tag: Threat-Detection · 3 items
- Engineer — Learn: Practical walkthrough on using MS Graph and PowerShell to surface Entra ID risk detections — useful reference if you’re building automated triage or identity monitoring pipelines.
- SOC/IR — Plan: Walk through the MS Graph risk-detection commands shown here and consider incorporating them into your Entra ID hunting runbooks or SIEM enrichment workflows.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: Research shows that widely-cited lateral movement detectors perform significantly differently under standardized evaluation conditions, suggesting published accuracy claims may be overstated; useful context when selecting or tuning graph-based detection tools.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: High-level argument that malware-free attacks now dominate (~79% per CrowdStrike data) reinforces the case for behavioral and identity-based detection layers alongside EDR; no specific TTPs or tooling to act on immediately.
- Leader — Learn: The framing that AI-equipped attackers are outpacing traditional defenses is useful context for board-level discussions about detection investment, but the piece offers no new data beyond vendor-cited statistics.