Skip to content

Commit 8f9b244

Browse files
committed
Spring updates
1 parent f136e86 commit 8f9b244

10 files changed

Lines changed: 35 additions & 1 deletion

File tree

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
# Detection Engineering & Threat Hunting Resources
2+
3+
- [Detection Wiki](https://detection.wiki/)
4+
- [Why Security Events Are the Crown Jewels of Detection](https://www.linkedin.com/pulse/why-security-events-crown-jewels-detection-david-alonso-dominguez-jp5ve/)
5+
- [AD Security Events — Custom Detections Package](https://github.com/davidalonsod/Dalonso-Security-Repo/tree/main/Use%20Cases%20Threat%20Hunting/ADSecurityEvents)
6+
- [ClickOnce Abuse](https://detection.wiki/labs/clickonce-abuse/)

docs/entraid.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1856,6 +1856,7 @@
18561856
## Podcasts
18571857

18581858
- [Entra Chat](https://podcasts.apple.com/gb/podcast/entra-chat/id1801200012)
1859+
- [Finding Every MFA Gap: Testing 250 Million Conditional Access Combinations in Under 20 Minutes](https://entra.news/p/finding-every-mfa-gap-testing-250)
18591860

18601861
## Tools
18611862

@@ -1866,6 +1867,8 @@
18661867
- [Tier 0 Table](https://github.com/SpecterOps/TierZeroTable/)
18671868
- [https://www.entradocumentation.com/](https://www.entradocumentation.com/)
18681869
- [Conditional Access Documenter](https://idpowertoys.merill.net/ca)
1870+
- [CA Insight](https://github.com/emiliensocchi/entra-ca-insight)
1871+
- [EntraFalcon](https://github.com/CompassSecurity/EntraFalcon)
18691872

18701873
## EntraOps Classification and Automation
18711874

docs/learn.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@
3434
## Interactive Lab Simulations
3535

3636
- [SC-200 Interactive Lab Simulations - Microsoft Security Operations Analyst](https://mslabs.cloudguides.com/guides/SC-200%20Lab%20Simulations%20-%20Microsoft%20Security%20Operations%20Analyst)
37+
- [HackLab](https://github.com/csu-techhub/scenario-security-labs/tree/main)
3738

3839
## Entra
3940

@@ -52,3 +53,6 @@
5253

5354
- [Docs Tracker](https://docstracker.marshsecurity.org/)
5455

56+
## Azure
57+
58+
[Azure API Connections: A Red Team Deep Dive](https://azurehacking.com/post.html?slug=azure-api-connections-a-red-team-deep-dive)

docs/mdca.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,6 +34,7 @@
3434

3535
## Community Blogs
3636

37+
- [Stop Inforamtional Alerts generated by Defender for Cloud Apps](https://medium.com/@erik_lindeboom/stop-informational-alerts-generated-by-defender-for-cloud-apps-a36baca420db)
3738
- [Mastering Policies in Defender for Cloud Apps: A Deep Dive for the SOC Trenches](https://www.itprofessor.cloud/defender-for-cloud-apps-policy-management-deep-dive/)
3839
- [A SOC Analyst's Introduction to Defender for Cloud Apps](https://www.itprofessor.cloud/defender-for-cloud-apps-shadow-it-guide/)
3940
- [How to check for OAuth apps with specific Graph permissions assigned](https://jeffreyappel.nl/how-to-check-for-oauth-apps-with-specific-graph-permissions-assigned/)

docs/mdi.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77

88
## Microsoft Tech Community Blogs
99

10+
- [Redefining identity security for the modern enterprise](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/redefining-identity-security-for-the-modern-enterprise/4503129)
1011
- [Announcing General Availability: Unified identity and endpoint sensor](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-general-availability-unified-identity-and-endpoint-sensor/4463585)
1112
- [Monthly news - October 2025](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/monthly-news---october-2025/4458349)
1213
- [How Microsoft Defender helps security teams detect prompt injection attacks in Microsoft 365 Copilot](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/how-microsoft-defender-helps-security-teams-detect-prompt-injection-attacks-in-m/4457047)
@@ -86,4 +87,5 @@
8687

8788
## Documentation
8889

89-
- [Microsoft Defender for Identity sensor v3.x prerequisites (Preview)](https://learn.microsoft.com/en-us/defender-for-identity/deploy/prerequisites-sensor-version-3)
90+
- [Microsoft Defender for Identity sensor v3.x prerequisites (Preview)](https://learn.microsoft.com/en-us/defender-for-identity/deploy/prerequisites-sensor-version-3)
91+
- [TechExcel: Defender for Identity (level 300 / CSU) lab](https://microsoft.github.io/TechExcel-Defender-for-Identity/)

docs/mdti.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,6 +83,7 @@
8383
## GitHub
8484

8585
- [MDTI Solutions](https://github.com/Azure/MDTI-Solutions)
86+
- [REDHEBERG — MikroTik Botnet Threat Intelligence](https://github.com/wicked-design/REDHEBERG-botnet)
8687

8788
## Social Media
8889

docs/mdxdr.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,8 @@
99

1010
## Microsoft Tech Community Blogs
1111

12+
- [Security Copilot in Defender: empowering the SOC with assistive and autonomous AI](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/security-copilot-in-defender-empowering-the-soc-with-assistive-and-autonomous-ai/4503047)
13+
- [RSA 2026: What’s new in Microsoft Defender?](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/rsa-2026-what%E2%80%99s-new-in-microsoft-defender/4503046)
1214
- [From signal to strategy: Closing attack paths with identity intelligence](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/from-signal-to-strategy-closing-attack-paths-with-identity-intelligence/4491856)
1315
- [Security Copilot for SOC: bringing agentic AI to every defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/security-copilot-for-soc-bringing-agentic-ai-to-every-defender/4470187)
1416
- [Enhancing visibility into your identity fabric with Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/enhancing-visibility-into-your-identity-fabric-with-microsoft-defender/4470662)
@@ -110,6 +112,7 @@
110112

