Blue Team
of One
field notes · security
SOC
IR
Identity
Endpoint
Email
Detection
Cloud
Forensics
PS
About
Search
Practitioner security field notes
Real defensive work, written
honestly
.
Ram Mudigina
✓
Security Lead · Surya Technologies · Bengaluru, India
27
Field notes
09
Verticals
Explore by vertical
01
Identity Security
Tokens, Conditional Access, PIM, passwordless.
9
posts
→
02
Endpoint Security
EDR, hardening, Intune, LAPS.
4
posts
→
03
Digital Forensics
Legal holds, eDiscovery, preservation.
3
posts
→
04
Email Security
Mail flow, phishing, delegation.
3
posts
→
05
Incident Response
Containment and honest writeups.
2
posts
→
06
Detection Engineering
KQL hunting, Sentinel rules.
2
posts
→
07
Cloud Security
Secure access, posture.
2
posts
→
08
SOC Operations
Triage, workflow, automation.
1
posts
→
09
PowerShell Library
Reusable blue-team scripts.
1
posts
→
Latest
PowerShell Library · Aug 21
A privileged-access reporter: who holds admin, and is it standing or JIT?
Newest field note →
Aug 2026
Identity Security
Temporary Access Pass is a loaded gun: using it without shooting yourself
Aug 2026
Identity Security
Killing standing admin: tiered privileged access with PIM
Aug 2026
Endpoint Security
Windows Hello for Business via Intune: the two paths, and picking the right one