# Marcel Graewer > IT Security Manager, Autor von "Die neue Realität der Cybersecurity" und nebenberuflich selbständig mit MAGRA Security. Schwerpunkte: Security-Architektur, Incident Response und KI in der Cybersecurity. Zertifizierungen: CISSP, CompTIA CySA+, Microsoft SC-200 Security Operations Analyst, TÜV-zertifizierter Datenschutzbeauftragter und ITIL. Marcel Graewer ist außerdem IHK-Prüfer für Fachinformatiker und nebenberuflich selbständig mit MAGRA Security. ## Seiten - [Über mich](https://graewer.com/about/): Werdegang, Haltung, Zertifizierungen und öffentliche Community-Arbeit. - [Die neue Realität der Cybersecurity](https://graewer.com/book/): Künstliche Intelligenz in Security-Architecture und Incident Response. ISBN 978-3-695-70883-3. Mit Inhaltsverzeichnis und Leseprobe. - [Cybersecurity Blog](https://graewer.com/blog/): Englischsprachige technische Deep-Dives und Research-Artikel. - [Open-Source Security Tools & Projekte](https://graewer.com/projects/): WebSSH, DHCPulse, SecKit und weitere Security-Projekte. - [Kontakt](https://graewer.com/contact/): Persönliche und geschäftliche Kontaktwege. ## Artikel - [Building WebSSH: From Browser Terminal to Security-Focused SSH Workspace](https://graewer.com/blog/building-webssh/index.txt): How WebSSH grew from a browser terminal into a self-hosted SSH and SFTP workspace, with explicit trust boundaries and practical security controls. Published 2026-08-22. - [RoguePlanet: The Fourth Defender Zero-Day, and Why the Patch Is Not the End of It](https://graewer.com/blog/rogueplanet-defender-lpe/index.txt): How CVE-2026-50656 works, how to validate Defender engine coverage, and how blue teams can hunt for exploitation that happened before the fix. Published 2026-07-12. - [The Classic-Agent Blind Spot: Detecting Non-Human Identities in Microsoft Sentinel](https://graewer.com/blog/classic-ai-agents-sentinel-detection/index.txt): Two KQL detections for classic agents, service principals, and managed identities in Sentinel, including the diagnostic settings that make them work. Published 2026-06-17. - [Wiring Microsoft Security Exposure Management Into Sentinel - Triage with Asset Criticality and Attack-Path Context](https://graewer.com/blog/sentinel-msem-incident-enrichment/index.txt): How to enrich Microsoft Sentinel triage with MSEM asset criticality and attack-path context, including KQL patterns and entity-matching pitfalls. Published 2026-04-23. - [BlueHammer: A Defender's Perspective on the Unpatched Windows LPE](https://graewer.com/blog/bluehammer-windows-lpe/index.txt): A defender-focused analysis of the BlueHammer Windows LPE, its fragile exploit chain, practical detection paths, and mitigations for blue teams. Published 2026-04-07. - [From Azure Sentinel Log Analytics Workspace to Data Lake - Why Now Is the Right Time](https://graewer.com/blog/sentinel-data-lake-migration/index.txt): A practical migration guide for Microsoft Sentinel Data Lake, covering architecture, cost trade-offs, KQL patterns, and rollout pitfalls. Published 2026-04-04. - [LLM Hardening in Practice - What Actually Secures Agent Deployments](https://graewer.com/blog/llm-hardening/index.txt): Practical controls for securing LLM agents against prompt injection, data exfiltration, and tool abuse, based on real deployment hardening work. Published 2026-02-23. - [Building Heimdall - A Threat Intelligence MCP Server From Scratch](https://graewer.com/blog/building-heimdall/index.txt): How I built a FastMCP threat intelligence server that connects VirusTotal, AbuseIPDB, Shodan, and MITRE ATT&CK, including what broke along the way. Published 2025-03-15. ## Projekte - [WebSSH](https://github.com/bifrost0x/webssh): Self-hosted Web-SSH- und SFTP-Terminal für den Browser. Mehrere Server parallel, Dateitransfer per Drag and Drop und Bastion-Zugriff - ohne lokalen SSH-Client. - [DHCPulse](https://bifrost0x.github.io/dhcpulse/): Statischer, lokal im Browser arbeitender Workspace zur Analyse von DHCP-Konfigurationen und zur Vorbereitung sicherer Änderungen - ohne Backend oder Upload produktiver Infrastrukturdaten. - [SecKit](https://magra-sec.de/seckit/): Browserbasierter Generator für verbindliche IT-Sicherheits- und Datenschutzdokumente. Aus den eigenen Firmendaten, auf dem Rechtsstand Juli 2026 - in Stunden statt Wochen. - [heimdall](https://graewer.com/projects/): Threat Intelligence Toolset als FastMCP Server. Integriert VirusTotal, AbuseIPDB, Shodan, Hybrid Analysis und MITRE ATT&CK Mapping. Nutzbar als SOC-Analyst-Tool. - [detection-rules](https://graewer.com/projects/): Kuratierte Sammlung eigener Detection Rules im Sigma-Format. Praxiserprobt in produktiven SOC-Umgebungen, regelmäßig gegen MITRE ATT&CK gemappt. - [llm-sec-bench](https://graewer.com/projects/): Benchmark-Suite zur systematischen Evaluierung von LLM-basierten Security-Tools. Testet Detection-Qualität, Halluzinationsraten und Zuverlässigkeit im SOC-Alltag. ## Nebenberufliche Firma - [MAGRA Security](https://magra-sec.de/): Nebenberufliche Security-Beratung für den Mittelstand. ## Profile - [Microsoft Security Community Spotlight](https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsoft-security-community-spotlight-marcel-graewer/4523372): Öffentliches Porträt über Marcel Graewers Arbeit mit Microsoft Sentinel und Detection Engineering. - [LinkedIn](https://www.linkedin.com/in/mgraewer) - [GitHub](https://github.com/bifrost0x)