01Blog
Perspectives on security, technology and engineering.
Practical writing for the people who have to make the decisions, and for the people who have to make them work. No listicles, no gated downloads.
- Published
- 12 articles
- Topics
- 10
- Reading time
- 5 to 8 minutes each
03Latest
Latest articles
12 articles, newest first
- Read article
Building a practical cloud security monitoring strategy
A practical order of work for cloud security monitoring on AWS, Azure and Google Cloud, from control plane logs to detections, cost control and response.
- Read article
Detection engineering: turning security telemetry into action
How to run detections as code, from an ATT&CK hypothesis through a tested KQL rule to tuning and analyst notes, with a worked Microsoft Sentinel example.
- Read article
From VAPT findings to continuous security improvement
How to read a VAPT report, prioritize with CVSS, EPSS and CISA KEV, fix root causes, and feed findings into development, detection and the next test.
- Read article
OAuth abuse and modern identity threats
How attackers get past MFA by stealing tokens and abusing OAuth consent in Microsoft Entra ID, which logs record it and how to respond when it happens.
- Read article
Practical threat hunting in Microsoft security environments
A practical method for threat hunting in Microsoft Defender XDR and Microsoft Sentinel, with two KQL examples and guidance on recording every outcome.
- Read article
Security governance without turning compliance into paperwork
How to build security governance on real operations: one mapped control library, evidence from daily work, and a risk register that drives decisions.
- Read article
Security telemetry: what organizations should actually monitor
A priority order for security log sources, from identity and endpoint to cloud audit and SaaS, with guidance on retention, cost and log health monitoring.
- Read article
What good incident response looks like before the incident
What to prepare before a security incident: decision authority, contacts, log retention, evidence handling, playbooks, exercises and tested backups.
- Read article
A working threat model for LLM applications
A practical threat model for applications built on large language models, covering trust boundaries, the main threats and the controls that limit them.
- Read article
Running ISO/IEC 27001:2022 and SOC 2 from one control set
How to satisfy ISO/IEC 27001:2022 and SOC 2 with one set of controls and one body of evidence, and where the two still differ.
- Read article
Segmenting IT from OT with the Purdue model and IEC 62443
A practical guide to separating IT from OT networks using the Purdue levels, IEC 62443 zones and conduits, an industrial DMZ and passive discovery.
Security Labs
Looking for deeper technical research?
The blog explains and advises. Security Labs is where the underlying research is done: threat research, detection engineering, AI security and vulnerability research.
