Using AbuseIPDB in Microsoft Sentinel for IP Reputation and Threat Enrichment.
Enhance Microsoft Sentinel with AbuseIPDB to enrich incidents, assess IP reputation, and automate threat response using playbooks.

This article is coming soon.
Search for a command to run...
Enhance Microsoft Sentinel with AbuseIPDB to enrich incidents, assess IP reputation, and automate threat response using playbooks.

This article is coming soon.
No comments yet. Be the first to comment.
Designing a Resilient Linux Application Stack on Windows Infrastructure.

A deep dive on ClickFix, mapping fake CAPTCHA lures to endpoint code execution, covering investigation, response, and preventative controls.

Overview. Prerequisites. Join types. LAPS is only supported on: Microsoft Entra joined devices. Microsoft Entra hybrid joined devices. Microsoft Entra registered devices are not supported. License requirements. LAPS is available to all customers ...

A complete analysis of a compromised identity in Microsoft 365, covering key tactics, techniques, and procedures.

Streamlining Level RMM deployment across Windows devices using PowerShell and a Microsoft Intune deployment script.

Ciaran Doherty's SecOps Blog
24 posts