

Configuring UEBA in Microsoft Sentinel for Behavioural Threat Detection
**User and Entity Behavior Analytics (UEBA)** in **Microsoft Sentinel** provides machine learning-driven anomaly detection that goes beyond signature-based alerts. In this post, I'll walk through enabling and configuring UEBA to detect insider threats, compromised accounts, and l
William Clarkson-Antill
43 minutes ago4 min read
Â


Hardening Linux Endpoints for Microsoft Defender for Endpoint
Deploying **Microsoft Defender for Endpoint** on Linux servers is a solid first step, but the real security value comes from proper hardening. In this post, I'll walk through practical configurations that go beyond the default deployment to reduce your attack surface and improve
William Clarkson-Antill
6 days ago3 min read
Â


Azure Policy for Security Compliance Automation
Managing security compliance across Azure environments manually doesn't scale. I've seen too many organisations rely on periodic audits and spreadsheets to track security configurations, only to discover drift during incidents or compliance reviews. Azure Policy provides the auto
William Clarkson-Antill
Jul 184 min read
Â


Deploying OCSF to Microsoft Sentinel: A Step-by-Step Implementation Guide (Part 2 of 2)
In **Part 1**, we covered what **OCSF** is and why it solves critical problems for **Microsoft Sentinel** deployments. This post walks through the technical implementation: creating custom tables for OCSF event classes, configuring **Data Collection Rules (DCR)** to transform log
William Clarkson-Antill
May 84 min read
Â


Understanding OCSF: The Universal Translator for Security Data in Microsoft Sentinel (Part 1 of 2)
The **Open Cybersecurity Schema Framework (OCSF)** addresses one of the most persistent challenges in security operations: inconsistent log formats across vendors. If you've spent hours writing custom parsers for every new data source in **Microsoft Sentinel**, OCSF offers a stan
William Clarkson-Antill
May 14 min read
Â


Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
William Clarkson-Antill
Apr 56 min read
Â










