SOCAutomators
Helping build next generation security operations leveraging automations, risk analysis, machine learning and artificial intelligence.
- Indexed issues, last 90 days
- 9
- Latest publication
- Sep 30, 2026
- Audience
- Checking…
- Earliest in this view
- Jul 20, 2026
Latest issues
Defender ISOC Unleashed (opens the original)
Read excerpt
Why security sellers and consultants should know Defender ISOC and the Microsoft Sentinel data lakePreview note: Integrated Security Operations Center (ISOC) in Microsoft Defender is currently in preview. Capabilities, eligibility, and availability may change. Confirm the current status before recommending it for a production deployment.Microsoft’s security operations story is changing. Microsoft Defender XDR, Microsoft Sentinel, automation, threat intelligence, security data, and AI-assisted wo
Microsoft delivers security upgrade to Windows (opens the original)
Read excerpt
IT pros love a shiny new security product. A new dashboard, a new acronym, a new promise to stop the latest threat. But one of the most effective security investments is often much closer to home: securing Windows itself.Microsoft is making Windows more secure by expanding Memory Integrity protection across more eligible Windows devices. Beginning in October 2026, Windows quality updates will automatically enable Memory Integrity on additional supported systems after readiness chec
Change the Battlefield - Your ONLY choice (opens the original)
Read excerpt
The attackers have AI. You have decisions. You really want to buy more tools? You really think AI will save the SOC?Situation Report: The Front LineContoso Regional Health System is a fictional 2,000-user hospital I built to argue with. It runs 250 beds and seventeen ambulatory sites with four security people. Twenty-one of its unpatched vulnerabilities appear on CISA’s Known Exploited Vulnerabilities catalog, the federal list of flaws attackers are confirmed to be exploiting right now. The publ
Sentinel UEBA gets a major boost with new data sources (opens the original)
Read excerpt
Sentinel has made two significant changes to UEBA this week. They’ve added new data sources for UEBA behaviors and anomaly detection and is adding contextual anomaly insights directly to UEBA behavior records.New behaviorsThere are more than 40 new behavior signals from Fortinet FortiGate that can help identify potentially risky administrative activities such as configuration changes, certificate modifications, backups, and service disruptions. Sentinel also broadened anomaly detection support t
New Identity Timeline makes Defender investigations easier (opens the original)
Read excerpt
When investigating a potentially compromised user, context is everything. Security analysts need to understand not only what happened, but also how events across different systems and services connect to a single identity. Sign-in logs live in one place, endpoint activity in another, cloud application events somewhere else, and identity risk signals in yet another portal. This approach can slow investigations and make it harder to see the bigger picture.Security analysts need to understand not o
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.