ISOC in Microsoft Defender is a benefit for M365 E5 and E7 customers, it is not a new product. Those lucky customers will save 44% off 3P security log ingestion.
I spent all day reading and broke it down here to bring it to you straight:
https://t.co/goKE8zSnUI
If you work in CTI, bookmark this:
CLOAK - a MITRE ATT&CK-style framework for cybercriminal concealment measures.
→ 1,387 TTPs
→ Technical, Behavioral & Physical layers
→ Open source
→ Updated Feb 2026
→ Interactive at https://t.co/ZcsxWU1w5N
Detection performance shouldn’t be buried across alerts and metrics. 📊
In our latest blog, we introduce and open-source #FalconDash - a modular dashboard built to make Microsoft Sentinel detection performance visible, explorable, and easier to tune. 🚀 https://t.co/0EVJcKB0VY
I made a little tool which you can use (with or without an LLM) to make (I think very cool) network diagrams, business process diagrams, and it features a journey mode to walk people through things!
https://t.co/qCbspVmAq7
We have conducted a thorough investigation into the Hugging Face incident.
We are releasing a technical report and accompanying blog post that reconstruct the agents’ activity, explain why existing safeguards failed, and detail how we’re preventing recurrence.
https://t.co/hfxlbiXXiP
Detection engineers don't want you to know this one trick
SigninLogs
| where AppDisplayName in ("OfficeHome", "Microsoft Azure CLI") and RiskLevelDuringSignIn in~ ("medium", "high")
Entra Cloud Sync finally supports syncing devices for Hybrid join 🥳
https://t.co/Ea1cmGOOLY
This was one of the last holdout features that was keeping folks on Entra Connect Sync, and for many, we can now retire that service and move to the more resilient Cloud Sync engine!
> Peter Stokes
> Scattered Spider guy
> Arrested
> Microsoft helps FBI
> Read court documents
> Page 12
> Microsoft tracks Stokes from GDID
> Microsoft Global Device Identifier (GDID)
> Stokes used Windows
> Page 34
> GDID assigned to each OS install
> GDID unique to each device
> GDID only change if OS wiped
> Stokes GDID 6755467234350028
> GDID reported internet activity to Microsoft
> GDID showed Stokes using Ngrok
> GDID reported Stokes IP address
> GDID showed Stokes web activity
> GDID showed timestamps of web activity
> GDID mapped with video game activity
> GDID showed games played
> GDID undocumented
> GDID only mentioned in one MSDN document
> Azure UCDOStatus
> Azure Monitor Logging
MICROSOFT OPEN-SOURCED A PII DETECTION SDK
presidio detects and anonymizes sensitive data before it ever touches your model
the problem is real: names, emails, SSNs, credit cards, medical records all flowing through LLM pipelines unfiltered
presidio stops that
▫️ detects PII in text, images, and structured data
▫️ redacts, masks, or anonymizes before it hits the model
▫️ supports NLP, regex, rule-based, and transformer detection
▫️ runs on Python, PySpark, Docker, and Kubernetes
▫️ even handles DICOM medical images
in an era of GDPR, HIPAA, and AI compliance audits, this is infrastructure not optional
https://t.co/pcEkm4mMt7