Skip to main content

Choose a project

Open any project below for its purpose, prerequisites, deployment and cleanup steps, exact reviewed source revision, safety boundaries, and companion article. Start with the outcome you want, then read the complete project page before running commands in your own environment.

What the evidence labels mean

The deployment or behavior was exercised and retained evidence is described on the project page.
The source, safety controls, and documentation were checked, but the current revision was not freshly deployed end to end.
A source-backed walkthrough or architecture pattern. Its page identifies what you still need to configure and validate in your environment.

The date beside each project label is its evidence or source-review boundaryβ€”not a guarantee that a cloud provider, subscription, or tenant will behave identically today.

Explore 13 projects

Choose a project to see its source, prerequisites, safety notes, implementation steps, and companion write-up.

Agent 365 Defender Playbook

Validate current Defender for AI Services model alerts and Sentinel correlations for a tool-using Azure AI application.

GigaWiper Detection as Code

Validate five behavior-based Defender XDR custom-detection designs with live and synthetic evidence, document an observed Sentinel Repositories preview result, and use a bounded Graph-only OIDC fallback without destructive activity.

AKS Runtime Security with Defender for Cloud

Deploy binary drift detection, container anti-malware, and gated deployment on AKS with Microsoft Defender for Cloud. Includes Bicep templates, KQL detections, and a Sentinel workbook.

Defender for Storage Malware Scanning and Sentinel

Deploy malware scanning for uploaded blobs and correlate post-verdict reads in Sentinel with Bicep, analytics rules, a workbook, and safe simulations.

LLM Prompt Injection Firewall

Deploy a serverless prompt injection firewall with AWS Lambda, API Gateway, and DynamoDB. Complete Terraform code included.

OAuth Redirect Abuse Detection with Microsoft Sentinel

Deploy Sentinel analytics rules and a security workbook, run a read-only OAuth audit, and optionally apply Entra ID hardening; five KQL hunting queries are included for manual use.

Entra Device Code Phishing Detection

Hunt device-code phishing across Sentinel and Defender XDR with safe replay data, telemetry checks, KQL detections, and a triage checklist.

Custom Sentinel Connector with CCF Push

Build a reviewed CCF Push artifact set and owned Sentinel sandbox for Feodotracker ingestion, rule examples, hunting, and visualization.

Detecting Infostealer Session Hijacking in Microsoft Sentinel

Deploy 5 Sentinel analytics rules and a Session Hijack Threat Dashboard, with 5 included hunting queries for stolen-token and session-hijack investigations.

Just-In-Time Access for AI Agents in Azure

Deploy a ZSP gateway that grants temporary Azure permissions to AI agents, automation workflows, and service principals. Bicep + PowerShell included.

Container SBOM, Signing, and Attestation

Build a keyless container supply-chain pipeline with vulnerability scanning, SBOM generation, signing, provenance, and deployment verification.

Sentinel Data Federation and Custom Graphs

Guide for federating synthetic security context into Sentinel and modeling hidden privilege paths with reusable KQL, GQL, and sample tables.

Keep Supported Secrets Out of Terraform State

Compare traditional secret arguments with Terraform write-only and ephemeral patterns across AWS and Azure, then scan state for accidental exposure.