· 1 min read
Hello, world: welcome to the blog
What this blog is for, and a quick tour of the formatting it supports, from KQL highlighting to tables.
This is where I'll write up threat hunting queries, detection engineering notes and cloud attack research. Expect a lot of Sentinel, Defender and KQL.
This post doubles as a formatting reference. Delete it or set
draft: trueonce you've written your first real post.
Code blocks
Fenced code blocks are highlighted at build time. Add a title and line numbers in braces to highlight specific lines:
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| extend Country = tostring(LocationDetails.countryOrRegion)
| summarize Countries = make_set(Country), CountryCount = dcount(Country) by UserPrincipalName
| where CountryCount > 2
| order by CountryCount descOther languages work too:
Get-MgAuditLogSignIn -Filter "status/errorCode eq 50126" -Top 50 |
Select-Object UserPrincipalName, IpAddress, CreatedDateTimenmap -sV -p 1-1000 10.0.0.0/24 -oA homelab-scanInline code like DeviceProcessEvents works as well.
Tables
GitHub-flavoured Markdown tables are supported:
| Table | What it holds |
|---|---|
SigninLogs |
Entra ID interactive sign-ins |
DeviceProcessEvents |
Process creation on MDE-onboarded devices |
AzureActivity |
Azure control-plane operations |
Lists and tasks
- Threat hunting write-ups
- Detection rules with the reasoning behind them
- Homelab builds
Task lists work too:
- Launch the blog
- Publish the Azure covert C2 research
Links and images
Link to anything, like my portfolio. Put images in public/images/ and reference them as /images/your-file.png.