Insights & Guides

Practical Guidance on Security Frameworks, Compliance, and Implementation

Cybersecurity frameworks, compliance documentation, and security program implementation — written by a practitioner, not a content team.

Security insights and implementation guides
13 April 2026 Threat Hunting 6 min read

Hunting Mailbox Rules After Credential Compromise in M365

After an AiTM credential compromise, the attacker creates inbox rules within minutes — forwarding financial emails externally, hiding security notifications, staging data for BEC. Here is the KQL to find them, what the default Sentinel templates miss, and how to respond when you find one.

Read more →
13 April 2026 Detection Engineering 7 min read

The M365 Detections Microsoft Doesn't Give You

Microsoft ships 200+ Sentinel analytics rule templates. Coverage clusters around brute force, impossible travel, and known malware — leaving significant gaps in mailbox rule abuse, consent grant attacks, data staging, privilege escalation, and cross-tenant movement. Here are five detections you need to build yourself.

Read more →
7 April 2026 Security Operations 12 min read

Are Current SOCs Adequate for the Threats They Face?

Most SOCs were built for a threat landscape that no longer exists. Perimeter-era tools, single-environment playbooks, and alert-queue thinking are failing against identity-first, cross-environment attacks. Here's what the gap looks like from inside the operation.

Read more →
4 April 2026 Security Operations 10 min read

Is M365 Security All It's Hyped Up to Be?

Microsoft would like you to believe that an E5 licence is a security strategy. After years operating M365 security in production and running incident response through its tools, the reality is more nuanced than the marketing deck.

Read more →

Ready to strengthen your security program?

Browse our products or use our guide to find the right products for your organization.