Monitoring for DNS changes in Microsoft Sentinel
Using Azure logic apps to feed DNS record information into Sentinel
Cybersecurity and other technical wanderings
Using Azure logic apps to feed DNS record information into Sentinel
Using the Graph API to query Authentication Methods for Entra ID users
Recently, a Sentinel instance that I'm responsible for showed a significant decrease in the volume of firewall logs being ingested. This drop coincided with an upgrade to the firewall firmware version, so I assumed there may have been a change in what logs were being sent by the
When workstations and services are used in a language other than English, some changes to detection rules are required to ensure consistent coverage
Some Entra ID signins generate multiple signin logs, The cause of these is other events which causes Microsoft to re-evaluate risk scoring
For anyone not familiar with Canary Tokens - it's a free service offered by Thinkst which allows for the creation of various kinds of token that can be hidden in a environment ready to be tripped by an attacker. They also offer a commercial service where canaries are deployed
Using the Microsoft Graph API with Python to hunt down malicious inbox rules in Office365 mailboxes
Using HoneyDB and Suricata together with Azure Sentinel to analyse honeypot data and provide useful insights
I've been starting to use Azure Sentinel recently and explore some of its capabilities - there are currently about 40 built-in data-connectors that take logs from different services/products. I decided to see if I could add integrations with some open-source network tools and Zeek (formerly
The real-time information displays at Bus and Tram stops in Nottingham are really useful but for a while I've wanted to get this information before I leave the house/office. I've recently discovered the API which exposes this information and used it to build a
When you think about software for information security you probably think of NMAP, Mimikatz, maybe a SIEM or Burp. But I find I spend quite a lot of time taking data from various sources in varying formats and wanting to do some analysis, I'm no data scientist so
An easy to follow process guide can improve consistency and professionalism while collecting details and performing triage
I've recently taken (and passed) the CPSA exam and wanted to write up some thoughts and some guidance for others taking (or thinking about taking) the exam since there's not too much information out there about what it's like. I want to make it