rcegan (@rcegann) 's Twitter Profile
rcegan

@rcegann

Microsoft Sentinel Practice Lead @ MSSP. Defender, Detection Engineering, Threat Emulation. Blog-haver. Hack the planet.

ID: 838713770

linkhttps://rcegan.xyz calendar_today21-09-2012 23:09:22

1,1K Tweet

317 Followers

676 Following

rcegan (@rcegann) 's Twitter Profile Photo

Anyone ever setup the 'Repositories' feature in Microsoft Sentinel and had it work across multiple tenants? πŸ‘€

rcegan (@rcegann) 's Twitter Profile Photo

As a detection engineer, detection objectively sucks compared to prevention ;) Stop the baddies first, and keep the SOC alerts low :))

rcegan (@rcegann) 's Twitter Profile Photo

In keeping with the tenets of Elastic's detection engineering maturity model, I am going to spin up a DaC lab and see how we go. The native Sentinel 'Repositories' feature is a little underbaked, and I need to support multiple SIEM platforms, so should be good fun. 😎

rcegan (@rcegann) 's Twitter Profile Photo

After 6 years in the industry and multiple years fiddling with ci/cd pipelines, the day has come for me to finally perform a 3-way git merge

rcegan (@rcegann) 's Twitter Profile Photo

If anyone has designed Detection as Code repos and pipelines with CI/CD pushing content to *many* SIEM instances simultaneously, I'd love to talk! Designing something similar and I want to compare notes.

rcegan (@rcegann) 's Twitter Profile Photo

Today's a rare moment where I'm thankful the majority of orgs I know have migrated to M365 and SharePoint Online πŸ‘€

rcegan (@rcegann) 's Twitter Profile Photo

Detection as Code update: * I have a YAML to ARM script (I'm working in Sentinel) turning the psuedo code into an analytics rule * I have a script for deploying ARM templates into different (or multiple) Sentinel instances * A basic CI/CD pipeline Just need to put it all

Justin Elze (@hackinglz) 's Twitter Profile Photo

Enjoyable leak from NK And Twitter/X is blocking the URL :( http[s]://data.ddosecrets.com/APT%20Down%20-%20The%20North%20Korea%20Files/

rcegan (@rcegann) 's Twitter Profile Photo

Shoutout to the folks at CrowdStrike who maintain FalconPy. Honestly such a great and easy to use wrapper for the bajillions of APIs that exist. My Detection as Code repo now supports NG-SIEM rules, alongside MS Sentinel 🀘🀘