

Why Your MDI Alerts Are Noisy (And How to Fix Them)
**Microsoft Defender for Identity** is one of the most powerful tools for detecting on-premises Active Directory attacks — but out of the box, it's also one of the noisiest. If you've deployed MDI sensors and found yourself drowning in alerts about suspicious LDAP queries, encryp
William Clarkson-Antill
14 hours ago6 min read


Configuring UEBA in Microsoft Sentinel for Behavioural Threat Detection
**User and Entity Behavior Analytics (UEBA)** in **Microsoft Sentinel** provides machine learning-driven anomaly detection that goes beyond signature-based alerts. In this post, I'll walk through enabling and configuring UEBA to detect insider threats, compromised accounts, and l
William Clarkson-Antill
3 days ago4 min read


Hardening Linux Endpoints for Microsoft Defender for Endpoint
Deploying **Microsoft Defender for Endpoint** on Linux servers is a solid first step, but the real security value comes from proper hardening. In this post, I'll walk through practical configurations that go beyond the default deployment to reduce your attack surface and improve
William Clarkson-Antill
Jul 283 min read


Azure Policy for Security Compliance Automation
Managing security compliance across Azure environments manually doesn't scale. I've seen too many organisations rely on periodic audits and spreadsheets to track security configurations, only to discover drift during incidents or compliance reviews. Azure Policy provides the auto
William Clarkson-Antill
Jul 184 min read


Deploying OCSF to Microsoft Sentinel: A Step-by-Step Implementation Guide (Part 2 of 2)
In **Part 1**, we covered what **OCSF** is and why it solves critical problems for **Microsoft Sentinel** deployments. This post walks through the technical implementation: creating custom tables for OCSF event classes, configuring **Data Collection Rules (DCR)** to transform log
William Clarkson-Antill
May 84 min read


Understanding OCSF: The Universal Translator for Security Data in Microsoft Sentinel (Part 1 of 2)
The **Open Cybersecurity Schema Framework (OCSF)** addresses one of the most persistent challenges in security operations: inconsistent log formats across vendors. If you've spent hours writing custom parsers for every new data source in **Microsoft Sentinel**, OCSF offers a stan
William Clarkson-Antill
May 14 min read










