoft Sentinel instance.</description><pubDate>Fri, 27 Dec 2024 00:00:00 GMT</pubDate><category>Cyber Security</category><category>PowerShell</category><category>Threat Intelligence</category><category>MISP</category><category>Microsoft Sentinel</category><category>Upload Indicators API</category></item><item><title>Tool Release: pwshmisp</title><link>https://infernux.no/blog/toolrelease-pwshmisp/</link><guid isPermaLink="true">https://infernux.no/blog/toolrelease-pwshmisp/</guid><description>In an attempt to make using MISP easier, I have created a PowerShell module to interact with MISP. The release of this module is the first step towards creating a powershell integration function for pushing data from MISP to Microsoft Sentinel.</description><pubDate>Mon, 23 Dec 2024 00:00:00 GMT</pubDate><category>Cyber Security</category><category>PowerShell</category><category>Threat Intelligence</category><category>MISP</category><category>Microsoft Sentinel</category></item><item><title>Test Yourself Part 1: Identity</title><link>https://infernux.no/blog/testyourself-pt2/</link><guid isPermaLink="true">https://infernux.no/blog/testyourself-pt2/</guid><description>Some tips, tricks and tools to help you get started testing your own infrastructure. This is the part 1 where we&apos;ll look into identity and how you can test it.</description><pubDate>Sat, 26 Oct 2024 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Entra ID</category><category>Security Monitoring</category><category>Azure</category><category>Microsoft 365</category></item><item><title>Hardening Entra ID</title><link>https://infernux.no/blog/entraid-generalhardening/</link><guid isPermaLink="true">https://infernux.no/blog/entraid-generalhardening/</guid><description>This is an update to a previous article I wrote on hardening Azure Active Directory. The idea of this update is to provide a table of default settings that I would change in any Entra ID-tenant I manage.</description><pubDate>Fri, 18 Oct 2024 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Entra ID</category><category>Hardening</category><category>Data and logging</category><category>App registration</category><category>Enterprise applications</category><category>Consent</category></item><item><title>Security Monitoring - Threat Modeling and Data Sources</title><link>https://infernux.no/blog/securitymonitoring-datasources/</link><guid isPermaLink="true">https://infernux.no/blog/securitymonitoring-datasources/</guid><description>One of the most misunderstood aspects of security monitoring is determining what data sources to use for what purpose. In this post, we will go through the process of determining what data sources to use for what purpose, where to prioritize developing use cases and how to plan for the future.</description><pubDate>Sun, 25 Aug 2024 00:00:00 GMT</pubDate><category>Security Monitoring</category><category>Data and logging</category><category>SIEM</category><category>Use Cases</category><category>Microsoft Sentinel</category></item><item><title>Security Monitoring Antipatterns</title><link>https://infernux.no/blog/securitymonitoringantipatterns/</link><guid isPermaLink="true">https://infernux.no/blog/securitymonitoringantipatterns/</guid><description>A little bit of a deconstruction of some antipatterns in Security Operations</description><pubDate>Mon, 19 Aug 2024 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Security Architecture</category><category>Antipatterns</category><category>Security Monitoring</category></item><item><title>Adding Graph API permissions to Managed Identities</title><link>https://infernux.no/blog/graphapipermissionsformanagedidentity/</link><guid isPermaLink="true">https://infernux.no/blog/graphapipermissionsformanagedidentity/</guid><description>Making a little note of this in Graph API so it&apos;s easy to find for using it</description><pubDate>Fri, 16 Aug 2024 00:00:00 GMT</pubDate><category>Nice to know</category><category>Entra ID</category><category>Azure</category><category>Logic App</category><category>Managed Identity</category></item><item><title>5 Years On - The Microsoft Sentinel Experience</title><link>https://infernux.no/blog/5yearsofsentinel/</link><guid isPermaLink="true">https://infernux.no/blog/5yearsofsentinel/</guid><description>Around 5 years ago, Microsoft announced the general availability of Azure Sentinel. This post aims to assess how far we along we have come - the good, the bad and the ugly.</description><pubDate>Tue, 09 Jul 2024 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Security Monitoring</category><category>Microsoft Sentinel</category><category>Microsoft Security</category></item><item><title>Test Yourself: The Prelude</title><link>https://infernux.no/blog/testyourself/</link><guid isPermaLink="true">https://infernux.no/blog/testyourself/</guid><description>Some tips, tricks and tools to help you get started testing your own infrastructure. This is the start, where I&apos;ll just lay out some basic principles of security that we need to keep in mind moving forward.