kql
Lessons from the field. Always landing on my feet.
All
Cloud Security
Identity Security
Microsoft Sentinel
AI Security
Detection Engineering
Microsoft Defender
Threat Detection
Entra ID
Container Security
Zero Trust
DevSecOps
Infrastructure as Code
Agentic AI
12 posts
Detecting OAuth Redirect Abuse with Microsoft Sentinel and Entra ID
On March 2, 2026, Microsoft published an advisory on OAuth redirection abuse enabling phishing and malware delivery. Microsoft described phishing-led campaigns where attackers register OAuth apps with attacker-controlled redirect URIs, then send โฆ
The February 2026 Microsoft Sentinel Drop: UEBA Essentials, Copilot Connector, and 9 New GA Connectors
February 2026 brought one of the more substantial Sentinel drops in recent memory. UEBA Essentials hit v3.0.6 with a refined workbook and more than 30 hunting queries (including multi-cloud detections shipped in earlier releases), the M365 Copilot โฆ

