KQL

Finding password.txt Before Someone Else Does

Alright class. Somewhere in your tenant right now there is

Fixing the "Mass Secret Retrieval from Azure Key Vault" Analytic Rule

Alright class. This time let's take a trip

Fixing the "Rare Application Consent" Analytic Rule

Alright class. Back in the Entra audit log for this

Fixing the "Account Created From Non-Approved Sources" Analytic Rule

Alright class. A companion piece to the last lesson, from

Fixing the "Account Created or Deleted by Non-Approved User" Analytic Rule

Alright class. This one comes from the Entra ID audit

Fixing the "Account Created and Deleted in Short Timeframe" Analytic Rule

Alright class. Today it is "Account Created and Deleted

Why Abandoned Resources Are a Security Problem, Not Just a Billing One

Everything here is built on the work of Dolev Shor.

Advanced Hunting Just Got a Lot More Powerful. You Can Now Act on What You Find.

All right class Hunting was always "find bad things

Building Your First Threat Hunting Hypothesis (The MITRE Way)

All right class. Lots of SOC teams say they do

Azure Key Vault: The High-Value Queries Your SOC Isn't Running

All right class. Key Vault is where your secrets live.
Consent Preferences