</description><pubDate>Fri, 21 Jun 2024 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Entra ID</category><category>Security Monitoring</category><category>Azure</category><category>Microsoft 365</category></item><item><title>Authenticate to Azure DevOps using Managed Identity and REST API</title><link>https://infernux.no/blog/authenticatetoazuredevops/</link><guid isPermaLink="true">https://infernux.no/blog/authenticatetoazuredevops/</guid><description>How to add a managed identity to Azure DevOps and get access tokens for Azure Devops</description><pubDate>Wed, 17 Apr 2024 00:00:00 GMT</pubDate><category>Entra ID</category><category>Azure</category><category>Managed Identity</category><category>Identity and Access Management</category><category>Cloud Security</category><category>Azure DevOps</category></item><item><title>Download Azure DevOps Repositories using a Managed Identity and REST API</title><link>https://infernux.no/blog/downloadazuredevopsrepo/</link><guid isPermaLink="true">https://infernux.no/blog/downloadazuredevopsrepo/</guid><description>Everything you need to know to download Azure DevOps repositories using a Managed Identity and REST API</description><pubDate>Wed, 17 Apr 2024 00:00:00 GMT</pubDate><category>Nice to know</category><category>Entra ID</category><category>Azure</category><category>Azure DevOps</category><category>Managed Identity</category></item><item><title>Tools You Should Know: ScubaGear</title><link>https://infernux.no/blog/toolsyoushouldknow-scubagear/</link><guid isPermaLink="true">https://infernux.no/blog/toolsyoushouldknow-scubagear/</guid><description>Developed by CISA, ScubaGear is an assessment tool that verifies a Microsoft 365 (M365) tenant’s configuration conforms to the policies described in the Secure Cloud Business Applications (SCuBA) Security Configuration Baseline documents.</description><pubDate>Sat, 09 Mar 2024 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Entra ID</category><category>Security Monitoring</category><category>Azure</category><category>Microsoft 365</category><category>ScubaGear</category></item><item><title>Automating Security Monitoring - Part 2: Automation</title><link>https://infernux.no/blog/automatingsecuritymonitoringp2/</link><guid isPermaLink="true">https://infernux.no/blog/automatingsecuritymonitoringp2/</guid><description>A look at automating alerts and incident-handling.</description><pubDate>Sat, 03 Feb 2024 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Automation</category><category>SOAR</category><category>Security Monitoring</category></item><item><title>Automating Security Monitoring - Part 1: Data</title><link>https://infernux.no/blog/automatingsecuritymonitoring1/</link><guid isPermaLink="true">https://infernux.no/blog/automatingsecuritymonitoring1/</guid><description>A look at how to get started automating security monitoring (or just stuff in general).</description><pubDate>Wed, 31 Jan 2024 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Automation</category><category>SOAR</category><category>Security Monitoring</category><category>Data Engineering</category></item><item><title>Christmas Wrappers - Part 2</title><link>https://infernux.no/blog/christmas-wrappers-part2/</link><guid isPermaLink="true">https://infernux.no/blog/christmas-wrappers-part2/</guid><description>How to create a wrapper script in Powershell</description><pubDate>Mon, 15 Jan 2024 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>MISP</category></item><item><title>Christmas Wrappers - Part 1</title><link>https://infernux.no/blog/christmas-wrappers/</link><guid isPermaLink="true">https://infernux.no/blog/christmas-wrappers/</guid><description>How to create a wrapper script in Powershell</description><pubDate>Mon, 18 Dec 2023 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>MISP</category></item><item><title>Security Monitoring - Developing Use Cases</title><link>https://infernux.no/blog/securitymonitoring-developingusecases/</link><guid isPermaLink="true">https://infernux.no/blog/securitymonitoring-developingusecases/</guid><description>Some thoughts on developing use cases and the importance of detection engineering</description><pubDate>Sun, 17 Sep 2023 00:00:00 GMT</pubDate><category>Cyber Security</category><category>Security Monitoring</category><category>SIEM</category><category>Use Cases</category><category>Microsoft Sentinel</category></item><item><title>Figuring out MISP2Sentinel Event Filters</title><link>https://infernux.no/blog/misp2sentinel-eventfilters/</link><guid isPermaLink="true">https://infernux.no/blog/misp2sentinel-eventfilters/</guid><description>How they work, how to use them and some (hopefully not horrible) examples.