Series · 8 parts
Building a Sentinel detection lab
How I built a Sentinel lab from scratch, licensing walls and all.
- Part 1 ·
Catching Brute Force (and the Bug That Flagged the Wrong Account)
Writing my first detection, and the parsing bug that taught me more than the detection itself.
- Part 2 ·
Suspicious PowerShell, and Why Some Detections Need No Threshold
Hunting malicious PowerShell with Sysmon, and the difference between volume detections and signature detections.
- Part 3 ·
My Detection Flagged Legitimate Windows Behavior. Here's How I Tuned It Without Going Blind
Registry persistence, a textbook false positive, and the single most important lesson in detection engineering.
- Part 4 ·
Catching Reconnaissance, and the Case-Sensitivity Bug That Made It Look Broken
The first detection in the lab that looks for a pattern of behavior, and the case-sensitivity bug that made it look broken.
- Part 5 ·
MFA Registration, a Missing License, and the First Detection That Talks Back
Attackers registering their own MFA methods to keep access after a password reset, and the first detection that talks back.
- Part 6 ·
Shadow AI and the Detection That's Honest About What It Hasn't Proven Yet
AI tooling showing up on endpoints with nobody in IT knowing it's there.
- Part 7 ·
The Detection That Taught Me My Own Telemetry's Blind Spot
Where AI tooling talks to once it's running, and the most useful failure in the lab so far.
- Part 8 ·
Watching for Agents, Not Just Attackers
The same process-lineage technique, pointed at a different actor: not a human attacker, an AI agent.