Deployed a cloud-native SIEM integrating Microsoft Azure infrastructure, Windows endpoints, Micro...Deployed a cloud-native SIEM integrating Microsoft Azure infrastructure, Windows endpoints, Micro...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Deployed a cloud-native SIEM integrating Microsoft Azure infrastructure, Windows endpoints, Microsoft 365, and Defender XDR telemetry into a unified detection and response platform.
Wrote KQL analytics rules for real-time threat detection covering: privilege escalation, suspicious PowerShell execution, lateral movement via RDP and SMB, anomalous Azure AD sign-ins, and malware execution patterns. Automated incident response using Azure Logic Apps.
Reduced log ingestion costs by 20% through optimised data collection, balancing coverage against cost without losing detection fidelity.
Published full write-up on Medium: medium.com/@babsib2dk
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started