</description><pubDate>Sat, 02 Sep 2023 00:00:00 GMT</pubDate><category>MISP</category><category>Threat Intelligence</category><category>Microsoft Sentinel</category><category>IOC</category></item><item><title>Use Update Indicators API to push Threat Intelligence from MISP to Microsoft Sentinel</title><link>https://infernux.no/blog/microsoftsentinel-misp2sentinelupdate/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-misp2sentinelupdate/</guid><description>A quick intro on how to set up MISP, Azure Functions and Sentinel to push threat intelligence from MISP to Sentinel</description><pubDate>Thu, 03 Aug 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Microsoft Sentinel</category><category>Data and logging</category><category>Azure Functions</category><category>Automation</category><category>MISP</category><category>Upload Indicators API</category></item><item><title>Pushing Threat Intelligence from MISP to Microsoft Sentinel</title><link>https://infernux.no/blog/microsoftsentinel-pushtifrommisp/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-pushtifrommisp/</guid><description>A quick intro on how to set up MISP, Azure Functions and Sentinel to push threat intelligence from MISP to Sentinel</description><pubDate>Sun, 04 Jun 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Microsoft Sentinel</category><category>Data and logging</category><category>Azure Functions</category><category>Automation</category><category>MISP</category></item><item><title>Increasing the default timeout of Azure Functions</title><link>https://infernux.no/blog/microsoftsentinel-azurefunctiondataconnectorstimeout/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-azurefunctiondataconnectorstimeout/</guid><description>Azure Functions are used for most data connectors, but some of them have a very low default timeout.</description><pubDate>Fri, 02 Jun 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Microsoft Sentinel</category><category>Data and logging</category><category>Azure Functions</category><category>Automation</category><category>MISP</category></item><item><title>Removing orphaned Azure resource assigments</title><link>https://infernux.no/blog/microsoftazure-removeorphanedidentities/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftazure-removeorphanedidentities/</guid><description>Simple fix for removing any &quot;identity not found&quot; on resources in Microsoft Azure.</description><pubDate>Mon, 15 May 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Azure</category><category>IAM</category></item><item><title>Microsoft Sentinel Workspace Manager</title><link>https://infernux.no/blog/microsoftsentinel-workspacemanager/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-workspacemanager/</guid><description>Short introduction to the new preview, what it does and what I think of it currently.</description><pubDate>Mon, 24 Apr 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Microsoft Sentinel</category><category>Workspace Manager</category><category>MSSP</category></item><item><title>Field notes on security strategy</title><link>https://infernux.no/blog/securitystrategy/</link><guid isPermaLink="true">https://infernux.no/blog/securitystrategy/</guid><description>Some thoughts and notes around implementing security features and what it is that we keep doing the wrong way.</description><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Microsoft Sentinel</category><category>Data and logging</category></item><item><title>Azure Lighthouse access design considerations</title><link>https://infernux.no/blog/azurelighthouse-designconsiderations/</link><guid isPermaLink="true">https://infernux.no/blog/azurelighthouse-designconsiderations/</guid><description>Considerations when creating an Azure Lighthouse managed service design.</description><pubDate>Tue, 10 Jan 2023 00:00:00 GMT</pubDate><category>Azure</category><category>Azure Lighthouse</category><category>ARM Templates</category><category>Managed Services</category></item><item><title>Cost estimation in Microsoft Sentinel</title><link>https://infernux.no/blog/microsoftsentinel-costestimation/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-costestimation/</guid><description>An introduction to methods for doing cost estimation in Microsoft Sentinel.