System Online

Cybersecurity Knowledge Hub

A curated collection of interactive mind maps, technical references, and security engineering resources — focused on Microsoft Purview, Entra ID, Defender XDR, and modern identity & data protection.

» Microsoft Security Engineer » Purview & Entra ID » Zero Trust Architecture

Identity & Access

0 items

Hybrid identity, Entra ID security stack, and Conditional Access — the foundations of Zero Trust.

Hybrid Identity

Microsoft Identity — Hybrid Mind Map

End-to-end view of Microsoft hybrid identity — on-premises AD DS, Entra Connect, Entra ID, and the security services that tie them together.

Entra ID

Microsoft Entra ID — Security Stack

The complete Entra ID security surface — PIM, Identity Protection, Access Reviews, Entitlement Management, External ID, Workload Identities, and Verified ID.

CA

Conditional Access — Mind Map

Entra ID Conditional Access — assignments, conditions, grant & session controls, authentication strengths, and every policy setting mapped visually.

Threat Protection & Endpoint

0 items

Defender XDR, Defender for Endpoint, and Intune — detection, response, and device management across the modern endpoint estate.

Defender XDR

Microsoft Defender Security Stack — Mind Map

The Defender XDR family at a glance — Defender for Endpoint, Identity, Office 365, Cloud Apps — unified incidents, hunting, and automated response.

MDE

Defender for Endpoint — Deep Dive

End-to-end MDE: onboarding, ASR rules, EDR, automated investigation & response, Threat & Vulnerability Management, and advanced hunting.

Intune

Microsoft Intune — Deep Dive

Intune end-to-end — MDM, MAM, compliance, configuration profiles, app protection, endpoint security baselines, and Autopilot.

MDA

Defender for Cloud Apps — Integration Mind Map

Interactive radial mind map of MDA's 7 capability areas and 25 features — with dotted lines tracing every integration with the Defender XDR stack, Purview, and Entra ID. Click a partner to trace its connections.

Data Protection & AI Security

0 items

Microsoft Purview for data governance, and the rapidly evolving AI threat landscape — from prompt injection to model-supply-chain risk.

Purview

Microsoft Purview — Mind Map

The full Purview surface — MIP sensitivity labels, encryption, auto-labeling, DLP, Endpoint DLP, Insider Risk Management, and Adaptive Protection.

AI Security

AI Security Threats — Microsoft Defense Map

The AI threat landscape — prompt injection, jailbreaks, data exfiltration via LLMs, model supply-chain attacks — and how Microsoft's stack defends against each.

OWASP · LLM

OWASP Top 10 LLM Attacks — Microsoft Defense Playbook

Interactive Matrix-styled playbook: the 10 OWASP LLM risks explained in plain English with real examples, attack workflows from attacker to compromised asset, and the Microsoft Protect / Detect / Respond stack for each.

Operating Systems

0 items

Deep architectural maps of the Windows OS itself — from kernel and shell to its security surface and blast radius.

OS Architecture

Windows OS — Complete Architecture Mind Map

The entire Windows OS mapped end-to-end — kernel & executive, storage & file systems, networking, identity, administration, Windows Server roles, boot process, virtualization, and more. 14 categories, 170+ components, searchable and expandable.

Attack Surface

Windows OS — Security Architecture & Blast Radius Map

Interactive map of the Windows OS attack surface — every component tagged as attacker-abused, dual-use, protective, or telemetry, with MITRE ATT&CK mapping and blast-radius escalation chains for incident triage.

Cloud Platforms

0 items

Full-platform security architecture maps for the cloud providers themselves — every service and feature that touches security, in one place.

Azure Security

Azure Security — Complete Architecture Mind Map

Every layer of Azure security in one map — identity, network, data, storage, compute & containers, database, apps, posture management, Defender for Cloud threat protection plans, Sentinel, governance, DevSecOps, backup, and AI/Copilot. 15 categories, 150+ components. Includes a Top 10 real-world attack scenarios section below the map, with clickable defenses that jump straight to the relevant node.

Azure Network Security

Azure Network Security — Interactive Reference Architecture

A full Azure network topology — VNet, subnets, VPN Gateway, ExpressRoute, on-prem link, VMs, AKS, App Service, SQL and storage — with every network security service (Firewall, WAF, NSGs, ASGs, Bastion, Private Link, DDoS Protection, and more) placed where it actually defends. Click through 6 attack scenarios plus a flagship "every layer" view to see the attacker's path in red and the engaged defenses light up in green.

Attack Chains & Techniques

0 items

Attacker tactics, techniques and multi-stage kill chains, each mapped to the Microsoft control that detects, prevents, or responds.

Attacker TTPs

Top 30 Attacker Techniques — MS Defense Reference

The 30 most common techniques used by script-kiddies and opportunistic attackers — each paired with the Microsoft Defender control that detects or blocks it.

Attack Chains

Attack Chain Explorer — Practitioner View

Interactive explorer of 10 real-world attack chains across 71 stages. For every stage, the top 3 attacker tools paired with the Microsoft defense that detects, prevents, or responds to each — with light/dark theme, compact mode, and per-stage chain progress sidebar.

XDR Scenario

Operation Shadow Harvest — Microsoft XDR Attack Chain

An end-to-end simulated attack walk-through — from initial access through impact — showing how each Microsoft XDR solution detects, correlates, and responds at every stage.

Scenarios & Playbooks

0 items

Applied, day-to-day material — FAQs and operational cadences for running the Microsoft security stack in practice.

Best Practices

Microsoft Security — Top Questions & Answers

Curated FAQ across Microsoft Security solutions — top questions per product (Purview, Entra, Defender, Intune) with practical answers, including AI security topics.

Operational Playbook

Driving Operational Excellence — Security Portals Cadence

Interactive dashboard for the daily, weekly, and monthly rhythm across Defender, Purview, and Entra. Click any of the 8 ransomware stages to filter the activities that break the chain at that stage.

Incident Response & Operations

0 items

Operational playbooks for cyber defense — incident command, triage methodology, and coordination practices built on Microsoft Defender XDR and Sentinel.

XDR · IR

Incident Command Playbook — Triage to Resolution

End-to-end incident commander playbook: triage methodology, severity matrix, 10-step response workflow with KQL, executive update templates, and field-tested best practices on the Microsoft XDR stack.

About

Hi, I'm Rudnei // Microsoft Cybersecurity Solution Engineer

I work as a Microsoft Cybersecurity Solution Engineer, helping customers design and operationalize security across the Microsoft stack — Azure Security, Microsoft Sentinel, Defender for Cloud, Defender XDR, Entra ID security, and Microsoft Purview (MIP, DLP, Insider Risk Management). This site is my open notebook: mind maps, deep-dive references, and operational notes I've found useful and want to share.

Azure Security
Microsoft Sentinel
Defender for Cloud
Defender XDR
Entra ID Security
Purview MIP