Sign in

Sami Lamppu

@samilamppu.bsky.social
543 followers 156 following 38 posts
PostsRepliesMedia
Sami Lamppu @samilamppu.bsky.social · 25/06/2026
🛡️Microsoft's DCU took down five CaaS operations in nine months: RaccoonO365, RedVDS, Tycoon 2FA, Fox Tempest, Amadey/StealC. The pattern: Target the supply-chain providers; phishing-kit sellers, MFA-bypass platforms, etc, not just the attackers running campaigns. www.microsoft.com/en-us/corpor...
microsoft.com
How Microsoft is tackling the cybercrime economy | Microsoft
Microsoft’s Digital Crimes Unit (DCU) disrupted five major cybercrime operations in the last nine months. Learn how these five disruptions are part of a single strategic effort to dismantle the infras...
000
Reposted by Sami Lamppu
Thomas Naunheim @naunheim.cloud · 02/11/2025
Had the great privilege and a lot of fun joining 🎙️#EntraChat together with my friend and MVP fellow @samilamppu.bsky.social! 🙏 Big thanks to @merill.net for having us - it was a pleasure to be part of the podcast. I hope everyone listening enjoyed it as much as we did recording it!
061
Sami Lamppu @samilamppu.bsky.social · 01/11/2025
Great chat with Merill Fernando on Entra Chat! We (Thomas Naunheim & I) shared some favorite findings and stories from the past years working with Entra ID Attack & Defense Playbook. Link to the full episode below👇
061
Reposted by Sami Lamppu
Merill Fernando 💚 @merill.net · 01/11/2025
Thomas Naunheim and Sami Lamppu quietly built one of the most useful open projects for Entra ID defenders. The Entra ID Attack & Defense Playbook It’s free, community-driven, and packed with real detection logic and KQL queries. 🧵👇
1224
Sami Lamppu @samilamppu.bsky.social · 11/07/2025
Whoop!, Whoop 🎉 I've earned my 5th consecutive MVP award! Now is a great time to start my vacation and think about security and AI stuff next time in August!
030
Sami Lamppu @samilamppu.bsky.social · 04/07/2025
New in #DefenderXDR advanced hunting: Automatic Attack Disruption events are now in the DisruptionAndResponseEvents table! 🛡️ - Includes both block & policy-application events from disruption policies, plus auto-response actions across related workloads - Boost visibility into complex attacks
200
Sami Lamppu @samilamppu.bsky.social · 26/06/2025
Spent the week test-driving the Microsoft Learn Docs MCP server with the Claude desktop. Fast, precise document look-ups make it easy to ground answers in official Microsoft content. Links: - github.com/microsoftdoc... - techcommunity.microsoft.com/blog/azurede...
techcommunity.microsoft.com
Building an MCP Server for Microsoft Learn | Microsoft Community Hub
So why Microsoft Learn? Well, it's a treasure trove of knowledge for developers and IT pros. Secondly, because it has search page with many filters, it lends...
000
Sami Lamppu @samilamppu.bsky.social · 24/06/2025
I tried #Lokka MCP server made by @merill.net . Lokka bridges Claude to Entra/Azure via Microsoft Graph. I exported Entra security settings through APIs, parsed CA policies, and drafted a report with the Claude desktop. Early days, but looks promising! #CloudSec #MCP lokka.dev/docs/intro/
162
Sami Lamppu @samilamppu.bsky.social · 17/02/2025
Storm-2372 conducts a device code phishing campaign. Update on Feb 14, 2025: 'Within the past 24 hours, MS has observed Storm-2372 shifting to using the specific client ID for MS AuthBroker in the device code sign-in flow. Read the full story below 👇 www.microsoft.com/en-us/securi...
microsoft.com
Storm-2372 conducts device code phishing campaign | Microsoft Security Blog
Microsoft Threat Intelligence Center discovered an active and successful device code phishing campaign by a threat actor we track as Storm-2372. Our ongoing investigation indicates that this campaign ...
