

Hardening Linux Endpoints for Microsoft Defender for Endpoint
Deploying **Microsoft Defender for Endpoint** on Linux servers is a solid first step, but the real security value comes from proper hardening. In this post, I'll walk through practical configurations that go beyond the default deployment to reduce your attack surface and improve
William Clarkson-Antill
1 day ago3 min read


Azure Policy for Security Compliance Automation
Managing security compliance across Azure environments manually doesn't scale. I've seen too many organisations rely on periodic audits and spreadsheets to track security configurations, only to discover drift during incidents or compliance reviews. Azure Policy provides the auto
William Clarkson-Antill
Jul 184 min read


Deploying OCSF to Microsoft Sentinel: A Step-by-Step Implementation Guide (Part 2 of 2)
In **Part 1**, we covered what **OCSF** is and why it solves critical problems for **Microsoft Sentinel** deployments. This post walks through the technical implementation: creating custom tables for OCSF event classes, configuring **Data Collection Rules (DCR)** to transform log
William Clarkson-Antill
May 84 min read


Understanding OCSF: The Universal Translator for Security Data in Microsoft Sentinel (Part 1 of 2)
The **Open Cybersecurity Schema Framework (OCSF)** addresses one of the most persistent challenges in security operations: inconsistent log formats across vendors. If you've spent hours writing custom parsers for every new data source in **Microsoft Sentinel**, OCSF offers a stan
William Clarkson-Antill
May 14 min read


Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
William Clarkson-Antill
Apr 56 min read


Enabling Defender for Cloud - Initial Setup and Config
Enabling Defender for Cloud - Initial Setup and Config
William Clarkson-Antill
Apr 55 min read










