UK Water Utility

Make recurring investigation questions reusable

Extend Defender Live Response with PowerShell and KQL

My KQL functions cover Entra sign-in context, VPN address attribution and Defender account actions. The accompanying runbooks explain investigation of NTLM/Kerberos brute force, Pass-the-Ticket, unwanted software, reconnaissance and Sysmon health. I also contributed investigation standards covering evidence, root cause, impact and response.

Return to the full story ←

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.