2026
-

Thunderstruck in Microsoft Defender XDR
This article builds a controlled Microsoft Defender XDR hunt that correlates process and network telemetry, creates a reusable filtered data set, assigns a transparent risk score, and identifies unusual scripting volume. The AC/DC theme stays light; the technical work does not. Bringing a couple of my own passions for metal & KQL together! Join me…
-

Azure Updates – Number 143 – August 8, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.
-

Saturday Heat – Bonus Walkthrough!
There is too much heat this week for me. I took the opportunity to try & find some distraction for you too! In this Saturday bonus article, we will build several practical security queries progressively. We will begin by reviewing raw Microsoft Entra sign-in data, add filters, summarize the results, extract values from dynamic fields,…
-

Protect Azure API Management APIs with Microsoft Defender for APIs
APIs often expose business logic directly to users, partners, mobile apps, and automation. When an API lacks authentication, exposes sensitive data, or carries unused legacy routes, the risk is not just infrastructure exposure; it is application behavior exposed through a managed gateway.
-

Azure Updates – Number 142 – July 25, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.
-

Azure Updates – Number 141 – July 11, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.
-

Deploy Microsoft Defender for Storage with Malware Scanning and Sensitive Data Threat Detection
Azure Storage often becomes the handoff point for partners, applications, automation jobs, exports, and user-generated files. That makes it a high-value security boundary: a malicious upload, exposed blob container, or unusual access pattern can turn a simple storage account into an incident source.
-

Azure Updates – Number 140 – June 27, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.
-

Microsoft Sentinel Baseline Deployment: From Zero to Operational SOC – Summer Bonus!
Microsoft Sentinel is powerful—but it can’t manage itself. Manual operations like onboarding data connectors, validating ingestion, monitoring workspace health, and auditing configuration changes quickly become a burden. This bonus article walks through building automation around your Sentinel foundations, so you can: Keep your workspaces healthy Ensure configuration compliance Alert on critical changes Free SOC engineers…
-

Azure Updates – Number 139 – June 13, 2026
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.