Skip to content

Commit 41c18f3

Browse files
committed
Updates September 10
1 parent 204dab2 commit 41c18f3

6 files changed

Lines changed: 35 additions & 3 deletions

File tree

docs/entraid.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1761,6 +1761,7 @@
17611761

17621762
## Community Blogs
17631763

1764+
- [Entra: Retrieve Entra Connect Version Information](https://www.french365connection.co.uk/post/entra-retrieve-entra-connect-version-information)
17641765
- [How to Secure Redirect URIs in Microsoft Entra ID Applications](https://ourcloudnetwork.com/how-to-secure-redirect-uris-in-microsoft-entra-id-applications/)
17651766
- [What is Tier Zero — Part 1](https://posts.specterops.io/what-is-tier-zero-part-1-e0da9b7cdfca)
17661767
- [What is Tier Zero — Part 2](https://posts.specterops.io/what-is-tier-zero-part-2-6e1d14fddcaf)
@@ -1838,6 +1839,7 @@
18381839
- [Conditional access Baseline](https://github.com/j0eyv/ConditionalAccessBaseline)
18391840
- [Microsoft Zero Trust Assessment V2 - Private Preview](https://github.com/microsoft/zerotrustassessment/blob/psnext/src/powershell/doc/readme.md)
18401841
- [Microsoft Zero Trust Assessment Code](https://github.com/microsoft/zerotrustassessment/tree/psnext/src/powershell)
1842+
- [Hunt domains with Seamless SSO enabled in Entra ID Connect](https://github.com/HybridBrothers/Hunting-Queries-Detection-Rules/blob/main/Entra%20ID/HuntDomainsWithSeamlessSsoEnabled.md)
18411843

18421844
## Podcasts
18431845

docs/learn.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,9 +8,11 @@
88
- [Zero Trust Lab](https://microsoft.github.io/ztlabguide/)
99
- [Zero Trust Workshop: Advance your knowledge with an online resource](https://www.microsoft.com/en-us/security/blog/2024/11/06/zero-trust-workshop-advance-your-knowledge-with-an-online-resource/)
1010
- [Microsoft Security enablement Hub](https://adoption.microsoft.com/en-us/microsoft-security/)
11+
- [Microsoft Defender Experts: S.T.A.R.](https://www.youtube.com/playlist?app=desktop&list=PLmAptfqzxVEXNqF--ySIIb5Kl4AdDv2Ud)
1112

1213
## Ninja Trainings
1314

15+
- [Microsoft Security Exposure Management Ninja Training](https://techcommunity.microsoft.com/blog/securityexposuremanagement/microsoft-security-exposure-management-ninja-training/4444285)
1416
- [Welcome to the Microsoft Incident Response Ninja Hub](https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/welcome-to-the-microsoft-incident-response-ninja-hub/ba-p/4243594)
1517
- [Microsoft Sentinel & Defender XDR Virtual Ninja Training](https://adoption.microsoft.com/en-us/ninja-show/)
1618
- [Train your security staff for Microsoft Defender XDR](https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender-train-security-staff)

docs/mde.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -260,6 +260,7 @@
260260

261261
## Community Blogs
262262

263+
- [IoC's in Defender for Endpoint](https://www.indefent.com/iocs-in-defender-for-endpoint/)
263264
- [Isolation Exclusion Rules: Fixing Microsoft Teams & Outlook Communication During Isolation](https://www.lousec.be/mde/isolation-exclusion-rules-fixing-microsoft-teams-outlook-communication-during-isolation/)
264265
- [Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way Using Microsoft Defender for Endpoint](https://academy.bluraven.io/blog/detecting-vulnerable-drivers-using-defender-for-endpoint-kql)
265266
- [The Hitchhiker's Guide to Microsoft Defender for Endpoint exclusions](https://cloudbrothers.info/guide-to-defender-exclusions/)
@@ -355,3 +356,4 @@
355356
- [Nuke It From Orbit](https://github.com/lkarlslund/nifo)
356357
- [MDE Troubleshooter](https://github.com/ThomasVrhydn/MDE-troubleshooter)
357358
- [Powershell Digital Forensics & Incident Response](https://github.com/Bert-JanP/Incident-Response-Powershell)
359+
- [Defender for Endpoint docs](https://github.com/MicrosoftDocs/defender-docs/tree/public/defender-endpoint)

docs/mdti.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -83,8 +83,7 @@
8383

