01Blog

Perspectives on security, technology and engineering.

Practical writing for the people who have to make the decisions, and for the people who have to make them work. No listicles, no gated downloads.

Published
12 articles
Topics
10
Reading time
5 to 8 minutes each

03Latest

Latest articles

12 articles, newest first

  1. Cloud Security07 min read

    Building a practical cloud security monitoring strategy

    A practical order of work for cloud security monitoring on AWS, Azure and Google Cloud, from control plane logs to detections, cost control and response.

    Read article
  2. Detection Engineering07 min read

    Detection engineering: turning security telemetry into action

    How to run detections as code, from an ATT&CK hypothesis through a tested KQL rule to tuning and analyst notes, with a worked Microsoft Sentinel example.

    Read article
  3. Offensive Security08 min read

    From VAPT findings to continuous security improvement

    How to read a VAPT report, prioritize with CVSS, EPSS and CISA KEV, fix root causes, and feed findings into development, detection and the next test.

    Read article
  4. Identity & Access08 min read

    OAuth abuse and modern identity threats

    How attackers get past MFA by stealing tokens and abusing OAuth consent in Microsoft Entra ID, which logs record it and how to respond when it happens.

    Read article
  5. Threat Hunting07 min read

    Practical threat hunting in Microsoft security environments

    A practical method for threat hunting in Microsoft Defender XDR and Microsoft Sentinel, with two KQL examples and guidance on recording every outcome.

    Read article
  6. Compliance & Governance07 min read

    Security governance without turning compliance into paperwork

    How to build security governance on real operations: one mapped control library, evidence from daily work, and a risk register that drives decisions.

    Read article
  7. Security Operations07 min read

    Security telemetry: what organizations should actually monitor

    A priority order for security log sources, from identity and endpoint to cloud audit and SaaS, with guidance on retention, cost and log health monitoring.

    Read article
  8. Incident Response08 min read

    What good incident response looks like before the incident

    What to prepare before a security incident: decision authority, contacts, log retention, evidence handling, playbooks, exercises and tested backups.

    Read article
  9. AI & Security05 min read

    A working threat model for LLM applications

    A practical threat model for applications built on large language models, covering trust boundaries, the main threats and the controls that limit them.

    Read article
  10. Compliance & Governance05 min read

    Running ISO/IEC 27001:2022 and SOC 2 from one control set

    How to satisfy ISO/IEC 27001:2022 and SOC 2 with one set of controls and one body of evidence, and where the two still differ.

    Read article
  11. OT Security05 min read

    Segmenting IT from OT with the Purdue model and IEC 62443

    A practical guide to separating IT from OT networks using the Purdue levels, IEC 62443 zones and conduits, an industrial DMZ and passive discovery.

    Read article

Security Labs

Looking for deeper technical research?

The blog explains and advises. Security Labs is where the underlying research is done: threat research, detection engineering, AI security and vulnerability research.