Incident Response & Detection Engineering
Practical IR, hunting, detections, playbooks, and operational learnings.
-
Microsoft Sentinel documentation hub
2024-10-09Central landing page for Sentinel features, data connectors, analytics, and operations.
-
Defender XDR overview and response workflows
2024-09-22Guidance for investigating incidents, correlating signals, and responding across the XDR stack.
-
Sentinel data connector reference
2024-07-29Connector catalog and setup guidance for bringing data into Sentinel.
-
Defender for Identity documentation
2024-06-18Identity-focused detection capabilities and investigation workflows.
-
KQL quick reference
2024-04-03Query language reference for building detections, hunts, and analytics.
Why it matters: Helpful for refining detection logic and hunting queries.
-
Defender for Endpoint documentation
2024-03-26Endpoint protection, investigation, and response guidance for Defender for Endpoint.
-
Security operations best practices
2024-02-01Guidance on SOC workflows, incident response, and security operations maturity.
Why it matters: Useful for aligning SOC operations and metrics.
-
Sentinel analytics rule templates
2024-01-18Overview of built-in analytics rules and detection templates.
-
Defender XDR incident response guide
2023-10-28Incident investigation workflow and response steps for Defender XDR.