Bartosz Wysocki

Microsoft Sentinel on a Shoestring: What You Can Actually Do with Business Premium

All right class You have Entra ID P1 and Business

Why KQL Enrichment Actually Works (And Why Your Alerts Are So Much Better With It)

All right class. You run an analytic rule. It fires

Data Connectors: The Order That Actually Matters

All right class I've seen people enable data

Sentinel Deployment Checklist: What You Actually Need Before Day One

All right class. This is the pre-deployment checklist for

User Audit Investigation Workbook: Deploy in Minutes, Investigate in Seconds

All right class. This is the workbook I wish people

KQL User Audit Playbook V2: The Insider Threat Investigation Guide

All right class. This is a continuation of my previous

Teams Threat Protection: What Actually Changed and What You Can Actually Hunt

All right class Your SOC has limited visibility into Teams.

Threat Analytics in Microsoft Defender: What It Actually Does and Why Your SOC Needs It

All right class. You're doing your SOC investigations

Hunting in Microsoft Sentinel: What Hunting Actually Is and Why You Need It

Terminology matters here. Microsoft uses these words in specific ways,

Three Essential Sentinel Workbooks You Should Deploy Right Now

All right class. Workbooks That Actually Solve Problems Microsoft has
Consent Preferences