Anything About IT

Learning, Building, Sharing

Exploring IdentityAccountInfo - Building a KQL Query to Assess Identity Password Security Posture

Use IdentityAccountInfo and IdentityInfo in Defender XDR to assess password hygiene, account sensitivity, and risky password policy settings.

Shedding Light on Dormant Sensitive Accounts

Use Microsoft Defender XDR and KQL to enrich dormant sensitive account findings and add missing account context for remediation.

Users can create AzureAD tenants

Review and monitor the Azure AD setting that allows users to create new tenants, with KQL detection queries.

Generating Advanced hunting queries with PowerShell

Writing advanced hunting queries for Microsoft Defender ATP to search for execution of specific PowerShell commands.