066
Sami Lamppu @samilamppu.bsky.social · 14/02/2025
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation www.microsoft.com/en-us/securi...
microsoft.com
The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation | Microsoft Security Blog
Microsoft is publishing for the first time our research into a subgroup within the Russian state actor Seashell Blizzard and its multiyear initial access operation, tracked by Microsoft Threat Intelli...
000
Sami Lamppu @samilamppu.bsky.social · 11/02/2025
Next-Gen Device Incident Investigation & Threat Hunting with Custom Plugins in #Securitycopilot techcommunity.microsoft.com/blog/securit...
techcommunity.microsoft.com
Next-Gen Device Incident Investigation & Threat Hunting with Custom Plugins | Microsoft Community Hub
          The Security Copilot custom plugin empowers you to extend Security Copilot functionalities beyond the preinstalled and...
000
Reposted by Sami Lamppu
Thomas Naunheim @naunheim.cloud · 29/01/2025
EntraOps repository: github.com/Cloud-Archit... Learn more about XSPM and Graph: Deep Dive blog post on XSPM by @samilamppu.bsky.social samilamppu.com/2024/04/25/m... Blog posts by @fabian.bader.cloud cloudbrothers.info/en/workshop-... cloudbrothers.info/en/find-late... Kusto Graph rocks! (3/3)
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
021
Sami Lamppu @samilamppu.bsky.social · 05/02/2025
Unified Device Timeline Experience in Microsoft SIEM + XDR techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Introducing the Unified Device Timeline Experience in Microsoft SIEM + XDR | Microsoft Community Hub
We are thrilled to announce the launch of the Unified Device Timeline, a feature that integrates device activity timelines from Microsoft Sentinel and...
000
Sami Lamppu @samilamppu.bsky.social · 03/02/2025
Sentinel Content Hub leverages AI technology in the new search capability. Check out below how techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
What’s new: Find the Sentinel content you need using AI search | Microsoft Community Hub
Overview Getting value from Microsoft Sentinel and the Microsoft Unified Security Operations Platform requires deploying the right solutions. Microsoft and...
000
Sami Lamppu @samilamppu.bsky.social · 28/01/2025
Speed up incident triage with Security Copilot and Microsoft Sentinel techcommunity.microsoft.com/blog/securit...
techcommunity.microsoft.com
Boost SOC automation with AI: Speed up incident triage with Security Copilot and Microsoft Sentinel | Microsoft Community Hub
The Solution This solution leverages AI and automation to speed up incident triage by providing automated response to an incident while infusing AI reasoning...
000
Sami Lamppu @samilamppu.bsky.social · 23/01/2025
Hunt for identity-based threats with Security Copilot and Microsoft Sentinel techcommunity.microsoft.com/blog/securit...
techcommunity.microsoft.com
Hunt for identity-based threats with Security Copilot and Microsoft Sentinel | Microsoft Community Hub
Enter Microsoft Sentinel and Security Copilot, a powerful duo that brings great value to your security operations. Microsoft Sentinel's User and Entity...
010
Sami Lamppu @samilamppu.bsky.social · 18/01/2025
Blog summarizes the three takeaways from the Microsoft AI Red team white paper: 'Lessons from red teaming 100 generative AI products' www.microsoft.com/en-us/securi...
microsoft.com
3 takeaways from red teaming 100 generative AI products | Microsoft Security Blog
The growing sophistication of AI systems and Microsoft’s increasing investment in AI have made red teaming more important than ever. Learn more.
010
Reposted by Sami Lamppu
Thomas Naunheim @naunheim.cloud · 09/01/2025
#MicrosoftEntra Attack & Defense Playbook Update: @samilamppu.bsky.social and I have updated some content: 🔃 #EntraConnect: New capabilities by MDI sensor & XSPM 🎯 #AiTM: Attack scenarios on MDA sessions 🛡️ #MITRE: Updated TTP coverage & map Check out the latest version: github.com/Cloud-Archit...
github.com
GitHub - Cloud-Architekt/AzureAD-Attack-Defense: This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can b...
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected. - Cloud-Architekt/Azu...
