Detecting Suspicious RMM Tool Execution Chains in Microsoft Defender (T1219)

One of the most common initial access vectors into environments by threat actors is through use of legitimate RMM tooling, offering both hands-on-keyboard access as well as stealth. Read more below for some considerations on detecting such activity.

July 10, 2026 · 9 min · Matt Swann

Detection Deep Dive: Encoded PowerShell Commands (T1059.001)

The first entry in the Detection Deep Dive series: mapping encoded PowerShell execution to detection logic in Microsoft Defender, tuning out the false positives, and knowing what the detection can’t see.

July 7, 2026 · 4 min · Matt Swann

How a Single KQL Query Stopped an Entire EvilTokens Phishing Campaign

An AI-powered PhaaS campaign leaned on legit-vendor redirects and device-code phishing — but spoofing left a fingerprint. One KQL query plus a 5-minute MDE automation loop neutralized over 1,200 malicious emails in 48 hours.

June 11, 2026 · 4 min · Matt Swann

5 KQL Queries to Slash Your Containment Time in Microsoft Sentinel

In an active breach, speed is everything. These five KQL queries — covering file drops, identity compromise, lateral movement, C2 beaconing, and persistence — are designed for the first hour of incident response.

January 5, 2026 · 8 min · Matt Swann