3 min read
Practical KQL query patterns for uncovering anomalous authentication, privilege escalation, and lateral movement in Microsoft Sentinel SIEM.
Microsoft SentinelKQLThreat HuntingSOCSIEM
Technical writeups, threat hunting guides, detection engineering analysis, and cloud infrastructure architectures.
Practical KQL query patterns for uncovering anomalous authentication, privilege escalation, and lateral movement in Microsoft Sentinel SIEM.
A deep dive into implementing zero-trust principles in cloud environments: mutual TLS, workload identity federation, and dynamic authorization policies.
A practical guide to securing GitHub Actions workflows: OIDC token authentication, pinned SHAs, least-privilege permissions, and secret management.