</description><pubDate>Mon, 02 Jan 2023 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Microsoft Sentinel</category><category>Data and logging</category></item><item><title>I want you to steal my job</title><link>https://infernux.no/blog/stealmyjob/</link><guid isPermaLink="true">https://infernux.no/blog/stealmyjob/</guid><description>I&apos;m a Security Engineer (whatever that means) and maybe you want to be to? Hopefully this helps a little towards that.</description><pubDate>Fri, 02 Dec 2022 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Azure DevOps</category><category>PowerShell</category><category>Microsoft Sentinel</category><category>Azure</category><category>AWS</category><category>GCP</category></item><item><title>Design an MSSP access strategy for Microsoft Sentinel</title><link>https://infernux.no/blog/azurelighthouse-msspaccess/</link><guid isPermaLink="true">https://infernux.no/blog/azurelighthouse-msspaccess/</guid><description>Some thoughts and considerations when designing an Azure Lighthouse access strategy</description><pubDate>Tue, 08 Nov 2022 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Azure Lighthouse</category><category>Privileged Identity Management</category><category>Privileged Access Groups</category><category>MSSP</category></item><item><title>Simple security in Azure DevOps pipelines</title><link>https://infernux.no/blog/azuredevops-webhooktriggersecurity/</link><guid isPermaLink="true">https://infernux.no/blog/azuredevops-webhooktriggersecurity/</guid><description>Quick introduction to starting pipelines with webhook triggers and (hopefully) making them secure-ish</description><pubDate>Fri, 28 Oct 2022 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Azure DevOps</category><category>Webhook triggers</category><category>Pipelines</category></item><item><title>IP Allowlisting in Microsoft Sentinel Playbooks</title><link>https://infernux.no/blog/microsoftsentinel-ipallowlist/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-ipallowlist/</guid><description>Quick introduction to IP allowlisting in Microsoft Sentinel and some thoughts around how to (not) implement it.</description><pubDate>Wed, 26 Oct 2022 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Microsoft Sentinel</category><category>Playbooks</category></item><item><title>Enable Defender for DevOps in Azure DevOps pipelines</title><link>https://infernux.no/blog/defenderfordevops/</link><guid isPermaLink="true">https://infernux.no/blog/defenderfordevops/</guid><description>Quick introduction to Defender for DevOps and how to enable it in an Azure DevOps pipeline.</description><pubDate>Thu, 13 Oct 2022 00:00:00 GMT</pubDate><category>Cloud Security</category><category>Defender for Cloud</category><category>Defender for DevOps</category><category>Azure DevOps</category></item><item><title>Creating smart Data Collection Rules by parsing EventIDs from Analytic Rules</title><link>https://infernux.no/blog/microsoftsentinel-smartdatacollectionrules/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-smartdatacollectionrules/</guid><description>Data Collection Rules allows us to create custom filters based on XPath-queries. If we do this based on active Analytic Rules, we can create DCRs that only ingest the data we actually have detection for.</description><pubDate>Tue, 04 Oct 2022 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Active Directory</category><category>Azure Monitor Agent</category><category>Azure Arc</category><category>Data and logging</category><category>Windows Security Events</category><category>Data Collection Rules</category></item><item><title>Azure Lighthouse 101</title><link>https://infernux.no/blog/azurelighthouse-101/</link><guid isPermaLink="true">https://infernux.no/blog/azurelighthouse-101/</guid><description>What is Azure Lighthouse, what does it do and how does it do it?</description><pubDate>Wed, 21 Sep 2022 00:00:00 GMT</pubDate><category>Azure</category><category>Azure Lighthouse</category><category>ARM Templates</category><category>Managed Services</category></item><item><title>Templating Microsoft Sentinel Analytic Rules using Powershell and CI/CD pipelines</title><link>https://infernux.no/blog/microsoftsentinel-templateanalyticrules/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-templateanalyticrules/</guid><description>Using the Microsoft Sentinel API and Powershell we can download all the components we want and template them for deployment - this allows you to create Analytic Rules in the Azure Portal and deploy them to multiple customers using CI/CD pipelines.</description><pubDate>Thu, 15 Sep 2022 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Azure DevOps</category><category>Analytic Rules</category><category>PowerShell</category><category>Microsoft Sentinel API</category><category>ARM Templates</category></item><item><title>Adding a Key Vault to your Microsoft Sentinel Data Connector ARM-template</title><link>https://infernux.no/blog/microsoftsentinel-addkeyvaultdataconnector/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-addkeyvaultdataconnector/</guid><description>A subset of Data Connector for Sentinel come in the form of Azure Functions deployed using an ARM-template. Most if not all of these functions avoid actually implementing a Key Vault to secure your variables, so here&apos;s the snippets to implement it yourself.