Discussion about this post

User's avatar
Neural Foundry's avatar

Really solid roundup of detection engineering updates across these repos. The KQL enrichment for AADSTS error codes is particularly clever since those raw codes are basically useless for triaging failed auth attempts without constantly looking them up. I've spent way too much time hunting down what ErrorCode 50126 actually means in the middle of an incident. Adding that lookup directly into the query saves like 10 steps and makes it way eaiser to spot patterns when authentication failures spike.

Expand full comment

No posts

Ready for more?