1106
Sami Lamppu @samilamppu.bsky.social · 09/01/2025
Together with @naunheim.cloud we did the following updates on Entra ID Attack & Defense Playbook: Entra Connect: Added MDI enhancements and XSPM queries AiTM: MDA section with Edge In-browser MITRE: Updated heat map & TTPs Check out the latest version 👉 github.com/Cloud-Archit...
github.com
GitHub - Cloud-Architekt/AzureAD-Attack-Defense: This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can b...
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected. - Cloud-Architekt/Azu...
020
Sami Lamppu @samilamppu.bsky.social · 03/01/2025
Defender XDR monthly news - January 2025 techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Monthly news - January 2025 | Microsoft Community Hub
Microsoft Defender XDRMonthly newsJanuary 2025 Edition This is our monthly "What's new" blog post, summarizing product updates and various new...
010
Sami Lamppu @samilamppu.bsky.social · 20/12/2024
KQL Migrator powered by Microsoft Security Copilot techcommunity.microsoft.com/blog/securit...
techcommunity.microsoft.com
KQL Migrator powered by Microsoft Security Copilot | Microsoft Community Hub
Overview A couple of weeks ago, Hesham and Hiten attended an internal Global Blackbelt summit in Redmond. Unfortunately, we encountered bad weather due to a...
040
Sami Lamppu @samilamppu.bsky.social · 20/12/2024
Leveraging ASIM-based KQL plugins in Microsoft Security Copilot for investigation scenarios techcommunity.microsoft.com/blog/securit...
techcommunity.microsoft.com
Leveraging ASIM-based KQL plugins in Microsoft Security Copilot for investigation scenarios | Microsoft Community Hub
Microsoft Security Copilot enhances the capabilities of Microsoft Sentinel by providing an AI-driven assistant that can help interpret complex hunting query...
010
Sami Lamppu @samilamppu.bsky.social · 17/12/2024
Looking for how to audit Security Copilot activities? Great Techcommunity blog explains how. Monitor user activities & system events with Security Copilot and Sentinel 👇 techcommunity.microsoft.com/blog/securit...
techcommunity.microsoft.com
Monitor User Activities and System Events with Security Copilot and Microsoft Sentinel | Microsoft Community Hub
We do recommend you read through the our Privacy and data security document to understand more about what data we are capturing Privacy and data security as...
031
Sami Lamppu @samilamppu.bsky.social · 15/12/2024
Unified SOC Operations Platform latest enhancement: Use Sentinel Workbooks directly from the Defender XDR portal techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
What's New: View Microsoft Sentinel Workbooks Directly from Unified SOC Operations Platform | Microsoft Community Hub
  Key Benefits  Unified Viewing Experience:  Microsoft Sentinel workbook templates and saved workbooks can now be accessed directly within the...
010
Sami Lamppu @samilamppu.bsky.social · 11/12/2024
#MSUGFI aka 'Microsoft Security User Group Finland' kokoontuu seuraavan kerran keskiviikkona 15.1.2024 klo 17:00, jolloin hostina toimii Arrow ECS. Vielä olisi muutama paikka vapaana, jos event kiinnostaa nappaa itsellesi sisäänpääsy tapahtumaan linkin takaa 👇 www.meetup.com/microsoft-se...
meetup.com
MSUG #5: Arrow ECS, Wed, Jan 15, 2025, 5:00 PM | Meetup
Microsoft Security User Group Finlandin tammikuun tapahtuma järjestetään [Arrow ECS:llä](https://www.arrow.com/globalecs/fi/). Tule mukaan osallistumaan, kuulemaan, pohtima
010
Sami Lamppu @samilamppu.bsky.social · 10/12/2024
Defender XDR monthly news - December 2024 edition techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Monthly news - December 2024 | Microsoft Community Hub
Microsoft Defender XDRMonthly newsDecember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and various...
000
Sami Lamppu @samilamppu.bsky.social · 04/12/2024
It's great to see SaaS initiative in Defender for Cloud Apps & Exposure Management announced! A lot of work behind the scenes in private preview phase! learn.microsoft.com/en-us/defend...
learn.microsoft.com
SaaS Security Initiative - Microsoft Defender for Cloud Apps
Learn how to use the SaaS Security Initiative in Microsoft Defender XDR.
