Skip to content

Commit a3c1cff

Browse files
committed
October Updates
1 parent 41c18f3 commit a3c1cff

9 files changed

Lines changed: 38 additions & 0 deletions

File tree

docs/entraid.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1761,6 +1761,9 @@
17611761

17621762
## Community Blogs
17631763

1764+
- [Detect threats using GraphAPIAuditEvents - Part 3](https://cloudbrothers.info/detect-threats-graphapiauditevents-part-3/)
1765+
- [Detect threats using Microsoft Graph activity logs - Part 2](https://cloudbrothers.info/detect-threats-microsoft-graph-logs-part-2/)
1766+
- [Detect threats using Microsoft Graph activity logs - Part 1](https://cloudbrothers.info/detect-threats-microsoft-graph-logs-part-1/)
17641767
- [Entra: Retrieve Entra Connect Version Information](https://www.french365connection.co.uk/post/entra-retrieve-entra-connect-version-information)
17651768
- [How to Secure Redirect URIs in Microsoft Entra ID Applications](https://ourcloudnetwork.com/how-to-secure-redirect-uris-in-microsoft-entra-id-applications/)
17661769
- [What is Tier Zero — Part 1](https://posts.specterops.io/what-is-tier-zero-part-1-e0da9b7cdfca)

docs/learn.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,12 @@
3838
## Entra
3939

4040
- [Microsoft Entra Suite: Comprehensive Zero Trust user access at your fingertips](https://www.youtube.com/watch?v=olAqPx7CTcM&list=PLmAptfqzxVEXzNRk276m5ssJk4YOM1H3w)
41+
- [Microsoft Entra Suite](https://www.youtube.com/watch?v=olAqPx7CTcM&list=PLmAptfqzxVEXzNRk276m5ssJk4YOM1H3w)
4142

4243
## Microsoft Cybersecurity Architect (SC-100)
4344

4445
- [Video Training](https://www.youtube.com/playlist?list=PLahhVEj9XNTfRZMathQ5fn1akTwV7R3w_)
46+
47+
## Tools
48+
49+
- [Docs Tracker](https://docstracker.marshsecurity.org/)

docs/mdc.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,10 @@
88

99
## Microsoft Tech Community Blogs
1010

11+
- [Securing GenAI Workloads in Azure: A Complete Guide to Monitoring and Threat Protection - AIO11Y](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/securing-genai-workloads-in-azure-a-complete-guide-to-monitoring-and-threat-prot/4463145)
12+
- [Secure AI by Design Series: Embedding Security and Governance Across the AI Lifecycle](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/secure-ai-by-design-series-embedding-security-and-governance-across-the-ai-lifec/4457200)
13+
- [Defender for Storage: Malware Automated Remediation - From Security to Protection](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/defender-for-storage-malware-automated-remediation---from-security-to-protection/4457040)
14+
- [Automated Remediation for Malware Detection - Defender for Storage](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/automated-remediation-for-malware-detection---defender-for-storage/4454641)
1115
- [New feature in Defender for Storage: Optional Index Tags](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/new-feature-in-defender-for-storage-optional-index-tags/4427987)
1216
- [Optimizing Resource Allocation with Microsoft Defender CSPM](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/optimizing-resource-allocation-with-microsoft-defender-cspm/4427785)
1317
- [Microsoft Named a Leader in the IDC MarketScape for CNAPP: Key Takeaways for Security Buyers](https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/microsoft-named-a-leader-in-the-idc-marketscape-for-cnapp-key-takeaways-for-secu/4427071)

docs/mde.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,9 @@
1212

1313
## Microsoft Tech Community Blogs
1414

15+
- [End of Windows 10 Support: What Defender Customers Need to Know](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/end-of-windows-10-support-what-defender-customers-need-to-know/4461349)
16+
- [Multi-tenant endpoint security policies distribution is now in Public Preview](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/multi-tenant-endpoint-security-policies-distribution-is-now-in-public-preview/4439929)
17+
- [Maintain connectivity for essential services with selective network isolation](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/maintain-connectivity-for-essential-services-with-selective-network-isolation/4422938)
1518
- [Behavior monitoring is now generally available for Microsoft Defender for Endpoint on macOS](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/behavior-monitoring-is-now-generally-available-for-microsoft-defender-for-endpoi/4415697)
1619
- [Manage global exclusion policies for Linux across both AV and EDR](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/manage-global-exclusion-policies-for-linux-across-both-av-and-edr/4420127)
1720
- [Discover how automatic attack disruption protects critical assets while ensuring business continuity](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/discover-how-automatic-attack-disruption-protects-critical-assets-while-ensuring/4416597)
@@ -260,6 +263,10 @@
260263

