blogging 13
- Sizing Event Hubs for the Defender Streaming API - TUs, Partitions and Tier Selection
- Custom Detections vs Analytics Rules - Why I Now Default to Custom Detections
- Defender for Containers - Gated Deployment - Blocking Vulnerable Container Images
- Defender for Containers - Blocking Kubernetes Misconfigurations with VAP
- Two Protocols and a Rust Bridge: How Windows Intelligent Terminal Works
- Defender Endpoint SenseIR Events - AIR and Live Response Under the Hood
- Defender Advanced Hunting - Tracking AI Tool URL Clicks and Git Repo Targets
- Defender for Cloud - Built-in Azure Roles and Permissions
- Defender for Cloud - Container Security - What's New in the Last 6 Months
- The New WSL Container: Running native Linux Containers on Windows
- Bring Your Own Harness: Running Security Investigator as Foundry Hosted Agent with GitHub Copilot
- Defender for Identity - 40+ New or Expanded Built-In Alerts You Might Have Missed
- Ingestion into Sentinel via Event Hub made simple