Writeups
Hunting shadow IT with Defender for Cloud Apps
An audit of 200+ unsanctioned cloud apps turned up a consumer file-sync service with foreign data residency and active uploads, which was blocked the same week.
Catching a dangling DNS record with a Cloudflare-to-Sentinel pipeline
Cloudflare already knew about the dangling record; the fix was getting its security insights into the SIEM where someone would act on them.
What 3,500 brute-force attempts in 24 hours look like
One exposed VM, one day, 3,516 failed logons. Most of them came from a single address, which changes what the right defense is.