Skip to content

Commit 61ff761

Browse files
committed
Jan 2026 updates
1 parent 85c84c5 commit 61ff761

6 files changed

Lines changed: 26 additions & 1 deletion

File tree

docs/entraid.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99

1010
## Microsoft Tech Community Blogs
1111

12+
- [Ignite’25 Spotlight: Announcing Microsoft Baseline security mode](https://techcommunity.microsoft.com/blog/microsoft_365blog/ignite%E2%80%9925-spotlight-announcing-microsoft-baseline-security-mode/4469709#community-4469709-authentication)
1213
- [Important Update: Azure AD Graph retirement](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-update-azure-ad-graph-retirement/4364990)
1314
- [Important Update: AzureAD PowerShell retirement](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/important-update-azuread-powershell-retirement/4364989)
1415
- [OAuth consent phishing explained and prevented](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/oauth-consent-phishing-explained-and-prevented/4423357)
@@ -1859,6 +1860,7 @@
18591860
- [Microsoft 365 Message Center Archive](https://mc.merill.net/)
18601861
- [Tier 0 Table](https://github.com/SpecterOps/TierZeroTable/)
18611862
- [https://www.entradocumentation.com/](https://www.entradocumentation.com/)
1863+
- [Conditional Access Documenter](https://idpowertoys.merill.net/ca)
18621864

18631865
## EntraOps Classification and Automation
18641866

docs/mde.md

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,11 +9,11 @@
99
- [What's new in Microsoft Defender for Endpoint on Mac](https://learn.microsoft.com/en-us/defender-endpoint/mac-whatsnew)
1010
- [What's new in Microsoft Defender for Endpoint on Linux](https://learn.microsoft.com/en-us/defender-endpoint/linux-whatsnew)
1111
- [Become a Microsoft Defender for Endpoint Ninja](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-for-endpoint-ninja-training-august-2021/ba-p/2611623)
12+
- [Defender for Endpoint - Error Codes](https://github.com/MicrosoftDocs/defender-docs/blob/public/defender-endpoint/event-error-codes.md)
1213

1314
## Microsoft Tech Community Blogs
1415

1516
- [Ignite 2025: Microsoft Defender now prevents threats on endpoints during an attack](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/ignite-2025-microsoft-defender-now-prevents-threats-on-endpoints-during-an-attac/4470805)
16-
1717
- [End of Windows 10 Support: What Defender Customers Need to Know](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/end-of-windows-10-support-what-defender-customers-need-to-know/4461349)
1818
- [Multi-tenant endpoint security policies distribution is now in Public Preview](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/multi-tenant-endpoint-security-policies-distribution-is-now-in-public-preview/4439929)
1919
- [Maintain connectivity for essential services with selective network isolation](https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/maintain-connectivity-for-essential-services-with-selective-network-isolation/4422938)
@@ -265,6 +265,11 @@
265265

266266
## Community Blogs
267267

268+
- [Bind Link – EDR Tampering](https://ipurple.team/2025/12/01/bind-link-edr-tampering/)
269+
- [Modern Security for Legacy Systems](https://medium.com/@verboonalex/modern-security-for-legacy-systems-0cb96f95a949)
270+
- [What is Microsoft Defender for Endpoint, for the Endpoint](https://kostaskoutrou.github.io/2025/12/17/what-is-mde.html)
271+
- [Microsoft Defender for Endpoint Internal 0x06 — Custom Collection](https://medium.com/falconforce/microsoft-defender-for-endpoint-internal-0x06-custom-collection-81fc1042b87c)
272+
- [Defender for Endpoint - Custom Data Collection Rules](https://infernux.no/blog/defenderforendpoint-customdatacollectionrules/)
268273
- [Guidance on how to manage products updates for Defender for Server on Linux distributions](https://vertho.tech/2025/08/27/guidance-on-how-to-manage-products-updates-for-defender-for-server-on-linux-distributions/)
269274
- [Tracking a device’s IP assignments with MDE’s DeviceNetworkInfo table](https://medium.com/@cybureauocracy/tracking-a-devices-ip-assignments-with-mde-s-devicenetworkinfo-table-430270ca539e)
270275
- [MDE’s DeviceNetworkEvents table [Part 2 — Connection* ActionTypes]](https://medium.com/@cybureauocracy/mdes-devicenetworkevents-table-part-2-connection-actiontypes-1c5ee20d2fc4)
@@ -370,6 +375,8 @@
370375
- [Microsoft Vulnerable Driver Block Lists](https://github.com/Cyb3r-Monk/Microsoft-Vulnerable-Driver-Block-Lists)
371376
- [Deploying Defender for Endpoint for macOS using Microsoft Intune](https://github.com/yujiaoMSFT/Microsoft-Defender-For-Endpoint/blob/main/macOS/Deploy-MDE-macOS-with-Intune/readme.md)
372377
- [MDE Monitoring App](https://github.com/chlaplan/MDE-Monitoring-App)
378+
- [TelemetryCollectionManager](https://github.com/FalconForceTeam/TelemetryCollectionManager)
379+
- [MISP2Defender](https://github.com/cudeso/misp2defender)
373380

