July 2026

Uncategorized

User Access Management in Active Directory Domain Services (AD DS)

Comprehensive Documentation (2026 Edition) 1. Introduction Purpose User Access Management (UAM) in Microsoft Active Directory Domain Services (AD DS) is the process of managing user identities, authentication, authorization, and permissions within an organization’s network. It ensures that only authorized users can access corporate resources while maintaining security, compliance, and operational efficiency. Objectives 2. Active Directory

User Access Management in Active Directory Domain Services (AD DS) Read Post »

security

what a SIEM does in a modern SOC, followed by a landscape of the top vendors.

Part 1: The Role of SIEM in the SOC (The Architectural View) In a mature SOC, the SIEM performs four critical architectural functions: 1. Telemetry Aggregation & Normalization (The Data Lake) 2. Correlation & Detection (The Brain) 3. Investigation & Forensics (The Time Machine) 4. Compliance & Reporting (The Audit Trail) Part 2: The Evolution

what a SIEM does in a modern SOC, followed by a landscape of the top vendors. Read Post »

security

critical ports, their functions, and the cyber attacks

Part 1: The Attack Surface (Critical Ports & Architectural Rules) Instead of a basic list, here are the most critical ports categorized by their architectural domain, along with the “Golden Rules” for securing them. 1. Identity & Infrastructure (The Crown Jewels) These ports manage authentication, directory services, and remote administration. If an attacker compromises these,

critical ports, their functions, and the cyber attacks Read Post »

security

Port Scanning (from a lab and defensive perspective) and the formal Incident Response (IR) phases.

Part 1: Port Scanning (Lab, Detection, and Architecture) A port scan is the digital equivalent of walking through a neighborhood checking which doors and windows are unlocked. It is the primary tool used in the Reconnaissance and Weaponization stages of the Cyber Kill Chain. 1. The Types of Scans (What the SOC is looking for)

Port Scanning (from a lab and defensive perspective) and the formal Incident Response (IR) phases. Read Post »

security

Cyber Kill Chain, tailored to modern cloud, IAM, and Fintech environments.

The 7 Stages of the Cyber Kill Chain 1. Reconnaissance (Gathering Intel) 2. Weaponization (Creating the Payload) 3. Delivery (Transmitting the Payload) 4. Exploitation (Triggering the Vulnerability) 5. Installation (Establishing a Foothold) 6. Command and Control (C2) (Two-Way Communication) 7. Actions on Objectives (The Endgame) The Modern Evolution: Limitations of the Traditional Kill Chain As

Cyber Kill Chain, tailored to modern cloud, IAM, and Fintech environments. Read Post »

security

advanced glossary of SOC terms, categorized by modern threat landscapes, detection engineering, and SOC leadership.

1. Advanced Threat & Attack Terminology (What the SOC is hunting) Modern attackers rarely use noisy, easily detected malware. The SOC must be trained to spot subtle, sophisticated techniques. 2. Advanced Detection & Investigation Concepts (How the SOC works) These terms describe the methodology of modern, proactive security operations. 3. SOC Leadership & Management Terminology

advanced glossary of SOC terms, categorized by modern threat landscapes, detection engineering, and SOC leadership. Read Post »

security

Networking, Network Types, and the OSI Model through the lens of a Head of Platform Security and Fintech Security Architect

This is about understanding how the foundational network fabric dictates your security architecture, risk posture, and cloud strategy. 1. What is Networking? (The Security Leader’s Perspective) At its core, networking is the practice of connecting computing devices to share resources and communicate. However, in modern enterprise architecture, networking is the central nervous system of the

Networking, Network Types, and the OSI Model through the lens of a Head of Platform Security and Fintech Security Architect Read Post »

security

IP Classes and DHCP

Part 1: IP Address Classes (The Historical Foundation) Before 1993, the internet used Classful Networking to allocate IP addresses. The 32-bit IPv4 address space was rigidly divided into five classes based on the first few bits of the address. Classful networking is obsolete, replaced in 1993 by CIDR (Classless Inter-Domain Routing). However, understanding classes is

IP Classes and DHCP Read Post »

Scroll to Top