Skip to main content
Jerrad Dahlager
Jerrad Dahlager, CISSP, CCSP Cloud Security Architect Β· Adjunct Instructor
About me β†’

From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel

Featured image for Threat-Hunting

CISA originally released the Microsoft Expanded Cloud Logs Implementation Playbook on January 15, 2025. The CISA resource page shown below also has a May 1, 2026 revision date, and the May 2026 DOCX I reviewed is marked as version 1.1 with general …

Block Device Code Phishing in Entra Without Breaking Legit Workflows

Featured image for Threat-Hunting

Device code phishing is nasty because the user does not hand over a password. They hand over a session. The lure sends the victim to a legitimate Microsoft device sign-in page. The victim enters a short code. Entra ID issues tokens to the attacker’s …

Detecting Infostealer Session Hijacking with Microsoft Sentinel

Featured image for Threat-Hunting

Nearly 70% of incidents in the Americas now begin with stolen or misused accounts. Infostealers are the engine behind that number – families like Lumma, RedLine, and Vidar export browser cookies and session tokens directly from the victim’s machine, …

Detecting OAuth Redirect Abuse with Microsoft Sentinel and Entra ID

Featured image for Threat-Hunting

On March 2, 2026, Microsoft published an advisory on OAuth redirection abuse enabling phishing and malware delivery. Microsoft described phishing-led campaigns where attackers register OAuth apps with attacker-controlled redirect URIs, then send …

Keyboard Shortcuts

Navigation
Ctrl + K Open search / command palette
? Show this help
ESC Close dialogs
Actions
G then H Go to Home
G then B Go to Blog
G then A Go to About
G then C Go to Contact
G then T Go to Threat Feeds
G then G Go to Glossary
Shift + C Copy page URL
Easter Eggs
↑↑↓↓←→←→BA Konami code
Click cat 9Γ— Nine lives activation
Click logo 9Γ— Cat Burglar mode