374381
## Simulations
375382

docs/mdti.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@
77

88
## Microsoft Tech Community Blogs
99

10+
- [Detect more, spend less: the future of threat intelligence correlation](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/detect-more-spend-less-the-future-of-threat-intelligence-correlation/4468661)
1011
- [New Copilot for Security Plugin Name Reflects Broader Capabilities](https://techcommunity.microsoft.com/t5/microsoft-defender-threat/new-copilot-for-security-plugin-name-reflects-broader/ba-p/4258810)
1112
- [MDTI for Government Now Available](https://techcommunity.microsoft.com/t5/microsoft-defender-threat/mdti-for-government-now-available/ba-p/4258823)
1213
- [Introducing the MDTI Article Digest](https://techcommunity.microsoft.com/t5/microsoft-defender-threat/introducing-the-mdti-article-digest/ba-p/4223917)

docs/mdxdr.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -106,6 +106,7 @@
106106

107107
## Community Blogs
108108

109+
- [Migrating Microsoft Sentinel to Microsoft Defender XDR](https://infernux.no/blog/migratingsentineltodefenderxdr/)
109110
- [The ultimate Defender XDR RBAC visualization](https://vertho.tech/2025/09/29/the-ultimate-defender-xdr-rbac-visualization/)
110111
- [Remove old or orphaned Sentinels from the XDR Streaming API](https://cloudbrothers.info/remove-orphaned-sentinels-xdr-streaming-api/)
111112
- [Detect security policy changes](https://www.lousec.be/ad/detect-security-policy-changes/)

docs/sentinel.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,19 @@
88

99
## Microsoft Tech Community Blogs
1010

11+
- [Announcing AI Entity Analyzer in Microsoft Sentinel MCP Server - Public Preview](https://techcommunity.microsoft.com/blog/microsoft-security-blog/announcing-ai-entity-analyzer-in-microsoft-sentinel-mcp-server---public-preview/4476230)
12+
- [Microsoft Sentinel Platform: Audit Logs and Where to Find Them](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/microsoft-sentinel-platform-audit-logs-and-where-to-find-them/4481838)
13+
- [Managing Microsoft Sentinel and Microsoft Defender XDR permissions in Microsoft Defender portal](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/managing-microsoft-sentinel-and-microsoft-defender-xdr-permissions-in-microsoft-/4480583)
14+
- [Call to Action: Migrate Your Classic Alert‑trigger Automations to Automation Rules Before March 2026](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/call-to-action-migrate-your-classic-alert%E2%80%91trigger-automations-to-automation-rule/4479137)
15+
- [Efficiently process high volume logs and optimize costs with Microsoft Sentinel data lake](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/efficiently-process-high-volume-logs-and-optimize-costs-with-microsoft-sentinel-/4478110)
16+
- [What’s New in Microsoft Sentinel: December 2025](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-december-2025/4477063)
17+
- [Build less, secure more: Simplify security data management with Microsoft Sentinel data lake](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/build-less-secure-more-simplify-security-data-management-with-microsoft-sentinel/4474792)
18+
- [New Compliance Solutions in Microsoft Sentinel: HIPAA & GDPR Reports](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/new-compliance-solutions-in-microsoft-sentinel-hipaa--gdpr-reports/4470452)
19+
- [Ignite 2025: New Microsoft Sentinel Connectors Announcement](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/ignite-2025-new-microsoft-sentinel-connectors-announcement/4454613)
20+
- [Detect more, spend less: the future of threat intelligence correlation](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/detect-more-spend-less-the-future-of-threat-intelligence-correlation/4468661)
21+
- [Operationalizing the Sentinel data lake: A Practitioner’s Guide](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/operationalizing-the-sentinel-data-lake-a-practitioner%E2%80%99s-guide/4466042)
22+
- [Automating IOC hunts in Microsoft Sentinel data lake](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/automating-ioc-hunts-in-microsoft-sentinel-data-lake/4467113)
23+
- [What’s New in Microsoft Sentinel: November 2025](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sentinel-november-2025/4466061)
1124
- [Using Microsoft Sentinel MCP Server with GitHub Copilot for AI-Powered Threat Hunting](https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/using-microsoft-sentinel-mcp-server-with-github-copilot-for-ai-powered-threat-hu/4464980)
1225
- [Introducing Microsoft Sentinel graph (Public Preview)](https://techcommunity.microsoft.com/blog/microsoft-security-blog/introducing-microsoft-sentinel-graph-public-preview/4456368)
1326
- [Microsoft Sentinel data lake is now generally available](https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsoft-sentinel-data-lake-is-now-generally-available/4456342)

docs/social.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@
2424
- [Maarten Goet](https://bsky.app/profile/maartengoet.com)
2525
- [Ru Campell](https://bsky.app/profile/campbell.scot)
2626
- [Suryendu Bhattacharyya](https://bsky.app/profile/crookedbong.bsky.social)
27+
- [Truls](https://bsky.app/profile/truls.infernux.no)
2728

2829
## Defenders on X
2930

0 commit comments

Comments
 (0)