261264
## Community Blogs
262265

266+
- [Tracking a device’s IP assignments with MDE’s DeviceNetworkInfo table](https://medium.com/@cybureauocracy/tracking-a-devices-ip-assignments-with-mde-s-devicenetworkinfo-table-430270ca539e)
267+
- [MDE’s DeviceNetworkEvents table [Part 2 — Connection* ActionTypes]](https://medium.com/@cybureauocracy/mdes-devicenetworkevents-table-part-2-connection-actiontypes-1c5ee20d2fc4)
268+
- [Understanding MDE’s DeviceNetworkEvents table for SOC analysts [Part 1 — Overview]](https://medium.com/@cybureauocracy/mdes-devicenetworkevents-table-for-soc-analysts-part-1-overview-094ca99b50c9)
269+
- [P5: Live Response in MDE](https://secureazcloud.com/microsoft-security/f/p5-live-response-in-mde?blogcategory=DEFENDER+FOR+ENDPOINT)
263270
- [IoC's in Defender for Endpoint](https://www.indefent.com/iocs-in-defender-for-endpoint/)
264271
- [Isolation Exclusion Rules: Fixing Microsoft Teams & Outlook Communication During Isolation](https://www.lousec.be/mde/isolation-exclusion-rules-fixing-microsoft-teams-outlook-communication-during-isolation/)
265272
- [Detecting Vulnerable Drivers (a.k.a. LOLDrivers) the Right Way Using Microsoft Defender for Endpoint](https://academy.bluraven.io/blog/detecting-vulnerable-drivers-using-defender-for-endpoint-kql)
@@ -357,3 +364,4 @@
357364
- [MDE Troubleshooter](https://github.com/ThomasVrhydn/MDE-troubleshooter)
358365
- [Powershell Digital Forensics & Incident Response](https://github.com/Bert-JanP/Incident-Response-Powershell)
359366
- [Defender for Endpoint docs](https://github.com/MicrosoftDocs/defender-docs/tree/public/defender-endpoint)
367+
- [Microsoft Vulnerable Driver Block Lists](https://github.com/Cyb3r-Monk/Microsoft-Vulnerable-Driver-Block-Lists)

docs/mdi.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,9 @@
77

88
## Microsoft Tech Community Blogs
99

10+
- [Monthly news - October 2025](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/monthly-news---october-2025/4458349)
11+
- [How Microsoft Defender helps security teams detect prompt injection attacks in Microsoft 365 Copilot](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/how-microsoft-defender-helps-security-teams-detect-prompt-injection-attacks-in-m/4457047)
12+
- [Announcing General Availability: Unified identity and endpoint sensor](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/announcing-general-availability-unified-identity-and-endpoint-sensor/4463585)
1013
- [Scope Identity Protection with Defender for Identity](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/new-scope-identity-protection-with-defender-for-identity/4422968)
1114
- [Microsoft Defender for Identity has announced the public preview of a new service account discovery module that automatically identifies and classifies service accounts in Active Directory](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/discover-and-protect-service-accounts-with-microsoft-defender-for-identity/4395347)
1215
- [Expanding the Identity perimeter: the rise of non-human identities](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/expanding-the-identity-perimeter-the-rise-of-non-human-identities/4418953)

docs/mdo.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,9 @@
77

88
## Microsoft Tech Community Blogs
99

10+
- [Microsoft Defender for Office 365: Migration & Onboarding](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/microsoft-defender-for-office-365-migration--onboarding/4462906)
11+
- [Protection against multi-modal attacks with Microsoft Defender](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/protection-against-multi-modal-attacks-with-microsoft-defender/4438786)
12+
- [Submissions Response Using AI for Enhanced Result Explainability](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/submissions-response-using-ai-for-enhanced-result-explainability/4423843)
1013
- [Protection Against Email Bombs with Microsoft Defender for Office 365](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/protection-against-email-bombs-with-microsoft-defender-for-office-365/4418048)
1114
- [Introducing the Microsoft Defender for Office 365 ICES vendor ecosystem](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/introducing-the-microsoft-defender-for-office-365-ices-vendor-ecosystem/4424817)
1215
- [Auto-Remediation of Malicious Messages in Automated Investigation and Response (AIR) is GA](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/auto-remediation-of-malicious-messages-in-automated-investigation-and-response-a/4418047?previewMessage=true)

docs/mdxdr.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,7 @@
103103

104104
## Community Blogs
105105

106+
- [Remove old or orphaned Sentinels from the XDR Streaming API](https://cloudbrothers.info/remove-orphaned-sentinels-xdr-streaming-api/)
106107
- [Detect security policy changes](https://www.lousec.be/ad/detect-security-policy-changes/)
107108
- [Windows Defender: Threat Hunting Campaign Ideas](https://www.linkedin.com/pulse/windows-defender-threat-hunting-campaign-ideas-adair-collins-lefze/)
108109
- [Microsoft Defender: Detecting Bumblebee Malware](https://www.linkedin.com/pulse/microsoft-defender-detecting-bumblebee-malware-adair-collins-dqc1e/)
@@ -135,6 +136,7 @@
135136

