Blue Team of Onefield notes · security

Practitioner security field notes

Real defensive work, written honestly.

Hands-on notes from actual engagements — identity, detection, incident response, and the PowerShell that ties it together. The mechanism, the gotcha, the reusable lesson. Never a client story.

Ram Mudigina
Ram Mudigina
Security Lead · Surya Technologies · Bengaluru

Latest

Detection EngineeringSep 2026

How Sentinel responds: the reflex and the muscle

Part 2 ended with an incident in the queue. This is what happens next — automation rules, the reflex inside Sentinel, and playbooks, the muscle that reaches out and

Detection EngineeringSep 2026

How Sentinel detects: rules, alerts, incidents, and the hunt

Storage isn't detection. This is the part that turns tables into a SIEM: the rules that read the data, the alerts they raise, the incidents you assemble, and the two

Detection EngineeringSep 2026

How Sentinel is built: from the loading dock to the lake

Most people meet Sentinel as a search bar over some logs. Underneath is a supply chain — data arrives, gets sorted, gets stored at a price that depends on how

Detection EngineeringAug 2026

What the logs won't tell you

You're asked to pull someone's activity and say whether they were really working. You can pull the data — the skill is reading it without inventing a

Browse by topic