PICKED BY MODERN SECURITY

LATEST ARTICLES

Connect WITH MODERN SECURITY

Stay in the Loop

Read all articles

ISOC

Microsoft ISOC explained: what it is, who it is for, and how it compares to Sentinel

On September 23, Microsoft announced the Integrated Security Operations Center, or ISOC, in Microsoft Defender. My LinkedIn feed filled up within the hour, and the first question I got was simple: “So is Sentinel dead?” Short answer: no. Longer answer: this is the most interesting change to Microsoft’s SOC story since Sentinel moved into the Defender…

AI playbook generator in Microsoft Sentinel: turn a sentence into working SOC automation

Every SOC lead has the same automation backlog problem. There is a long list of response actions everyone agrees would help, and a much shorter list of people who actually know Logic Apps well enough to build them. The playbook generator in Microsoft Sentinel is Microsoft’s answer to that gap: describe what you want in plain language, and get back a working, testable,…

BYOVD is back: how EDR killers ship inside RaaS kits and how to stop them

If you have been reading ransomware incident reports over the past few months, you have probably noticed the same thing I have. Almost every write-up includes some version of the same sentence: the attacker loaded a signed kernel driver and used it to kill the EDR agent before deploying the encryptor. Bring Your Own Vulnerable Driver, or BYOVD, is not new. But what is new is…

MDTI convergence: threat intelligence now built into Defender and Sentinel

The final phase of the Microsoft Defender Threat Intelligence (MDTI) convergence went generally available in the Defender portal on 1 August 2026. The legacy standalone portal and the legacy Intel Explorer are retired, and Microsoft threat intelligence now lives in the Threat intelligence section of the Defender portal, in entity pages, in Threat analytics, and in Sentinel…
AI agent runtime protection Defender for Endpoint

AI agent runtime protection in Microsoft Defender for Endpoint

Discovery tells you an agent exists. It doesn’t tell you when someone tries to hijack it. That’s the gap AI agent runtime protection in Microsoft Defender for Endpoint closes, and unlike discovery, this one actually stops things and raises alerts. It’s included with Defender for Endpoint Plan 2, Microsoft 365 E5, Microsoft Agent 365, or Microsoft 365 E7,…
Defender Deployment Tool Defender for Endpoint MDE onboarding

Defender deployment tool: Easy and simple onboarding for Defender for Endpoint

Onboarding devices to Microsoft Defender for Endpoint has always been one of those tasks that looks simple on paper and turns messy the moment you touch a real environment. Different scripts per OS, onboarding blobs that expire without warning, and zero visibility into whether a rollout actually succeeded until someone notices a device missing from the portal. Microsoft has…

Microsoft Defender for Endpoint custom data collection: get the telemetry you need

If you’ve been working with Microsoft Defender for Endpoint (MDE) for any length of time, you’ve probably run into this situation: you’re hunting for a specific behavior, you know it happened on a device, but when you query Advanced Hunting, there’s nothing. The event simply isn’t there. This isn’t a bug. It’s by design. Until…
Identity attack graph sentinel datalake

Identity attack graph in Microsoft Sentinel: easy find lateral movement paths

Sentinel graph ships with two layers. One is custom graphs, where you build your own schema from any data in the lake, which I will cover in a new blog post later. The other is a set of Microsoft-managed graphs that require no authoring at all. The identity attack graph is the most useful of those managed graphs. Enable two connectors, turn on the graph, wait for the initial…

Getting started with OpenCTI: threat intelligence connected to Microsoft Sentinel

For the past few years, MISP has been my go-to for threat intelligence. It’s open source, flexible, and does exactly what it says on the tin. But MISP is also showing its age in some areas — the interface is not the most intuitive, and wiring it into a modern SOC stack takes a fair amount of glue code. So when I kept seeing OpenCTI come up, I figured it was time to…
Microsoft Defender for Identity

Microsoft Defender for Identity sensor guide (v3.x)

In a previous post on modernsecurity.nl, I walked through the classic installation of Microsoft Defender for Identity (MDI) using the v2.x sensor — prerequisites, gMSA configuration, Windows event auditing, NTLM auditing, and the manual download-and-install process. If you’ve deployed MDI before, you’ll remember the overhead: downloading an installer package,…

Defender XDR advanced hunting tables: ingest directly into Sentinel data lake

If you’ve read my Microsoft Sentinel data lake implementation guide, you know I covered a DCR-based workaround for storing Defender XDR Advanced Hunting data long-term without paying full analytics tier ingestion costs. The approach: enable the XDR connector and use a Workspace Transformation DCR to redirect data from the original XDR table into that custom table. It…

Manage your live response library directly in Microsoft Defender

If you’ve been using live response in Microsoft Defender for Endpoint for a while, you’ve probably felt the friction. A critical incident comes in, you initiate a session, and then the race begins — digging through folders, shared drives, and old Teams chats trying to locate the right PowerShell script before the attacker moves laterally to the next system. In…

UEBA behaviors layer in Microsoft Sentinel: from raw logs to behavioral intelligence

Every SOC analyst knows the feeling. An alert fires. You open the incident. And then the real work begins: correlating AWS CloudTrail API calls, translating firewall log schemas, joining tables across data sources you barely recognize — all to answer one question: what actually happened? Microsoft’s new UEBA behaviors layer in Microsoft Sentinel changes that. Instead…

Microsoft Defender for Cloud Apps: AI agent monitoring and real-time protection

Low-code platforms like Microsoft Copilot Studio make it easy for business users to build and deploy AI agents without going through IT or security. That’s useful, but it also means agents are getting created outside of any centralized review — with access to data, external systems, and tool calls that security teams often know nothing about. Microsoft Defender for…

Proactively Block Cloud Apps (like AI) with Microsoft Defender for Cloud Apps and Defender for Endpoint

Shadow IT remains one of the biggest challenges for security teams. Users access cloud applications daily without IT awarenes, shady AI tooling, file sharing services, or apps that don’t meet compliance requirements like SOC 2 or ISO 27001. With the integration between Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint, you can proactively block apps…

Microsoft Sentinel data lake: implementation guide

What is Microsoft Sentinel data lake Microsoft Sentinel data lake is a purpose-built, cloud-native security data platform that addresses the fundamental challenge organizations face between comprehensive security coverage and cost sustainability. The platform transforms how organizations manage and analyze security data through: The business challenge solved Traditional SIEM…

Selective Isolation in Defender for Endpoint – Combining tools like Velociraptor for DFIR

With the introduction of Selective Isolation, Microsoft Defender for Endpoint has taken a significant step toward more flexible incident response. Instead of fully isolating an endpoint from the network, security teams can now allow specific outbound connections — enabling secure communication with approved services such as a forensic server or response platform. This…

Automatically tagging MITRE techniques with AI in SOC Optimization

Mapping security detections to the MITRE ATT&CK framework is crucial for understanding adversary behavior and improving threat response. However, maintaining accurate and consistent MITRE mappings across all analytics rules in large environments can be challenging. To support this process, Microsoft introduced AI-powered MITRE tagging—a feature available in public…