<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>leftanti</title><description>Detection engineering, KQL, and threat hunting notes.</description><link>https://leftanti.dev/</link><language>en-gb</language><item><title>Failed sign-on bursts from a single address</title><link>https://leftanti.dev/kql/failed-signon-burst/</link><guid isPermaLink="true">https://leftanti.dev/kql/failed-signon-burst/</guid><description>Groups failed Entra sign-ins by source address and application to surface password spraying, while ignoring the interrupt result codes that are not really failures.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>KqlLibrary</category><category>entra</category><category>identity</category><category>password-spray</category></item><item><title>Impossible travel that survives contact with a VPN estate</title><link>https://leftanti.dev/rules/impossible-travel-watchlist-suppression/</link><guid isPermaLink="true">https://leftanti.dev/rules/impossible-travel-watchlist-suppression/</guid><description>An impossible-travel rule is only as good as its suppression list. This one drives exclusions from a watchlist so the logic never has to be edited to add an egress range.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>AnalyticsRules</category><category>entra</category><category>identity</category><category>watchlists</category><category>false-positives</category></item><item><title>Where persistence hides in Entra app registrations</title><link>https://leftanti.dev/hunting/entra-app-registration-persistence/</link><guid isPermaLink="true">https://leftanti.dev/hunting/entra-app-registration-persistence/</guid><description>A hunt for credentials quietly added to existing service principals — the persistence that survives a password reset, an MFA enrolment, and a device wipe.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>ThreatHunting</category><category>entra</category><category>persistence</category><category>service-principals</category></item><item><title>BTL2 — network forensics reference</title><link>https://leftanti.dev/cheatsheets/btl2-network-forensics/</link><guid isPermaLink="true">https://leftanti.dev/cheatsheets/btl2-network-forensics/</guid><description>Ports, protocol tells, and the Wireshark and tcpdump filters worth having in muscle memory for the network forensics section of BTL2.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><category>CheatSheets</category><category>btl2</category><category>network</category><category>wireshark</category><category>pcap</category></item><item><title>Why I stopped writing 500-line analytics rules</title><link>https://leftanti.dev/notes/against-long-analytics-rules/</link><guid isPermaLink="true">https://leftanti.dev/notes/against-long-analytics-rules/</guid><description>Long detections feel thorough and behave badly. What actually goes wrong when one rule tries to cover six behaviours, and what to do instead.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>Notes</category><category>detection-engineering</category><category>opinion</category></item></channel></rss>