Category: Information Security
35 posts
- Best Practices for Building a Secure New-Hire Account Activation Workflow
Onboarding is a uniquely high-risk process in that the IT department creates new identities and communicates with people who may not yet be fully embedded in th
- Migrate Splunk to Sentinel Without Losing Detection Coverage
A phased playbook for migrating Splunk to Microsoft Sentinel: audit detections, translate SPL to KQL, validate parity, and plan rollback.
- Entra PIM vs. Delinea vs. CyberArk: Don’t Buy the Wrong PAM
Entra PIM grants roles; Delinea and CyberArk vault credentials. Compare scope, session recording, audit evidence, and three-year cost.
- Deploy PAWs with Microsoft Entra PIM
Harden privileged access by pairing Microsoft Entra PIM with PAWs, Intune compliance, and Conditional Access so admin roles activate only from trusted devices.
- A Practical Guide to Kubernetes Security Management
Manage Kubernetes security with RBAC, Pod Security, network policies, posture scanning, and runtime detection using Kubescape, Falco, and Defender.
- Taming AI Tool Sprawl: A PowerShell Guide to Auditing and Governing Unauthorized AI Applications
Detect and govern unauthorized AI tools with PowerShell, Microsoft Graph, Entra ID, and Defender for Cloud Apps.
- CMMC 2.0 Level 2: Your 2026 Compliance Blueprint
Build a 2026 CMMC Level 2 roadmap: scope CUI, implement 110 NIST SP 800-171 controls, prepare evidence, and plan for C3PAO assessment.
- Unify Your SOC: Integrating Defender XDR with Sentinel
Integrate Defender XDR with Microsoft Sentinel for unified incidents, endpoint event streaming, cross-product detections, and SOAR.
- Automate Your SOC: A Guide to Sentinel Playbook Generation
Generate Microsoft Sentinel Python playbooks with AI, Integration Profiles, real-alert testing, and safe SOC automation rollout steps.
- The Death of Security Questions: Why Identity Proofing Is the Future of Service Desk Security
Specops sponsored article explaining why service desk account recovery needs identity proofing instead of knowledge-based security questions.
- Reduce Microsoft Sentinel Ingestion Costs with Smarter Tiering
Learn how to reduce Microsoft Sentinel ingestion costs by filtering noisy logs at ingest, routing low-value data to cheaper tiers, and proving the savings with
- Cloud Security Engineer Guide: Salary, Certs, Roadmap (2026)
Learn how to become a cloud security engineer, compare 2026 salary ranges, choose certs, and build a 12-month roadmap to hiring-ready proof.
- 7 Steps to Implement SASE Architecture in Enterprise
A step-by-step SASE implementation guide for enterprise: assess topology, choose single-vendor vs. best-of-breed, configure ZTNA policies, deploy SD-WAN, and me
- Entra Automation: Users, Groups, and Conditional Access
Use Microsoft Graph PowerShell to automate Entra ID users, security groups, group membership, and Conditional Access policies with report-only validation.
- Protect Sensitive Data with Microsoft Purview DLP Policies
Configure Microsoft Purview DLP in M365 to protect sensitive data across Teams, Exchange, and SharePoint with sensitive information types and policy templates.
- Stop Multi-Stage Attacks with Microsoft Sentinel AI
Learn how Microsoft Sentinel’s Fusion engine, UEBA, and SOAR automation detect multi-stage threats before attackers achieve their objectives.
- Stop Silent Event Loss at Scale with Windows Event Collector
Enterprise Windows Event Collector architecture: subscription types, XPath optimization, capacity planning, and SIEM integration at scale.
- Stop GitHub Copilot From Leaking Your Enterprise Data
Learn how GitHub Copilot exposes enterprises to data leakage, insecure code, IP risks, and IDE-level attacks—and how to build a governance framework that works.
- 7 Tips for an Efficient and Secure Active Directory Setup
Learn 7 essential best practices for setting up an efficient and secure Active Directory environment, from planning your structure and applying least-privilege
- Azure Confidential Computing: Protect Data During Processing
Protect sensitive data during processing with Azure confidential computing using secure enclaves and hardware-based encryption technologies.
- Staying Certified with the Updated NCSC Cyber Essentials
Learn how to stay secure and certified with the newly updated NCSC Cyber Essentials certification in this ATA Learning article!
- How to Test Your Defenses with Practical Brute Force Attacks
Learn a variety of techniques to test and defend against malicious brute force attacks in this ATA Learning tutorial!
- Stop the Confusion: Keep End Users Secure with Strong Passwords
Utilize the best practices of 2022 to create strong passwords and policies with recently updated NIST guidelines and enforce them with Specops Password Policy!
- How To Use Netcat and Level-Up Your Networking Skills!
Learn how to use Netcat to enhance and level-up your networking and debugging skills with this powerful networking utility!
- Avoid Kerberoasting Attacks with a Secure Service Desk
Learn how a Kerberoasting attack works, its implications, and best practices to protect yourself. Protect yourself further with a secure service desk.
- Using Pageant Putty Agent to Unleash Your SSH Key Use
Learn how to streamline and unleash your SSH key use with the Pageant Putty agent in this ATA Learning tutorial!
- Master In-Depth Security Audits with OpenSCAP
Learn how to perform in-depth security audits on your server with OpenSCAP and SCAP Security Guide (SSG) in this step-by-step tutorial!
- Passwork: A Modern Password Manager for 2022
Passwork offers a modern and flexible password management solution for enterprises in a secure self-hosted solution!
- A Weak Password List Says Hack Me: Protect Yourself
Learn how easy cracking an NTLM password is and how to avoid hacked accounts by using a weak password list to ban insecure passwords!
- How to Install and Configure the CSF Firewall for Linux
Learn how to install and configure the CSF firewall for Linux and secure your server in this step-by-step tutorial!
- Configuring Suricata as an Intrusion Prevention System (IPS)
Learn how to configure Suricata IPS to detect and prevent suspicious activities on your network with this step-by-step tutorial!
- Getting Started with Lynis Security Auditing
Learn how to use the free Lynis auditing tool to scan your systems for vulnerabilities and build tons of useful reports.
- How to Track Important Windows Security Events with PowerShell
Learn how Windows security events are stored, how to manage audit policies and how to build a helpful PowerShell tool to track down security events.
- How to Install and Set Up an AWS CloudWatch Agent
CloudWatch is an AWS service that centrally manages all of logs. Learn how to set up the CloudWatch agent for Windows in this tutorial.
- Install Nessus on Kali and Enhance Linux Distribution
Install Nessus on Kali Linux, configure a network vulnerability scan, and learn to scan the local Kali Linux installation!