Skip to main content
Jerrad Dahlager
Jerrad Dahlager, CISSP, CCSP Cloud Security Architect Β· Adjunct Instructor
About me β†’

From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel

Featured image for Cloud Security

CISA originally released the Microsoft Expanded Cloud Logs Implementation Playbook on January 15, 2025. The CISA resource page shown below also has a May 1, 2026 revision date, and the May 2026 DOCX I reviewed is marked as version 1.1 with general …

Copy Fail in the Cloud: A Defender, Sentinel, and AKS Response Guide for CVE-2026-31431

Featured image for Cloud Security

A Linux local privilege escalation bug is easy to dismiss if you only think in traditional server terms. An attacker already needs local access, so how bad can it be? In cloud environments, that assumption breaks fast. A compromised container, a …

Agent 365 Launch Playbook: I Tested the Defender Response for AI Agent Attacks

Featured image for Cloud Security

Microsoft announced that Agent 365 would become generally available on May 1, 2026. Most launch-week posts explain what it is. I wanted to answer a different question: What does an AI agent attack look like in a real Microsoft defender stack as Agent …

Scan Every Blob, Trace Every Read: Defender for Storage + Sentinel

Featured image for Cloud Security

Storage is where malware waits. A blob uploaded to ingest/ by a pipeline step, a partner’s SFTP connector, or a misconfigured Logic App sits quietly until something downstream opens it β€” a Data Factory copy, a Function app, a Synapse notebook, a …

Investigate Hidden Privilege Paths with Microsoft Sentinel Data Federation and Custom Graphs

Featured image for Cloud Security

After a compromised service principal incident, the first triage question is always the same: β€œWhat else can this identity reach?” The answer usually lives outside Sentinel, buried in entitlement exports, RBAC snapshots, or asset inventories that …

Building Custom Sentinel Connectors in One Click with CCF Push

Featured image for Cloud Security

Getting custom data into Microsoft Sentinel has traditionally required a lot of moving parts. You need a Data Collection Endpoint, a Data Collection Rule, an Entra app registration with a client secret, RBAC role assignments, a custom table …

AKS Runtime Security: Binary Drift, Anti-Malware & Gated Deployment with Defender for Cloud

Featured image for Cloud Security

In December, I published a post on securing the container supply chain β€” SBOM generation, image signing, and build provenance with GitHub Actions. That covered build-time security: making sure the image you ship is the image you built. But what …

The February 2026 Microsoft Sentinel Drop: UEBA Essentials, Copilot Connector, and 9 New GA Connectors

Featured image for Cloud Security

February 2026 brought one of the more substantial Sentinel drops in recent memory. UEBA Essentials hit v3.0.6 with a refined workbook and more than 30 hunting queries (including multi-cloud detections shipped in earlier releases), the M365 Copilot …

Sentinel MCP Server: Securing Your SOC's New AI Attack Surface

Featured image for Cloud Security

In September 2025, Microsoft announced the Sentinel MCP Server, a Model Context Protocol implementation that lets MCP-compatible AI assistants query your Sentinel data using natural language. Microsoft highlights GitHub Copilot, Copilot Studio, and …

Terraform 1.11 Write-Only Arguments: Keep Supported Secrets Out of State

Featured image for Cloud Security

If you’ve worked with Terraform and secrets, you’ve probably wondered: β€œWait, is my password actually in that state file?” The answer has historically been: yes. The sensitive = true flag does a great job hiding values from CLI output, but the state …

Keyboard Shortcuts

Navigation
Ctrl + K Open search / command palette
? Show this help
ESC Close dialogs
Actions
G then H Go to Home
G then B Go to Blog
G then A Go to About
G then C Go to Contact
G then T Go to Threat Feeds
G then G Go to Glossary
Shift + C Copy page URL
Easter Eggs
↑↑↓↓←→←→BA Konami code
Click cat 9Γ— Nine lives activation
Click logo 9Γ— Cat Burglar mode