020
Reposted by Sami Lamppu
Thomas Naunheim @naunheim.cloud · 27/11/2024
New Release: #EntraOps 0.3.3! 🚀 This update includes bug fixes and enhancements to #MicrosoftSentinel workbooks and nested #MicrosoftEntra PIM for Groups. Get the latest version from the GitHub repository: github.com/Cloud-Archit...
0111
Sami Lamppu @samilamppu.bsky.social · 27/11/2024
Yesterday, I was privileged to share a stage at the MSUGFI with fellow MVP and good friend Joosua Santasalo. We focused this time only on AiTM attacks, and on a high level, we covered: Attack simulation, discussed the effective detections, mitigations Thanks to everyone who joined the session!
040
Sami Lamppu @samilamppu.bsky.social · 26/11/2024
Celebrating 4 years of the "#MicrosoftEntra Attack & Defense Playbook" 🔐 ☁️ community project! Last week, we (@naunheim.cloud & I) were in Chicago, and we took the opportunity to record a video about this project's journey. #MVPBuzz #TechCommunity youtu.be/fBD1ftf0PbA?...
youtu.be
Microsoft Entra ID Attack & Defense Playbook with Sami Lamppu
YouTube video by Thomas Naunheim
0111
Sami Lamppu @samilamppu.bsky.social · 21/11/2024
Ready for day 3 at the MS Ignite on the Security Copilot booth!
030
Sami Lamppu @samilamppu.bsky.social · 20/11/2024
Here we go! MS Ignite day 2 starts with Entra Suite stuff!
010
Sami Lamppu @samilamppu.bsky.social · 20/11/2024
Day 1 behind at MSIgnite. Great discussions, questions and connections. If you are at the MSIgnite & wanna have a chat, come to meet me at the SecurityCopilot booth on Thursday morning.
020
Sami Lamppu @samilamppu.bsky.social · 19/11/2024
Huge improvements were announced for the security copilot in the MS Entra embedded experience at Ignite. bit.ly/4hPpTyN
bit.ly
Security Copilot is now embedded in Microsoft Entra | Microsoft Community Hub
Today we’ve announced the public preview of Microsoft Security Copilot embedded in the Microsoft Entra admin center. This integration brings all identity...
000
Sami Lamppu @samilamppu.bsky.social · 18/11/2024
Here we go, ready for MSIgnite!
140
Sami Lamppu @samilamppu.bsky.social · 15/11/2024
Microsoft Defender Experts (DEX) plugin is a great example of a powerful KQL plugin in Copilot for Security. Full story on the blog: bit.ly/3O8jW23
bit.ly
Enhancing Threat Hunting with Microsoft Defender Experts Plugin | Microsoft Community Hub
In today's rapidly evolving digital landscape, cybersecurity threats are becoming increasingly sophisticated, requiring organizations to adopt proactive...
010
Sami Lamppu @samilamppu.bsky.social · 16/02/2024
We (Markus, Thomas & me) are excited to announce the next version of Entra ID Security Config Analyzer - EIDSCA (V3). This release includes some overall improvements and a new section to track your Entra ID Conditional Access policies. You can find the solution at bit.ly/3PtI3Kq
051
Sami Lamppu @samilamppu.bsky.social · 23/01/2024
Exited to announce that Raghu & I are releasing 'Microsoft Unified XDR and SIEM Solution Handbook' in March. Our book goes deep into the Unified XDR Solution - breaking down its capabilities and demonstrating effectiveness in real-world attack scenarios. www.amazon.com/dp/1835086853
131
Sami Lamppu @samilamppu.bsky.social · 20/01/2024
New Microsoft Incident Response guides help security teams analyze suspicious activity | Microsoft Security Blog www.microsoft.com/en-us/securi...
microsoft.com
Microsoft
020
Sami Lamppu @samilamppu.bsky.social · 16/01/2024
Introducing the new PowerShell Module for Microsoft Defender for Identity - Microsoft Community Hub techcommunity.microsoft.com/t5/microsoft...
030