all posts

· 1 min read

Hello, world: welcome to the blog

What this blog is for, and a quick tour of the formatting it supports, from KQL highlighting to tables.

This is where I'll write up threat hunting queries, detection engineering notes and cloud attack research. Expect a lot of Sentinel, Defender and KQL.

This post doubles as a formatting reference. Delete it or set draft: true once you've written your first real post.

Code blocks

Fenced code blocks are highlighted at build time. Add a title and line numbers in braces to highlight specific lines:

Users signing in from many countries
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| extend Country = tostring(LocationDetails.countryOrRegion)
| summarize Countries = make_set(Country), CountryCount = dcount(Country) by UserPrincipalName
| where CountryCount > 2
| order by CountryCount desc

Other languages work too:

Get-MgAuditLogSignIn -Filter "status/errorCode eq 50126" -Top 50 |
    Select-Object UserPrincipalName, IpAddress, CreatedDateTime
nmap -sV -p 1-1000 10.0.0.0/24 -oA homelab-scan

Inline code like DeviceProcessEvents works as well.

Tables

GitHub-flavoured Markdown tables are supported:

Table What it holds
SigninLogs Entra ID interactive sign-ins
DeviceProcessEvents Process creation on MDE-onboarded devices
AzureActivity Azure control-plane operations

Lists and tasks

  • Threat hunting write-ups
  • Detection rules with the reasoning behind them
  • Homelab builds

Task lists work too:

  • Launch the blog
  • Publish the Azure covert C2 research

Link to anything, like my portfolio. Put images in public/images/ and reference them as /images/your-file.png.