136137
- [EDR Telemetry](https://www.edr-telemetry.com/index.html)
137138
- [GraphWeaver: Billion-Scale Cybersecurity Incident Correlation](https://arxiv.org/abs/2406.01842)
139+
- [(Microsoft XDR table schema](https://xdrinternals.com/)
138140

139141
## Attack Simulations & Testing
140142

docs/securitycopilot.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,3 +93,4 @@
9393
- [Learn Live: Get started with Microsoft Copilot for Security](https://learn.microsoft.com/en-us/shows/learn-live/microsoft-copilot-for-security/)
9494
- [How to Become a Microsoft Security Copilot Ninja: The Complete Level 400 Training](https://techcommunity.microsoft.com/blog/securitycopilotblog/how-to-become-a-microsoft-security-copilot-ninja-the-complete-level-400-training/4106928)
9595
- [LinkedIn Learn - Security Copilot](https://www.linkedin.com/learning/topics/microsoft-security-copilot)
96+
- [Security Copilot Skilling Series](https://www.youtube.com/watch?v=Rfx_4nMko1o&list=PLmAptfqzxVEWGjqfUaMx9R2DjPjrXrfjK)

docs/sentinel.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,14 @@
88

99
## Microsoft Tech Community Blogs
1010

11+
- [Introducing Microsoft Sentinel graph (Public Preview)](https://techcommunity.microsoft.com/blog/microsoft-security-blog/introducing-microsoft-sentinel-graph-public-preview/4456368)
12+
- [Microsoft Sentinel data lake is now generally available](https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsoft-sentinel-data-lake-is-now-generally-available/4456342)
13+
- [New bi-directional export for TI in Microsoft Sentinel and strategic Cyware partnership](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/new-bi-directional-export-for-ti-in-microsoft-sentinel-and-strategic-cyware-part/4457947)
14+
- [6 truths about migrating Microsoft Sentinel to the Defender portal](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/6-truths-about-migrating-microsoft-sentinel-to-the-defender-portal/4460437)
15+
- [Microsoft Sentinel data lake FAQ](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel-data-lake-faq/4457728)
16+
- [App Assure's Sentinel promise now extends to Microsoft Sentinel data lake](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/app-assures-sentinel-promise-now-extends-to-microsoft-sentinel-data-lake/4454612)
17+
- [Microsoft Sentinel and Defender: ITSM Integrations Explained](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel-and-defender-itsm-integrations-explained/4457282)
18+
- [Automate Security Workflows in Microsoft Sentinel with BlinkOps](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/automate-security-workflows-in-microsoft-sentinel-with-blinkops/4454575)
1119
- [Microsoft Sentinel’s AI-driven UEBA ushers in the next era of behavioral analytics](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel%E2%80%99s-ai-driven-ueba-ushers-in-the-next-era-of-behavioral-analyti/4448390)
1220
- [How to: Ingest Splunk alert data to Microsoft Sentinel SIEM](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/how-to-ingest-splunk-alert-data-to-microsoft-sentinel-siem/4449027)
1321
- [Table Talk: Sentinel’s New ThreatIntel Tables Explained](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/table-talk-sentinel%E2%80%99s-new-threatintel-tables-explained/4440273)
@@ -571,6 +579,7 @@
571579

572580
## Community Blogs
573581

582+
- [Protecting Your Microsoft Sentinel Solution from Deletion or Corruption](https://cybermohr.ghost.io/2025/05/28/protecting-your-microsoft-sentinel-solution-from-deletion-or-corruption/)
574583
- [SentinelCodeGuard: A Journey from Concept to VS Code Plugin](https://sentinel.blog/sentinelcodeguard-a-journey-from-concept-to-vs-code-plugin/)
575584
- [SentinelCodeGuard: Revolutionising Microsoft Sentinel Rule Development](https://sentinel.blog/sentinelcodeguard-revolutionizing-microsoft-sentinel-rule-development/)
576585
- [Simplifying Azure Log Analytics Table Retention Management: A Modern Approach](https://sentinel.blog/simplifying-azure-log-analytics-table-retention-management-a-modern-approach/)

0 commit comments

Comments
 (0)