Practitioner security field notes
Hands-on notes from actual engagements — identity, detection, incident response, and the PowerShell that ties it together. The mechanism, the gotcha, the reusable lesson. Never a client story.
Latest
Part 2 ended with an incident in the queue. This is what happens next — automation rules, the reflex inside Sentinel, and playbooks, the muscle that reaches out and
Storage isn't detection. This is the part that turns tables into a SIEM: the rules that read the data, the alerts they raise, the incidents you assemble, and the two
Most people meet Sentinel as a search bar over some logs. Underneath is a supply chain — data arrives, gets sorted, gets stored at a price that depends on how
You're asked to pull someone's activity and say whether they were really working. You can pull the data — the skill is reading it without inventing a