

Understanding OCSF: The Universal Translator for Security Data in Microsoft Sentinel (Part 1 of 2)
The **Open Cybersecurity Schema Framework (OCSF)** addresses one of the most persistent challenges in security operations: inconsistent log formats across vendors. If you've spent hours writing custom parsers for every new data source in **Microsoft Sentinel**, OCSF offers a stan
William Clarkson-Antill
11 minutes ago4 min read
Â


Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
William Clarkson-Antill
Apr 56 min read
Â


Enabling Defender for Cloud - Initial Setup and Config
Enabling Defender for Cloud - Initial Setup and Config
William Clarkson-Antill
Apr 55 min read
Â


Deploying Microsoft Defender for Endpoint to Your First Machine
Deploying Microsoft Defender for Endpoint to Your First Machine
William Clarkson-Antill
Apr 54 min read
Â


Deploying OpenCTI on AKS using Helm
OpenCTI is an open‑source cyber threat intelligence platform designed to manage and visualise knowledge about cyber threats. This post...
William Clarkson-Antill
Sep 26, 20254 min read
Â


New Series: How to build a SOC
I decided to begin by writing a series of blog posts, starting with "How to Build a Security Operations Centre (SOC)." It has been a...
William Clarkson-Antill
Mar 31, 20251 min read
Â










