RSSAmplifier

Blog

Martin's Blog

Cybersecurity and other technical wanderings

blog.rothe.ukRSS feed ↗13 posts

Latest posts

Monitoring for DNS changes in Microsoft Sentinel

Using Azure logic apps to feed DNS record information into Sentinel

Monitoring Entra Auth Methods

Using the Graph API to query Authentication Methods for Entra ID users

The Mysterious Case of the Disappearing Logs

Recently, a Sentinel instance that I'm responsible for showed a significant decrease in the volume of firewall logs being ingested. This drop coincided with an upgrade to the firewall firmware version, so I assumed there may have been a change in what logs were being sent by the

Internationalizing SIEM Rules

When workstations and services are used in a language other than English, some changes to detection rules are required to ensure consistent coverage

Weird issues with Entra ID Signin Logs

Some Entra ID signins generate multiple signin logs, The cause of these is other events which causes Microsoft to re-evaluate risk scoring

Integrating Canary Tokens with Microsoft Sentinel

For anyone not familiar with Canary Tokens - it's a free service offered by Thinkst which allows for the creation of various kinds of token that can be hidden in a environment ready to be tripped by an attacker. They also offer a commercial service where canaries are deployed

Hunting for Risky Rules in Office 365

Using the Microsoft Graph API with Python to hunt down malicious inbox rules in Office365 mailboxes

Analyzing Honeypot Data with Sentinel

Using HoneyDB and Suricata together with Azure Sentinel to analyse honeypot data and provide useful insights

Network IDS & Azure Sentinel

I've been starting to use Azure Sentinel recently and explore some of its capabilities - there are currently about 40 built-in data-connectors that take logs from different services/products. I decided to see if I could add integrations with some open-source network tools and Zeek (formerly

Building a Tram-Time Display with AWS Lambda

The real-time information displays at Bus and Tram stops in Nottingham are really useful but for a while I've wanted to get this information before I leave the house/office. I've recently discovered the API which exposes this information and used it to build a

Excel for Infosec

When you think about software for information security you probably think of NMAP, Mimikatz, maybe a SIEM or Burp. But I find I spend quite a lot of time taking data from various sources in varying formats and wanting to do some analysis, I'm no data scientist so

Process Guide - A tool for generating HTML process walkthrough guides using Microsoft Excel

An easy to follow process guide can improve consistency and professionalism while collecting details and performing triage

Taking the CPSA (Crest Practitioner Security Analyst) Exam

I've recently taken (and passed) the CPSA exam and wanted to write up some thoughts and some guidance for others taking (or thinking about taking) the exam since there's not too much information out there about what it's like. I want to make it