Skip to content
View j-dahl7's full-sized avatar

Block or report j-dahl7

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
j-dahl7/README.md
Nine Lives, Zero Trust — Curiosity Verified. Jerrad Dahlager, Cloud Security.

READ THE BLOG   /   EXPLORE THE LABS   /   LET'S CONNECT

Hey, I'm Jerrad.

Cloud Security Architect · Adjunct Instructor · U.S. Marine Corps veteran

I build and document practical cloud security: stronger identities, useful detections, and repeatable engineering. Nine Lives, Zero Trust is where I share the designs, labs, and lessons along the way.

What I work on

Focus Tools and techniques
Identity & Zero Trust Entra ID · Conditional Access · phishing-resistant authentication
Detection & response Microsoft Sentinel · Defender XDR · KQL · detection as code
Cloud & DevSecOps Azure · AWS · Terraform · GitHub Actions · container security

Featured labs

01 / DETECTION ENGINEERING
GigaWiper Detection as Code ↗

Behavior-based Defender XDR detections, Bicep, and safe telemetry validation.

02 / IDENTITY SECURITY
Entra Device Code Phishing ↗

Sentinel analytics, Defender XDR hunts, and synthetic replay for device-code investigations.

03 / SOFTWARE SUPPLY CHAIN
Container Supply Chain ↗

Keyless image signing, signed SBOMs, and SLSA provenance with GitHub Actions.

Explore all labs →

Latest Blog Posts

The latest from Nine Lives, Zero Trust · Refreshed daily

Microsoft Security Fall 2026: Five Changes to Prepare For
Sep 12, 2026

Review update (September 25, 2026): The integration identity used for incident comments can require tenant-wide incident-write permission, not a…

Entra SSPR and Passkey Readiness for Microsoft-Provided SMS/Voice Delivery Retirement
Aug 11, 2026

Microsoft is advancing three related parts of the Entra authentication and recovery experience through July 2027: On September 1, 2026, Microsoft…

GigaWiper Detection as Code: Testing Custom Detections in Sentinel Repositories
Jul 13, 2026

Review update (September 25, 2026): The merged September 25 source now chooses a labeled executable identity from populated SHA1, then SHA256, then a…

From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel
May 10, 2026

Review update (September 25, 2026): The January 15, 2025 publication date is supported by CISA’s original release notice; the resource landing page…

Copy Fail in the Cloud: A Defender, Sentinel, and AKS Response Guide for CVE-2026-31431
May 2, 2026

Review update (September 25, 2026): The retained Sentinel/AKS evidence was captured May 2, 2026, without executing Copy Fail exploit code. The May 3…

More field notes →   ·   Subscribe via RSS

Certifications

CISSP CCSP AWS Solutions Architect Professional Azure Solutions Architect Expert Cybersecurity Architect Expert Azure Security Engineer Associate Azure Administrator Associate

The contribution trail

Snake animation


Stay curious. Keep building.
nineliveszerotrust.com · LinkedIn

Pinned Loading

  1. MicrosoftDocs/azure-docs MicrosoftDocs/azure-docs Public

    Open source documentation of Microsoft Azure

    Markdown 11k 21.8k