- Mar 4, 2026
Getting domain controller security events into Microsoft Sentinel has more failure modes than it should. Four layers must all work correctly (audit policy, Azure Arc, AMA, and the Data Collection Rule), and a misconfiguration at any one of them drops events silently, with no error and no alert. This post covers the full configuration chain, the gotchas that burn people in production (Event ID 5136 disappearing on Minimal, raw operation codes that break KQL filters, fields that look like columns but aren't), and the verification steps to confirm the pipeline is actually working end to end.
microsoft-sentinelazure-monitor-agentdomain-controlleractive-directorylog-ingestionamaazure-arcwindows-event-forwardingkqlaudit-policydcr
Read more
- Feb 27, 2026
A new Codeless Connector Framework kind just landed for Azure Blob Storage, and it's architecturally different from anything CCF has done before.
microsoft-sentinelccfcodeless-connectorazure-storageblob-storageevent-griddata-connectorslog-ingestion
Read more
- Feb 26, 2026
A playbook of patterns for building reliable LLM workflows, covering meta-prompting, state externalisation, and adversarial validation. Derived from analysing the GSD framework.
llmagentic-aiclaude-codeprompt-engineeringmeta-promptingcontext-engineering
Read more
- Feb 17, 2026
A practical walkthrough for connecting Google Workspace activity logs to Microsoft Sentinel, including the undocumented gotchas that'll save you from a frustrating afternoon.
microsoft-sentinelgoogle-workspacedata-connectoroauthcodeless-connector-frameworklog-ingestion
Read more
- Jan 29, 2026
Practical lessons learned from programmatically invoking Claude Code on Windows, including the gotchas around tool permissions and system prompts that took some time to figure out.
claude-codeanthropicwindowsclipythonautomationllm
Read more
- Jan 28, 2026
Microsoft's new Unified Tenant Configuration Management (UTCM) looks promising for drift monitoring, but doesn't fit the bill for point-in-time security assessments.
utcmmicrosoft-365graph-apisecurity-assessmentscubagearmicrosoft365dsc
Read more
- Jan 16, 2026
How security professionals can leverage Claude Code's extensibility framework to enforce deterministic security checks on AI-generated code, treating AI coding assistants like any other developer on the team.
claude-codeanthropicsecure-codingsastsemgrepbanditdevsecopsllm
Read more
- Nov 6, 2025
A technique for fingerprinting which third-party email services organisations have authorised through their Proofpoint Hosted SPF implementation.
proofpointspfreconnaissanceemail-securitydnsosint
Read more
- Oct 9, 2025
A comprehensive guide to Microsoft Sentinel Data Lake as at October 2025
microsoft-sentineldata-lakesecurity-operationsazure-securitysiem
Read more
- Aug 27, 2025
A cautionary tale about vibe coding utilities that combine synchronous and asynchronous code.
duckdbmcpasyncdebuggingrace-conditionsclaude-code
Read more