Recent Blogs
My name is Ron Arestia, and I am a Security Researcher with Microsoft’s Detection and Response Team (DART). We respond to customer cybersecurity incidents to assist with containment and recovery from...
Feb 08, 2026275Views
2likes
1Comment
Why TLS 1.3 matters
TLS (Transport Layer Security) is the protocol that encrypts traffic between clients and servers.
For many years, most SQL Server environments have relied on TLS 1.2, which d...
Feb 02, 2026379Views
1like
0Comments
4 MIN READ
This article describes a simple, yet effective solution for the problem of segregating Microsoft Defender XDR and Entra ID Sentinel logs ingestion in a single-tenant with multiple companies scenario,...
Jan 30, 20261.4KViews
4likes
1Comment
AI agents are rapidly becoming part of everyday enterprise operations summarizing incidents, analyzing logs, orchestrating workflows, or even acting as digital colleagues. As organizations adopt thes...
Jan 27, 20261.4KViews
1like
0Comments
3 MIN READ
1. Introduction
In modern Security Operations Centers (SOCs), mapping detections to the MITRE ATT&CK framework is critical. MITRE ATT&CK provides a structured, globally recognized model of adve...
Jan 26, 2026333Views
0likes
0Comments
What problem is this trying to solve?
Many security issues in applications come from the database layer: poorly written queries, dynamic SQL, or code that exposes more data than it should. These pr...
Jan 26, 2026253Views
0likes
0Comments
There are certain instances when a machine or machines are offboarded that the corresponding status takes an unusual amount of time to report in the Defender portal.
The status that is shown in the...
Jan 21, 2026370Views
0likes
0Comments
6 MIN READ
Hi All,
In this article, you can find a way to retrieve database permission from all your onboarded databases through Azure Arc. This idea is born from a customer request around maintaining a stand...
Jan 20, 2026434Views
3likes
1Comment
Hi All. Jerry Devore back again to continue talking about hardening Active Directory. This time I want to discuss disabling NTLM or more likely how to minimize its use in a domain until all depende...
Jan 14, 202611KViews
10likes
5Comments
There are certain instances when a machine or machines are offboarded that the corresponding status takes an unusual amount of time to report in the Defender portal.
The status that is shown in the...
Jan 08, 2026761Views
0likes
0Comments
Resources
Tags
- ChrisWeaver224 Topics
- SteveRachui208 Topics
- RonGrzywacz157 Topics
- AnthonyMarsiglia79 Topics
- Michael Hildebrand66 Topics
- MarkMorow59 Topics
- BrandonWilson53 Topics
- CarstenKinder50 Topics
- CTO44 Topics
- JenniferRoss41 Topics