PS> Get-Knowledge | Out-Blog
About Me
  • Jan 28, 2026

    UTCM: Quick Evaluation for Security Consultants

    Microsoft's new Unified Tenant Configuration Management (UTCM) looks promising for drift monitoring, but doesn't fit the bill for point-in-time security assessments.
    utcmmicrosoft-365graph-apisecurity-assessmentscubagearmicrosoft365dsc
    Read more
  • Jan 16, 2026

    Trust But Verify: Using Claude Code's Hooks, Skills, and Agents to Generate Code That's Not Totally Insecure

    How security professionals can leverage Claude Code's extensibility framework to enforce deterministic security checks on AI-generated code, treating AI coding assistants like any other developer on the team.
    claude-codeanthropicsecure-codingsastsemgrepbanditdevsecopsllm
    Read more
  • Nov 6, 2025

    Fingerprinting Services Behind Proofpoint Hosted SPF: A Reconnaissance Technique

    A technique for fingerprinting which third-party email services organisations have authorised through their Proofpoint Hosted SPF implementation.
    proofpointspfreconnaissanceemail-securitydnsosint
    Read more
  • Oct 9, 2025

    Everything You Need to Know About Sentinel Data Lake

    A comprehensive guide to Microsoft Sentinel Data Lake as at October 2025
    microsoft-sentineldata-lakesecurity-operationsazure-securitysiem
    Read more
  • Aug 27, 2025

    When DuckDB FTS Meets Async MCP: An AI-Assisted Debugging Nightmare

    A cautionary tale about vibe coding utilities that combine synchronous and asynchronous code.
    duckdbmcpasyncdebuggingrace-conditionsclaude-code
    Read more
  • Aug 15, 2025

    CISA BOD 25-01: When Compliance Contradicts Best Practice

    US Federal civilian executive branch agencies using Microsoft 365 must choose between complying with CISA's SCuBA requirements or following industry best practice for email authentication. They can't do both.
    email-securityspfdmarccompliancebod-25-01
    Read more
  • Aug 6, 2025

    Setting Up MITRE ATT&CK MCP Server on Windows for Claude

    How to set up the mitre-mcp server on Windows to give Claude direct access to MITRE ATT&CK framework data for threat intelligence and security analysis.
    mitre-attackmcpclaudethreat-intelligencesecurity-analysismodel-context-protocolwindows
    Read more
  • Aug 4, 2025

    Parsing JSON Data with PowerShell: From Raw API Responses to Structured Reports

    How to use PowerShell to parse and analyse JSON data from APIs and exports, transforming complex nested structures into structured reports ready for analysis.
    powershelljsondata-analysisapiautomationpscustomobject
    Read more
  • Jul 28, 2025

    M365 Email OSINT After the Lockdown: What Still Works in 2025

    Pondering Microsoft's recent Autodiscover service changes, and the information that remains publicly accessible for M365 email security reconnaissance.
    azureentra-idosintpowershelltenant-enumerationmoerasecurity-assessment
    Read more
  • Jul 8, 2025

    Connecting Azure to Claude Desktop via MCP

    How to connect the Azure MCP server to Claude Desktop for direct access to Azure resources, enabling Claude to help with Azure development and operations.
    claudemcpazureai-toolsmodel-context-protocol
    Read more
« Previous Page 2 of 6 Next »
Daniel Streefkerk
  • dstreefkerk
  • egosumdns
  • RSS

My collection of useful content that's worth sharing with the world. Windows Security, Cloud Security, PowerShell, AI, Model Context Protocol, and more.