AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

secops

  • Find Failed Create Operations in Azure using KQL

    Find Failed Create Operations in Azure using KQL

    Today, we embark on a thrilling quest through the Azure cosmos to uncover the secrets of failed create operations using Kusto Query Language (KQL). This quick post will equip you with the knowledge to track down those elusive “create” mishaps and help find clues behind these operations quickly.

    Read article

  • Unveil Delete Operations in Azure using KQL

    Unveil Delete Operations in Azure using KQL

    In this blog post, we’ll explore how to wield the mighty KQL to uncover those elusive “delete” actions within your Azure environment. Whether you’re a seasoned cloud explorer or just dipping your toes into the Azure waters, this guide will equip you with the knowledge to track down those vanishing resources.

    Read article

  • Incident Response Foundations – Identity

    Incident Response Foundations – Identity

    In today’s post I talk about responding to a compromised identity in Microsoft Entra ID. There is a lot of advice floating around on what to do and how to respond; I’m bringing experiences and existing guidelines together to provide a solid foundational starting point for identity based incident response in this post.

    Read article