</description><pubDate>Mon, 12 Sep 2022 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>ARM Templates</category><category>Azure Functions</category><category>Data and logging</category><category>Key vault</category></item><item><title>Hardening Azure Active Directory</title><link>https://infernux.no/blog/azureactivedirectory-generalhardening/</link><guid isPermaLink="true">https://infernux.no/blog/azureactivedirectory-generalhardening/</guid><description>Going over some attack paths for Azure Active Directory (that I know of) and how to harden your environment to avoid exploitation (or just minimize the risk slightly). The focus for this post is app registrations and basic enumeration.</description><pubDate>Sun, 11 Sep 2022 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Azure Active Directory</category><category>Hardening</category><category>Data and logging</category><category>App registration</category><category>Enterprise applications</category><category>Consent</category></item><item><title>Auditing Microsoft Sentinel queries in an Azure Lighthouse-environment</title><link>https://infernux.no/blog/microsoftsentinel-laquerylogs/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-laquerylogs/</guid><description>Quick introduction to auditing Microsoft Sentinel queries in a cross-tenant scenario - and some things to be aware of.</description><pubDate>Thu, 25 Aug 2022 00:00:00 GMT</pubDate><category>Microsoft Sentinel</category><category>Azure Lighthouse</category><category>LAQueryLogs</category><category>AzureActivity</category><category>Audit</category></item><item><title>Assign roles to managed identities in Microsoft Sentinel playbooks using Azure Lighthouse</title><link>https://infernux.no/blog/azurelighthouse-managedidentity/</link><guid isPermaLink="true">https://infernux.no/blog/azurelighthouse-managedidentity/</guid><description>Grant access via Azure Lighthouse using User Access Administrator delegation, ARM-templates, pipelines and powershell.</description><pubDate>Wed, 06 Jul 2022 00:00:00 GMT</pubDate><category>Azure REST API</category><category>Microsoft Sentinel</category><category>Azure Lighthouse</category><category>ARM Templates</category><category>PowerShell</category><category>Managed Identity</category><category>User Access Administrator</category></item><item><title>Create Managed Identity and assign roles using Azure Lighthouse</title><link>https://infernux.no/blog/azurelighthouse-usermanagedidentity/</link><guid isPermaLink="true">https://infernux.no/blog/azurelighthouse-usermanagedidentity/</guid><description>Create Managed Identites and grant access via Azure Lighthouse using User Access Administrator delegation.</description><pubDate>Tue, 07 Jun 2022 00:00:00 GMT</pubDate><category>Azure REST API</category><category>Microsoft Sentinel</category><category>Azure Lighthouse</category><category>ARM Templates</category><category>PowerShell</category><category>Managed Identity</category><category>User Access Administrator</category></item><item><title>Deploying Automation Rules via API</title><link>https://infernux.no/blog/microsoftsentinel-automationrules/</link><guid isPermaLink="true">https://infernux.no/blog/microsoftsentinel-automationrules/</guid><description>Automate more of your Azure Sentinel deployment by combining the Az Powershell-module and the 2019-01-01-preview API to deploy Automation Rules from JSON-templates.</description><pubDate>Mon, 23 Aug 2021 00:00:00 GMT</pubDate><category>Azure REST API</category><category>Microsoft Sentinel</category><category>SecurityInsights</category><category>Automation Rules</category><category>PowerShell</category></item><item><title>Practical Hacking</title><link>https://infernux.no/blog/practicalhacking/</link><guid isPermaLink="true">https://infernux.no/blog/practicalhacking/</guid><description>Practical guidance for getting started with ethical hacking and Hack The Box for hands-on skill development.</description><pubDate>Tue, 04 May 2021 00:00:00 GMT</pubDate><category>Hacking</category><category>HackTheBox</category></item><item><title>Securing Windows Server 2016 Exam Prep Guide (ish)</title><link>https://infernux.no/blog/securingwindowsserver/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver/</guid><description>A summary of the most important aspects from the 70-744 exam</description><pubDate>Tue, 04 May 2021 00:00:00 GMT</pubDate><category>Windows</category></item><item><title>Building a function</title><link>https://infernux.no/blog/automation-buildingafunction/</link><guid isPermaLink="true">https://infernux.no/blog/automation-buildingafunction/</guid><description>Learn PowerShell function structure, error handling patterns, and practical techniques for writing reusable automation scripts.