Anything About IT

Learning, Building, Sharing

Monitoring Windows built-in local security Groups with Microsoft Defender XDR or Sentinel

Detect and monitor local security group changes using Microsoft Defender XDR and Microsoft Sentinel.

Users can create AzureAD tenants

Review and monitor the Azure AD setting that allows users to create new tenants, with KQL detection queries.

Microsoft Defender for Identity - Npcap driver Update

How to migrate Microsoft Defender for Identity sensors from WinPcap to Npcap and detect impacted domain controllers.

Assessment and Control of Browser Extensions

How to assess, hunt, and control browser extensions with Microsoft Defender for Endpoint and policy controls.

How to analyze Microsoft Sentinel Daily Cap Alerts - AADNonInteractiveUserSignInLogs

How to investigate Microsoft Sentinel daily cap alerts and identify high-volume AADNonInteractiveUserSignInLogs contributors.

How To Detect the Log4Shell Vulnerability (CVE-2021-44228) with Microsoft Endpoint Configuration Manager

How to use Microsoft Endpoint Configuration Manager to detect the Log4Shell vulnerability (CVE-2021-44228)