Blog

Blog

Cybersecurity Insights, Incident Write-ups, Tooling Deep-Dives und Erfahrungen aus dem operativen Betrieb.

The Classic-Agent Blind Spot: Detecting Non-Human Identities in Microsoft Sentinel

Microsoft Entra Agent ID secures the agents you build tomorrow. The service principals and managed identities you already run - the classic agents - are a different story. Two KQL detections, the diagnostic switch nobody flips, and what to do this week.

Weiterlesen : The Classic-Agent Blind Spot: Detecting Non-Human Identities in Microsoft Sentinel

Wiring Microsoft Security Exposure Management Into Sentinel - Triage with Asset Criticality and Attack-Path Context

MSEM gives Sentinel something it never had: asset criticality and attack-path context per entity. Architecture, KQL patterns for incident enrichment, and the entity-matching pitfalls that quietly break them.

Weiterlesen : Wiring Microsoft Security Exposure Management Into Sentinel - Triage with Asset Criticality and Attack-Path Context