</description><pubDate>Thu, 13 Jun 2019 00:00:00 GMT</pubDate><category>PowerShell</category></item><item><title>A quick intro to handlings errors with try and catch</title><link>https://infernux.no/blog/automation-errorhandling/</link><guid isPermaLink="true">https://infernux.no/blog/automation-errorhandling/</guid><description>Master PowerShell error handling with try, catch, and finally blocks to build more resilient automation.</description><pubDate>Thu, 21 Mar 2019 00:00:00 GMT</pubDate><category>PowerShell</category></item><item><title>Configure Windows Defender Firewall (part 2)</title><link>https://infernux.no/blog/securingwindowsserver32/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver32/</guid><description>Securing Windows Server - Chapter 3, Part 2</description><pubDate>Wed, 13 Mar 2019 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category><category>Infrastructure</category><category>Networking</category><category>Windows Defender Firewall</category><category>Software Defined Networking</category></item><item><title>Configure Windows Defender Firewall</title><link>https://infernux.no/blog/securingwindowsserver31/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver31/</guid><description>Securing Windows Server - Chapter 3, Part 1</description><pubDate>Fri, 22 Feb 2019 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category><category>Infrastructure</category><category>Networking</category><category>Windows Defender Firewall</category></item><item><title>Implement shielded and encryption supported VMs</title><link>https://infernux.no/blog/securingwindowsserver22/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver22/</guid><description>Securing Windows Server - Chapter 2, Part 2</description><pubDate>Wed, 09 Jan 2019 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category><category>Hyper-V</category></item><item><title>Implement a Guarded Fabric solution</title><link>https://infernux.no/blog/securingwindowsserver21/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver21/</guid><description>Securing Windows Server - Chapter 2, Part 1</description><pubDate>Mon, 12 Nov 2018 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category><category>Hyper-V</category></item><item><title>Protect credentials and create security baselines</title><link>https://infernux.no/blog/securingwindowsserver13/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver13/</guid><description>Securing Windows Server - Chapter 1, Part 3</description><pubDate>Thu, 01 Nov 2018 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category></item><item><title>Implement server patching, updating solutions and malware protection</title><link>https://infernux.no/blog/securingwindowsserver12/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver12/</guid><description>Securing Windows Server - Chapter 1, Part 2</description><pubDate>Sun, 28 Oct 2018 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category><category>Windows Update</category><category>WSUS</category></item><item><title>Disk and file encryption</title><link>https://infernux.no/blog/securingwindowsserver11/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver11/</guid><description>Securing Windows Server - Chapter 1, Part 1</description><pubDate>Mon, 22 Oct 2018 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category></item><item><title>Securing Windows Server (70-744) scripts</title><link>https://infernux.no/blog/securingwindowsserver01/</link><guid isPermaLink="true">https://infernux.no/blog/securingwindowsserver01/</guid><description>Windows Server 70-744 script notes and practical hardening snippets focused on reusable exam prep workflows.</description><pubDate>Tue, 18 Sep 2018 00:00:00 GMT</pubDate><category>PowerShell</category><category>Cyber Security</category><category>Windows</category></item><item><title>Reading SecureString credentials as cleartext</title><link>https://infernux.no/blog/security-getnetworkcredential/</link><guid isPermaLink="true">https://infernux.no/blog/security-getnetworkcredential/</guid><description>Technical note on SecureString limitations and how GetNetworkCredential can expose credentials as cleartext in scripts.</description><pubDate>Thu, 03 May 2018 00:00:00 GMT</pubDate><category>PowerShell</category><category>GetNetworkCredential</category></item></channel></rss>