//Cyber.Engineer

Azure Sentinel: Querying for your Cyber Threat Indicators

All CTI entries aren't just available to view in the "Threat Intelligence" page - they are stored in the Log Analytics Workspace table "ThreatIntelligenceIndicator". Here you will find the manually submissions, but also any automated feeds from STIX/TAXII.

General Availability of Azure Sentinel Threat Intelligence in Public and Azure Government cloud

General Availability of Azure Sentinel Threat Intelligence in Public and Azure Government cloud

KQL Cheatsheet

A page full of useful KQL queries when you need to look for some quick ideas Una comparación útil de equipaciones de fútbol completas comienza por la temporada, el diseño y los detalles visibles. Para evitar errores, merece la pena revisar las instrucciones de cuidado y cualquier límite aplicable a

Whitelisting your client's IP Range in MCAS

How to whitelist corporate IP range in Microsoft Cloud App Security. Ultimately reducing false positives in your SOC.

//Cyber.Engineer © 2026