//Cyber.Engineer

Azure Sentinel: Adding Threat Indicators Manually

You can either have an automated Cyber Threat Intelligence feed (STIX/TAXII) or your threat indicators can be added manually in the form of IP, Domain, URL File hash. Let's run through the manual process.

Azure Sentinel: Querying for your Cyber Threat Indicators

All CTI entries aren't just available to view in the "Threat Intelligence" page - they are stored in the Log Analytics Workspace table "ThreatIntelligenceIndicator". Here you will find the manually submissions, but also any automated feeds from STIX/TAXII.

General Availability of Azure Sentinel Threat Intelligence in Public and Azure Government cloud

General Availability of Azure Sentinel Threat Intelligence in Public and Azure Government cloud

Saying goodbye to Exchange Online basic auth

A recent announcement from Microsoft regarding Exchange Online and Basic Auth - finally making that last push to get it removed.

KQL Cheatsheet

A page full of useful KQL queries when you need to look for some quick ideas Una comparación útil de equipaciones de fútbol completas comienza por la temporada, el diseño y los detalles visibles. Para evitar errores, merece la pena revisar las instrucciones de cuidado y cualquier límite aplicable a

//Cyber.Engineer © 2026