READ THE BLOG / EXPLORE THE LABS / LET'S CONNECT
Cloud Security Architect · Adjunct Instructor · U.S. Marine Corps veteran
I build and document practical cloud security: stronger identities, useful detections, and repeatable engineering. Nine Lives, Zero Trust is where I share the designs, labs, and lessons along the way.
| Focus | Tools and techniques |
|---|---|
| Identity & Zero Trust | Entra ID · Conditional Access · phishing-resistant authentication |
| Detection & response | Microsoft Sentinel · Defender XDR · KQL · detection as code |
| Cloud & DevSecOps | Azure · AWS · Terraform · GitHub Actions · container security |
|
01 / DETECTION ENGINEERING GigaWiper Detection as Code ↗ Behavior-based Defender XDR detections, Bicep, and safe telemetry validation. |
|
02 / IDENTITY SECURITY Entra Device Code Phishing ↗ Sentinel analytics, Defender XDR hunts, and synthetic replay for device-code investigations. |
|
03 / SOFTWARE SUPPLY CHAIN Container Supply Chain ↗ Keyless image signing, signed SBOMs, and SLSA provenance with GitHub Actions. |
The latest from Nine Lives, Zero Trust · Refreshed daily
Microsoft Security Fall 2026: Five Changes to Prepare For
Sep 12, 2026
Review update (September 25, 2026): The integration identity used for incident comments can require tenant-wide incident-write permission, not a…
Entra SSPR and Passkey Readiness for Microsoft-Provided SMS/Voice Delivery Retirement
Aug 11, 2026
Microsoft is advancing three related parts of the Entra authentication and recovery experience through July 2027: On September 1, 2026, Microsoft…
GigaWiper Detection as Code: Testing Custom Detections in Sentinel Repositories
Jul 13, 2026
Review update (September 25, 2026): The merged September 25 source now chooses a labeled executable identity from populated SHA1, then SHA256, then a…
From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel
May 10, 2026
Review update (September 25, 2026): The January 15, 2025 publication date is supported by CISA’s original release notice; the resource landing page…
Copy Fail in the Cloud: A Defender, Sentinel, and AKS Response Guide for CVE-2026-31431
May 2, 2026
Review update (September 25, 2026): The retained Sentinel/AKS evidence was captured May 2, 2026, without executing Copy Fail exploit code. The May 3…
More field notes → · Subscribe via RSS
Stay curious. Keep building.
nineliveszerotrust.com · LinkedIn



