READ THE BLOG / EXPLORE THE LABS / LET'S CONNECT
Cloud Security Architect · Adjunct Instructor · U.S. Marine Corps veteran
I build and document practical cloud security: stronger identities, useful detections, and repeatable engineering. Nine Lives, Zero Trust is where I share the designs, labs, and lessons along the way.
| Focus | Tools and techniques |
|---|---|
| Identity & Zero Trust | Entra ID · Conditional Access · phishing-resistant authentication |
| Detection & response | Microsoft Sentinel · Defender XDR · KQL · detection as code |
| Cloud & DevSecOps | Azure · AWS · Terraform · GitHub Actions · container security |
|
01 / DETECTION ENGINEERING GigaWiper Detection as Code ↗ Behavior-based Defender XDR detections, Bicep, and safe telemetry validation. |
|
02 / IDENTITY SECURITY Entra Device Code Phishing ↗ Sentinel analytics, Defender XDR hunts, and synthetic replay for device-code investigations. |
|
03 / SOFTWARE SUPPLY CHAIN Container Supply Chain ↗ Keyless image signing, signed SBOMs, and SLSA provenance with GitHub Actions. |
The latest from Nine Lives, Zero Trust · Refreshed daily
Entra SSPR and Passkey Readiness for Microsoft-Provided SMS/Voice Delivery Retirement
Aug 11, 2026
Microsoft is advancing three related parts of the Entra authentication and recovery experience between now and next March: On September 1, 2026…
GigaWiper Detection as Code: Testing the Sentinel Repositories Preview
Jul 13, 2026
Microsoft published its technical analysis of GigaWiper on July 9, 2026. Microsoft describes it as a modular backdoor with destructive capabilities…
From Authorization to Action: Operationalizing CISA's Microsoft Cloud Logs Playbook in Sentinel
May 10, 2026
CISA released the Microsoft Expanded Cloud Logs Implementation Playbook on January 15, 2025. Its implementation guidance remains a practical baseline…
Copy Fail in the Cloud: A Defender, Sentinel, and AKS Response Guide for CVE-2026-31431
May 2, 2026
A Linux local privilege escalation bug is easy to dismiss if you only think in traditional server terms. An attacker already needs local access, so…
Block Device Code Phishing in Entra Without Breaking Legit Workflows
Apr 25, 2026
Device code phishing is nasty because the user does not hand over a password. They hand over a session. The lure sends the victim to a legitimate…
More field notes → · Subscribe via RSS
Stay curious. Keep building.
nineliveszerotrust.com · LinkedIn



