

PIM (Privileged Identity Management) Deployment Gotchas
**Privileged Identity Management** is one of the best security features in **Entra ID P2** (formerly Azure AD Premium P2). It enforces just-in-time admin access, reduces standing privileges, and gives you an audit trail of who activated what role and when. On paper, it's perfect.
William Clarkson-Antill
3 days ago8 min read


MITRE ATT&CK Coverage Gaps (And How to Actually Fill Them)
If you've looked at **Microsoft's MITRE ATT&CK coverage dashboards** in Defender XDR or Sentinel, you've probably seen a lot of green. Microsoft will tell you they cover hundreds of techniques across the kill chain, and technically, that's true. But here's the uncomfortable reali
William Clarkson-Antill
3 days ago7 min read


Why Your MDI Alerts Are Noisy (And How to Fix Them)
**Microsoft Defender for Identity** is one of the most powerful tools for detecting on-premises Active Directory attacks — but out of the box, it's also one of the noisiest. If you've deployed MDI sensors and found yourself drowning in alerts about suspicious LDAP queries, encryp
William Clarkson-Antill
4 days ago6 min read


Configuring UEBA in Microsoft Sentinel for Behavioural Threat Detection
**User and Entity Behavior Analytics (UEBA)** in **Microsoft Sentinel** provides machine learning-driven anomaly detection that goes beyond signature-based alerts. In this post, I'll walk through enabling and configuring UEBA to detect insider threats, compromised accounts, and l
William Clarkson-Antill
6 days ago4 min read


Hardening Linux Endpoints for Microsoft Defender for Endpoint
Deploying **Microsoft Defender for Endpoint** on Linux servers is a solid first step, but the real security value comes from proper hardening. In this post, I'll walk through practical configurations that go beyond the default deployment to reduce your attack surface and improve
William Clarkson-Antill
Jul 283 min read


Azure Policy for Security Compliance Automation
Managing security compliance across Azure environments manually doesn't scale. I've seen too many organisations rely on periodic audits and spreadsheets to track security configurations, only to discover drift during incidents or compliance reviews. Azure Policy provides the auto
William Clarkson-Antill
Jul 184 min read


Deploying OCSF to Microsoft Sentinel: A Step-by-Step Implementation Guide (Part 2 of 2)
In **Part 1**, we covered what **OCSF** is and why it solves critical problems for **Microsoft Sentinel** deployments. This post walks through the technical implementation: creating custom tables for OCSF event classes, configuring **Data Collection Rules (DCR)** to transform log
William Clarkson-Antill
May 84 min read


Understanding OCSF: The Universal Translator for Security Data in Microsoft Sentinel (Part 1 of 2)
The **Open Cybersecurity Schema Framework (OCSF)** addresses one of the most persistent challenges in security operations: inconsistent log formats across vendors. If you've spent hours writing custom parsers for every new data source in **Microsoft Sentinel**, OCSF offers a stan
William Clarkson-Antill
May 14 min read


Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
Deploy MISP in an Azure Container Instances (ACI) and Integrate with Microsoft Sentinel
William Clarkson-Antill
Apr 56 min read


Enabling Defender for Cloud - Initial Setup and Config
Enabling Defender for Cloud - Initial Setup and Config
William Clarkson-Antill
Apr 55 min read


Deploying Microsoft Defender for Endpoint to Your First Machine
Deploying Microsoft Defender for Endpoint to Your First Machine
William Clarkson-Antill
Apr 54 min read


Deploying OpenCTI on AKS using Helm
OpenCTI is an open‑source cyber threat intelligence platform designed to manage and visualise knowledge about cyber threats. This post...
William Clarkson-Antill
Sep 26, 20254 min read


New Series: How to build a SOC
I decided to begin by writing a series of blog posts, starting with "How to Build a Security Operations Centre (SOC)." It has been a...
William Clarkson-Antill
Mar 31, 20251 min read


Settling Into the Unknown: Adjusting to Life in Australia
Hey all, I've been unable to write anything in a while as I've moved from little New Zealand to Australia. I havent been able to post...
William Clarkson-Antill
Feb 6, 20251 min read


Getting Started with Microsoft Security Copilot
Introduction With the rapid advancement of AI products, Microsoft Security Copilot is changing the game in cybersecurity. Harnessing the...
William Clarkson-Antill
Jul 30, 20245 min read


Microsoft Security Exposure Management - CTEM enablement with Microsoft
Earlier this week Microsoft announced the new Exposure Management capability within Microsoft Defender. This new tool will enable...
William Clarkson-Antill
Mar 19, 20242 min read


Microsoft Sentinel - Setting up
I thought id write something up for anyone wanting to setup Microsoft Sentinel for the first time, but are unsure how. Below are the...
William Clarkson-Antill
Feb 4, 20241 min read


Microsoft Defender for Endpoint - Enabling Vulnerabilities Notification
Something I thought id share with the wider community as more then likely most people wont be aware of this, or will have a different...
William Clarkson-Antill
Nov 8, 20231 min read


Microsoft Sentinel - Creating Parsers within a Workspace
I thought I'd write some tips, tricks, and notes on how to build out an effective parser for your Sentinel Workspace. There are a heap of...
William Clarkson-Antill
Oct 18, 20232 min read


Information on Signing up for the Microsoft Private Preview Community
I thought I would share some details of how to get into the Microsoft Private Preview Community, for the sake of sharing new ideas,...
William Clarkson-Antill
Oct 9, 20233 min read