111113
## Community Blogs
112114

115+
- [Unlock Different Security Perspectives with Kusto Graph Functions](https://kqlquery.com/posts/kql-graph-security-visualization/)
113116
- [Defender XDR Unified Detections Meet Sentinel Data Lake](https://tech.nicolonsky.ch/defender-xdr-unified-detections-sentinel-data-lake/)
114117
- [Migrating Microsoft Sentinel to Microsoft Defender XDR](https://infernux.no/blog/migratingsentineltodefenderxdr/)
115118
- [The ultimate Defender XDR RBAC visualization](https://vertho.tech/2025/09/29/the-ultimate-defender-xdr-rbac-visualization/)

docs/securitycopilot.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,16 @@
77

88
## Microsoft Tech Community Blogs
99

10+
- [Security Copilot in Defender: empowering the SOC with assistive and autonomous AI](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/security-copilot-in-defender-empowering-the-soc-with-assistive-and-autonomous-ai/4503047)
11+
- [From alert overload to decisive action: How Security Copilot agents are transforming security and IT](https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213)
12+
- [Introducing Secret Finder: Finding Real Credentials Where Traditional Tools Fail](https://techcommunity.microsoft.com/blog/securitycopilotblog/introducing-secret-finder-finding-real-credentials-where-traditional-tools-fail/4500983)
13+
- [Where Partners Build and Scale: Partner-Built Security Copilot Agents in Security Store](https://techcommunity.microsoft.com/blog/securitycopilotblog/where-partners-build-and-scale-partner-built-security-copilot-agents-in-security/4488589)
14+
- [Redefining Cyber Defence with Microsoft Security Exposure Management (MSEM) and Security Copilot](https://techcommunity.microsoft.com/blog/securitycopilotblog/redefining-cyber-defence-with-microsoft-security-exposure-management-msem-and-se/4459280)
15+
- [From idea to Security Copilot agent: Create, customize, and deploy](https://techcommunity.microsoft.com/blog/securitycopilotblog/from-idea-to-security-copilot-agent-create-customize-and-deploy/4458516)
16+
- [Agentic security your way: Build your own Security Copilot agents](https://techcommunity.microsoft.com/blog/securitycopilotblog/agentic-security-your-way-build-your-own-security-copilot-agents/4454555)
17+
- [Supercharging Security Copilot with Logic Apps: Best practices and pro tips](https://techcommunity.microsoft.com/blog/securitycopilotblog/supercharging-security-copilot-with-logic-apps-best-practices-and-pro-tips/4456379)
18+
- [Smarter Prompts for Smarter Investigations: Dynamic Prompt Suggestions in Security Copilot](https://techcommunity.microsoft.com/blog/securitycopilotblog/smarter-prompts-for-smarter-investigations-dynamic-prompt-suggestions-in-securit/4432135)
19+
- [New tools for Security Copilot management and capacity planning](https://techcommunity.microsoft.com/blog/securitycopilotblog/new-tools-for-security-copilot-management-and-capacity-planning/4432723)
1020
- [Using parameterized functions with KQL-based custom plugins in Microsoft Security Copilot](https://techcommunity.microsoft.com/blog/securitycopilotblog/using-parameterized-functions-with-kql-based-custom-plugins-in-microsoft-securit/4419286)
1121
- [Automating Phishing Email Triage with Microsoft Security Copilot](https://techcommunity.microsoft.com/blog/securitycopilotblog/automating-phishing-email-triage-with-microsoft-security-copilot/4416559)
1222
- [Busting myths on Microsoft Security Copilot](https://techcommunity.microsoft.com/blog/securitycopilotblog/busting-myths-on-microsoft-security-copilot/4414844)
@@ -86,6 +96,7 @@
8696

8797
- [Microsoft Copilot For Security Community](https://github.com/Azure/Copilot-For-Security/)
8898
- [AI Red Teaming Playground Labs](https://github.com/microsoft/AI-Red-Teaming-Playground-Labs)
99+
- [Security Investigation Automation System](https://github.com/SCStelz/security-investigator)
89100

90101
## Learning & Training
91102

docs/sentinel.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -599,6 +599,7 @@
599599

600600
## Community Blogs
601601

602+
- [Microsoft Sentinel Log Baseline: Cost vs Detection Value](https://infernux.no/blog/buildingapracticallogbaseline/)
602603
- [Boost Your TI: Integrating Free AlienVault OTX IOCs into Microsoft Sentinel](https://medium.com/@benj_774/boost-your-ti-integrating-free-alienvault-otx-iocs-into-microsoft-sentinel-02d6a743ddb9)
603604
- [Sentinel Watchlists: A Diamond in the rough](https://medium.com/@benj_774/sentinel-watchlists-a-diamond-in-the-rough-16f214f24416)
604605
- [The KQL User Audit Playbook: Your Template for Investigations](https://www.itprofessor.cloud/kql-user-audit-playbook/)

mkdocs.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,8 @@ nav:
2323
- Microsoft Threat Intelligence: 'mdti.md'
2424
- Microsoft Azure Network Security: 'azurenetworksecurity.md'
2525
- Podcasts & Newsletters: 'podcasts.md'
26+
- Other Security Resources:
27+
- Detection Engineering & Threat Hunting: 'detectionengineering and ThreatHunting.md'
2628
- Social Media: 'social.md'
2729
- Webinars & Videos: 'videos.md'
2830
- Learning & Training: 'learn.md'

0 commit comments

Comments
 (0)