PS> Get-Knowledge | Out-Blog
About Me
  • Mar 4, 2026

    Domain Controller Log Ingestion for Microsoft Sentinel: Complete Configuration Reference

    Getting domain controller security events into Microsoft Sentinel has more failure modes than it should. Four layers must all work correctly (audit policy, Azure Arc, AMA, and the Data Collection Rule), and a misconfiguration at any one of them drops events silently, with no error and no alert. This post covers the full configuration chain, the gotchas that burn people in production (Event ID 5136 disappearing on Minimal, raw operation codes that break KQL filters, fields that look like columns but aren't), and the verification steps to confirm the pipeline is actually working end to end.
    microsoft-sentinelazure-monitor-agentdomain-controlleractive-directorylog-ingestionamaazure-arcwindows-event-forwardingkqlaudit-policydcr
    Read more
  • Feb 27, 2026

    New in Sentinel: Azure Storage Blob Codeless Connector (Public Preview)

    A new Codeless Connector Framework kind just landed for Azure Blob Storage, and it's architecturally different from anything CCF has done before.
    microsoft-sentinelccfcodeless-connectorazure-storageblob-storageevent-griddata-connectorslog-ingestion
    Read more
  • Feb 26, 2026

    Agentic Architecture Playbook: Patterns for Reliable LLM Workflows

    A playbook of patterns for building reliable LLM workflows, covering meta-prompting, state externalisation, and adversarial validation. Derived from analysing the GSD framework.
    llmagentic-aiclaude-codeprompt-engineeringmeta-promptingcontext-engineering
    Read more
  • Feb 17, 2026

    Connecting Google Workspace to Microsoft Sentinel

    A practical walkthrough for connecting Google Workspace activity logs to Microsoft Sentinel, including the undocumented gotchas that'll save you from a frustrating afternoon.
    microsoft-sentinelgoogle-workspacedata-connectoroauthcodeless-connector-frameworklog-ingestion
    Read more
  • Jan 29, 2026

    Running Claude Code from Windows CLI: A Practical Guide

    Practical lessons learned from programmatically invoking Claude Code on Windows, including the gotchas around tool permissions and system prompts that took some time to figure out.
    claude-codeanthropicwindowsclipythonautomationllm
    Read more
  • Jan 28, 2026

    UTCM: Quick Evaluation for Security Consultants

    Microsoft's new Unified Tenant Configuration Management (UTCM) looks promising for drift monitoring, but doesn't fit the bill for point-in-time security assessments.
    utcmmicrosoft-365graph-apisecurity-assessmentscubagearmicrosoft365dsc
    Read more
  • Jan 16, 2026

    Trust But Verify: Using Claude Code's Hooks, Skills, and Agents to Generate Code That's Not Totally Insecure

    How security professionals can leverage Claude Code's extensibility framework to enforce deterministic security checks on AI-generated code, treating AI coding assistants like any other developer on the team.
    claude-codeanthropicsecure-codingsastsemgrepbanditdevsecopsllm
    Read more
  • Nov 6, 2025

    Fingerprinting Services Behind Proofpoint Hosted SPF: A Reconnaissance Technique

    A technique for fingerprinting which third-party email services organisations have authorised through their Proofpoint Hosted SPF implementation.
    proofpointspfreconnaissanceemail-securitydnsosint
    Read more
  • Oct 9, 2025

    Everything You Need to Know About Sentinel Data Lake

    A comprehensive guide to Microsoft Sentinel Data Lake as at October 2025
    microsoft-sentineldata-lakesecurity-operationsazure-securitysiem
    Read more
  • Aug 27, 2025

    When DuckDB FTS Meets Async MCP: An AI-Assisted Debugging Nightmare

    A cautionary tale about vibe coding utilities that combine synchronous and asynchronous code.
    duckdbmcpasyncdebuggingrace-conditionsclaude-code
    Read more
« Previous Page 1 of 6 Next »
Daniel Streefkerk
  • dstreefkerk
  • egosumdns
  • RSS

My collection of useful content that's worth sharing with the world. Windows Security, Cloud Security, PowerShell, AI, Model Context Protocol, and more.