8484
- [Microsoft Threat Intelligence](https://twitter.com/MsftSecIntel)
8585

86-
## Podcasts
86+
## Podcasts & Videos
8787

8888
- [Microsoft Threat Intelligence Podcast](https://open.spotify.com/show/7kaJodHquryFw5YDw0BShj?go=1&sp_cid=55270d6ee6b7c69aedade84e89d3152c&utm_source=embed_player_p&utm_medium=desktop&nd=1&dlsi=359a6a1f2bf54850)
89-
90-
89+
- [MDTI Convergence into Sentinel & Defender XDR, Overview & Phase 1](https://www.youtube.com/watch?v=_MbK-O2Qd7Q)

docs/mdxdr.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,16 @@
99

1010
## Microsoft Tech Community Blogs
1111

12+
- [Protect Copilot Studio AI Agents in Real Time with Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/protect-copilot-studio-ai-agents-in-real-time-with-microsoft-defender/4446560)
13+
- [Protect against OAuth Attacks in Salesforce with Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/protect-against-oauth-attacks-in-salesforce-with-microsoft-defender/4450584)
14+
- [Custom detection rules get a boost—explore what’s new in Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/custom-detection-rules-get-a-boost%E2%80%94explore-what%E2%80%99s-new-in-microsoft-defender/4443602)
15+
- [Leaving the key under the doormat: How Microsoft Defender uses AI to spot exposed credentials](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/leaving-the-key-under-the-doormat-how-microsoft-defender-uses-ai-to-spot-exposed/4439870)
16+
- [Announcing Public Preview: Phishing Triage Agent in Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-public-preview-phishing-triage-agent-in-microsoft-defender/4438301)
17+
- [Discover risks in AI model providers and MCP servers with Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/discover-risks-in-ai-model-providers-and-mcp-servers-with-microsoft-defender/4440050)
18+
- [Microsoft Sentinel’s New Data Lake: Cut Costs & Boost Threat Detection](https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsoft-sentinel%E2%80%99s-new-data-lake-cut-costs--boost-threat-detection/4445281)
19+
- [Microsoft Sentinel data lake pricing (preview)](https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsoft-sentinel-data-lake-pricing-preview/4433919)
20+
- [Introducing Microsoft Sentinel data lake](https://techcommunity.microsoft.com/blog/microsoft-security-blog/introducing-microsoft-sentinel-data-lake/4434280)
21+
- [Discover and govern ChatGPT and other AI apps accessing Microsoft 365 with Defender for Cloud Apps](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/discover-and-govern-chatgpt-and-other-ai-apps-accessing-microsoft-365-with-defen/4433435)
1222
- [Case management now supports multiple tenants in Microsoft Defender experience](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/case-management-now-supports-multiple-tenants-in-microsoft-defender-experience/4425329)
1323
- [Introducing TITAN-Powered Recommendations in Security Copilot Guided Response](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/introducing-titan-powered-recommendations-in-security-copilot-guided-response/4416350)
1424
- [From on-premises to cloud: Graph-powered detection of hybrid attacks with Microsoft exposure graph](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/from-on-premises-to-cloud-graph-powered-detection-of-hybrid-attacks-with-microso/4416295)
@@ -93,6 +103,8 @@
93103

