© 2026 Hashnode
https://github.com/Kajal-Dhanjal/sentinel-detection-lab Part 4 ended on this note: moving off the endpoint entirely and into identity, starting with attackers registering their own MFA methods on com

https://github.com/Kajal-Dhanjal/sentinel-detection-lab This is Part 4 of the series where I build a Microsoft Sentinel detection engineering lab from scratch and write down what actually happened —

Part 1 of a series on building a detection engineering lab in Microsoft Sentinel from scratch. This post: writing my first detection, and the parsing bug that taught me more than the detection itself.

This write-up came a little later than expected. The initial version of the Microsoft Sentinel environment was quite difficult to access, and it slowed down a lot of the hands-on progress. Thankfully, TryHackMe updated the Azure access, making everyt...

Microsoft has reached an agreement to provide discounted cloud services to U.S. federal agencies, the General Services Administration (GSA) announced Tuesday. The deal is part of a broader initiative by the administration to streamline technology pro...

Overview. DNS record manipulation is a subtle yet powerful technique often used by threat actors to intercept communication, reroute authentication flows, or disrupt services. Despite its impact, DNS change monitoring is often overlooked in security ...

Section 1: Cisco Umbrella Identity Federation Configuration. Introduction. Cisco Umbrella is a cloud-delivered security platform that provides DNS-layer protection, secure web gateway (SWG), cloud-delivered firewall, and cloud access security broker ...
