PICKED BY MODERN SECURITY
LATEST ARTICLES
Connect WITH MODERN SECURITY
Stay in the Loop

security related articles
Read all articles
Microsoft ISOC explained: what it is, who it is for, and how it compares to Sentinel
On September 23, Microsoft announced the Integrated Security Operations Center, or ISOC, in Microsoft Defender. My LinkedIn feed filled up within the hour, and the first question I got was simple: “So is Sentinel dead?” Short answer: no. Longer answer: this is the most interesting change to Microsoft’s SOC story since Sentinel moved into the Defender…
AI playbook generator in Microsoft Sentinel: turn a sentence into working SOC automation
Every SOC lead has the same automation backlog problem. There is a long list of response actions everyone agrees would help, and a much shorter list of people who actually know Logic Apps well enough to build them. The playbook generator in Microsoft Sentinel is Microsoft’s answer to that gap: describe what you want in plain language, and get back a working, testable,…
BYOVD is back: how EDR killers ship inside RaaS kits and how to stop them
If you have been reading ransomware incident reports over the past few months, you have probably noticed the same thing I have. Almost every write-up includes some version of the same sentence: the attacker loaded a signed kernel driver and used it to kill the EDR agent before deploying the encryptor. Bring Your Own Vulnerable Driver, or BYOVD, is not new. But what is new is…
MDTI convergence: threat intelligence now built into Defender and Sentinel
The final phase of the Microsoft Defender Threat Intelligence (MDTI) convergence went generally available in the Defender portal on 1 August 2026. The legacy standalone portal and the legacy Intel Explorer are retired, and Microsoft threat intelligence now lives in the Threat intelligence section of the Defender portal, in entity pages, in Threat analytics, and in Sentinel…
AI agent runtime protection in Microsoft Defender for Endpoint
Discovery tells you an agent exists. It doesn’t tell you when someone tries to hijack it. That’s the gap AI agent runtime protection in Microsoft Defender for Endpoint closes, and unlike discovery, this one actually stops things and raises alerts. It’s included with Defender for Endpoint Plan 2, Microsoft 365 E5, Microsoft Agent 365, or Microsoft 365 E7,…
Defender deployment tool: Easy and simple onboarding for Defender for Endpoint
Onboarding devices to Microsoft Defender for Endpoint has always been one of those tasks that looks simple on paper and turns messy the moment you touch a real environment. Different scripts per OS, onboarding blobs that expire without warning, and zero visibility into whether a rollout actually succeeded until someone notices a device missing from the portal. Microsoft has…
Microsoft Defender for Endpoint custom data collection: get the telemetry you need
If you’ve been working with Microsoft Defender for Endpoint (MDE) for any length of time, you’ve probably run into this situation: you’re hunting for a specific behavior, you know it happened on a device, but when you query Advanced Hunting, there’s nothing. The event simply isn’t there. This isn’t a bug. It’s by design. Until…
Identity attack graph in Microsoft Sentinel: easy find lateral movement paths
Sentinel graph ships with two layers. One is custom graphs, where you build your own schema from any data in the lake, which I will cover in a new blog post later. The other is a set of Microsoft-managed graphs that require no authoring at all. The identity attack graph is the most useful of those managed graphs. Enable two connectors, turn on the graph, wait for the initial…
Getting started with OpenCTI: threat intelligence connected to Microsoft Sentinel
For the past few years, MISP has been my go-to for threat intelligence. It’s open source, flexible, and does exactly what it says on the tin. But MISP is also showing its age in some areas — the interface is not the most intuitive, and wiring it into a modern SOC stack takes a fair amount of glue code. So when I kept seeing OpenCTI come up, I figured it was time to…
Microsoft Defender for Identity sensor guide (v3.x)
In a previous post on modernsecurity.nl, I walked through the classic installation of Microsoft Defender for Identity (MDI) using the v2.x sensor — prerequisites, gMSA configuration, Windows event auditing, NTLM auditing, and the manual download-and-install process. If you’ve deployed MDI before, you’ll remember the overhead: downloading an installer package,…
Defender XDR advanced hunting tables: ingest directly into Sentinel data lake
If you’ve read my Microsoft Sentinel data lake implementation guide, you know I covered a DCR-based workaround for storing Defender XDR Advanced Hunting data long-term without paying full analytics tier ingestion costs. The approach: enable the XDR connector and use a Workspace Transformation DCR to redirect data from the original XDR table into that custom table. It…
Manage your live response library directly in Microsoft Defender
If you’ve been using live response in Microsoft Defender for Endpoint for a while, you’ve probably felt the friction. A critical incident comes in, you initiate a session, and then the race begins — digging through folders, shared drives, and old Teams chats trying to locate the right PowerShell script before the attacker moves laterally to the next system. In…
UEBA behaviors layer in Microsoft Sentinel: from raw logs to behavioral intelligence
Every SOC analyst knows the feeling. An alert fires. You open the incident. And then the real work begins: correlating AWS CloudTrail API calls, translating firewall log schemas, joining tables across data sources you barely recognize — all to answer one question: what actually happened? Microsoft’s new UEBA behaviors layer in Microsoft Sentinel changes that. Instead…
Microsoft Defender for Cloud Apps: AI agent monitoring and real-time protection
Low-code platforms like Microsoft Copilot Studio make it easy for business users to build and deploy AI agents without going through IT or security. That’s useful, but it also means agents are getting created outside of any centralized review — with access to data, external systems, and tool calls that security teams often know nothing about. Microsoft Defender for…
Proactively Block Cloud Apps (like AI) with Microsoft Defender for Cloud Apps and Defender for Endpoint
Shadow IT remains one of the biggest challenges for security teams. Users access cloud applications daily without IT awarenes, shady AI tooling, file sharing services, or apps that don’t meet compliance requirements like SOC 2 or ISO 27001. With the integration between Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint, you can proactively block apps…
Microsoft Sentinel data lake: implementation guide
What is Microsoft Sentinel data lake Microsoft Sentinel data lake is a purpose-built, cloud-native security data platform that addresses the fundamental challenge organizations face between comprehensive security coverage and cost sustainability. The platform transforms how organizations manage and analyze security data through: The business challenge solved Traditional SIEM…
Automatic Attack Disruption in Microsoft Defender XDR
The reality of modern ransomware response Picture this: It’s 2 AM. Your on-call engineer gets an alert about suspicious activity. By the time they log in, investigate, and start containment procedures, the attackers have already pivoted through three critical servers and begun encrypting your file shares. Sound familiar? This scenario plays out in organizations…
Selective Isolation in Defender for Endpoint – Combining tools like Velociraptor for DFIR
With the introduction of Selective Isolation, Microsoft Defender for Endpoint has taken a significant step toward more flexible incident response. Instead of fully isolating an endpoint from the network, security teams can now allow specific outbound connections — enabling secure communication with approved services such as a forensic server or response platform. This…
Integrating Microsoft Defender EASM with Exposure Management
Microsoft has taken another step in closing the gap between internal risk and external exposure. With the June 2025 public preview release of Microsoft Defender External Attack Surface Management (EASM) integration into Defender Exposure Management, organizations can now analyze attacker pathways that begin outside the enterprise perimeter. This addition enables a more…
Automatically tagging MITRE techniques with AI in SOC Optimization
Mapping security detections to the MITRE ATT&CK framework is crucial for understanding adversary behavior and improving threat response. However, maintaining accurate and consistent MITRE mappings across all analytics rules in large environments can be challenging. To support this process, Microsoft introduced AI-powered MITRE tagging—a feature available in public…






