94104
## Community Blogs
95105

106+
- [Detect security policy changes](https://www.lousec.be/ad/detect-security-policy-changes/)
107+
- [Windows Defender: Threat Hunting Campaign Ideas](https://www.linkedin.com/pulse/windows-defender-threat-hunting-campaign-ideas-adair-collins-lefze/)
96108
- [Microsoft Defender: Detecting Bumblebee Malware](https://www.linkedin.com/pulse/microsoft-defender-detecting-bumblebee-malware-adair-collins-dqc1e/)
97109
- [Microsoft Defender: Hunting ScreenConnect](https://www.linkedin.com/pulse/microsoft-defender-hunting-screenconnect-adair-collins-hq3xe/)
98110
- [Insights from the trenches: building audit capacity for Microsoft Sentinel & Defender XDR](https://www.michalos.net/2025/06/20/insights-from-the-trenches-building-audit-capacity-for-microsoft-sentinel-defender-xdr/)
@@ -117,6 +129,7 @@
117129
- [Details and results of an automatic attack disruption action](https://learn.microsoft.com/en-us/defender-xdr/autoad-results#hunt-for-disable-user-account-actions)
118130
- [How Microsoft names threat actors](https://learn.microsoft.com/en-gb/unified-secops-platform/microsoft-threat-actor-naming)
119131
- [Defender Setup Guides](https://setup.cloud.microsoft/defender)
132+
- [Modern Security Operations](https://securitypartners.transform.microsoft.com/modern-security-operations)
120133

121134
## Other Sources
122135

@@ -127,3 +140,9 @@
127140

128141
- [Microsoft Defender for Endpoint - demonstration scenarios](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-demonstrations)
129142
- [Attack surface reduction rules demonstrations](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-demonstration-attack-surface-reduction-rules#test-files)
143+
144+
## Monthly News
145+
146+
- [Monthly news - September 2025](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/monthly-news---september-2025/4450292)
147+
- [Monthly news - August 2025](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/monthly-news---august-2025/4441024)
148+
- [Monthly news - July 2025](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/monthly-news---july-2025/4428862)

docs/sentinel.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,14 @@
88

99
## Microsoft Tech Community Blogs
1010

11+
- [Microsoft Sentinel’s AI-driven UEBA ushers in the next era of behavioral analytics](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel%E2%80%99s-ai-driven-ueba-ushers-in-the-next-era-of-behavioral-analyti/4448390)
12+
- [How to: Ingest Splunk alert data to Microsoft Sentinel SIEM](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/how-to-ingest-splunk-alert-data-to-microsoft-sentinel-siem/4449027)
13+
- [Table Talk: Sentinel’s New ThreatIntel Tables Explained](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/table-talk-sentinel%E2%80%99s-new-threatintel-tables-explained/4440273)
14+
- [Automating Microsoft Sentinel: Playbook Fundamentals](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/automating-microsoft-sentinel-playbook-fundamentals/4424475)
15+
- [Automating Watchlists in Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/automating-watchlists-in-microsoft-sentinel/4432054)
16+
- [Planning your move to Microsoft Defender portal for all Microsoft Sentinel customers](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/planning-your-move-to-microsoft-defender-portal-for-all-microsoft-sentinel-custo/4432055)
17+
- [Introducing Summary Rules Templates: Streamlining Data Aggregation in Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/introducing-summary-rules-templates-streamlining-data-aggregation-in-microsoft-s/4428779)
18+
- [Manage cases from across tenants in one place](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/manage-cases-from-across-tenants-in-one-place/4425326)
1119
- [Microsoft Sentinel: Repositories, the Future of Content-as-Code & Best Practices​](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel-repositories-the-future-of-content-as-code--best-practices%E2%80%8B/4422936)
1220
- [Exciting Announcements: New Data Connectors Released Using the Codeless Connector Framework](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/exciting-announcements-new-data-connectors-released-using-the-codeless-connector/4421104)
1321
- [Multi-workspace for Multi-tenant is now in Public Preview in Microsoft's Unified SecOps Platform](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/multi-workspace-for-multi-tenant-is-now-in-public-preview-in-microsofts-unified-/4398229)

0 commit comments

Comments
 (0)