Defender-Xdr
Lessons from the field. Always landing on my feet.
All
Cloud Security
Microsoft Sentinel
Identity Security
AI Security
Detection Engineering
Microsoft Defender
Threat Detection
Container Security
Entra ID
DevSecOps
Infrastructure as Code
Zero Trust
Agentic AI
2 posts
GigaWiper Detection as Code: Testing the Sentinel Repositories Preview
Microsoft published its technical analysis of GigaWiper on July 9, 2026. Microsoft describes it as a modular backdoor with destructive capabilities, including scheduled-task persistence, RabbitMQ-over-AMQP command C2, Redis status and output β¦
Block Device Code Phishing in Entra Without Breaking Legit Workflows
Device code phishing is nasty because the user does not hand over a password. They hand over a session. The lure sends the victim to a legitimate Microsoft device sign-in page. The victim enters a short code. Entra ID issues tokens to the attackerβs β¦

