# wizardcyber.com > AI-optimized mirror of wizardcyber.com containing 50 pages totalling 4,178 words of clean markdown content, structured data, and semantic HTML. Original source: https://wizardcyber.com/. Last updated: 2026-06-14T01:42:20.377Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [How Attackers Abuse Claude AI](/content/site-root.html): Wizard Cyber is a global cyber security company with offices in the UK, Jordan, & the USA, allowing us to provide 24x7 protection. (89 words) ## Articles & Blog Posts - [Best Practices for SOC Monitoring in Microsoft Sentinel](/content/learning-hub/learning-post/sentinel-detection-rules-explained/index.html): Learn how Microsoft Sentinel detection rules use KQL, analytics, and ML to identify threats, reduce alert noise, and improve SOC visibility. (82 words) - [Learn how Conditional Access, MFA, and Identity Protection secure access in Microsoft Entra with risk-based policy.](/content/learning-hub/learning-post/microsoft-security-identity-abuse-detection/index.html): Learn how attackers abuse identity and how Microsoft Security detects credential theft, token abuse, and privilege misuse early. (84 words) - [Understanding the IoT Attack Surface](/content/learning-hub/learning-post/it-vs-ot-vs-iot-security/index.html): Understand the key differences between IT, OT, and IoT security, and why each domain requires a different approach in practice. (85 words) - [How Microsoft Security connects identity, endpoint, cloud, and SOC capabilities to detect threats across the full attack path.](/content/learning-hub/learning-post/what-is-microsoft-security/index.html): An overview of Microsoft Security, its unified platform approach, and how it protects identities, endpoints, cloud, and data. (82 words) - [Learn how attackers abuse identity and how Microsoft Security detects credential theft, token abuse, and privilege misuse early.](/content/learning-hub/learning-post/itdr-microsoft-security/index.html): Learn how Microsoft Security delivers ITDR by correlating identity signals with endpoint, email, and cloud detection. (83 words) - [Discover Microsoft Entra ID](/content/learning-hub/learning-post/microsoft-security-stack/index.html): Learn how the Microsoft Security stack unifies identity, endpoint, cloud, and SOC operations for coordinated detection and response. (80 words) - [Microsoft Security Stack](/content/learning-hub/learning-post/microsoft-security-zero-trust/index.html): How Microsoft Security applies Zero Trust principles across identity, access, devices, detection, and SOC operations. (80 words) - [Microsoft Security ITDR Overview](/content/learning-hub/learning-post/microsoft-entra-id-security/index.html): Discover how Microsoft Entra ID secures identities with MFA, Conditional Access, and real-time threat detection. (81 words) - [Why identity is the new perimeter](/content/learning-hub/learning-post/conditional-access-mfa-identity-protection-microsoft-entra.html): Learn how Conditional Access, MFA, and Identity Protection secure access in Microsoft Entra with risk-based policy. (83 words) - [What is an Incident Response Policy?](/content/learning-hub/learning-post/build-an-incident-response-plan/index.html): Learn how to create an incident response plan, define roles, and establish procedures for faster, consistent responses. (86 words) - [Attacks on Building Management Systems (BMS)](/content/learning-hub/learning-post/ot-bms-convergence-security-blind-spot/index.html): OT and BMS convergence creates blind spots where building networks go unmonitored, exposing organizations to lateral movement risk. (83 words) - [How Microsoft Security Applies Zero Trust Principles](/content/learning-hub/learning-post/microsoft-security-identity-to-soc/index.html): How Microsoft Security connects identity, endpoint, cloud, and SOC capabilities to detect threats across the full attack path. (79 words) - [Incident Response Overview](/content/learning-hub/learning-post/what-is-an-incident-response-policy/index.html): What an incident response policy is, how it differs from a response plan, and why it’s essential for governance and compliance. (83 words) - [Overview](/content/learning-hub/learning-post/impossible-travel-detection-microsoft-sentinel/index.html): Learn how impossible travel detection works in Microsoft Sentinel, including how it identifies identity compromise and its limitations. (82 words) - [Ransomware and IoT](/content/learning-hub/learning-post/iot-attack-surface/index.html): Explore why the IoT attack surface is larger than most organizations realize and how unknown devices increase security risk. (87 words) - [Why Smart Building Security Requires 24/7 Monitoring](/content/learning-hub/learning-post/smart-building-threat-detection-monitoring/index.html): How smart building threat detection and monitoring identifies abnormal behavior using passive, protocol-aware security monitoring. (86 words) - [Compare In-House and Managed Security Models for Smart Buildings](/content/learning-hub/learning-post/smart-building-security-24-7-monitoring/index.html): Why smart building security requires 24/7 monitoring to detect threats quickly and protect always-on building systems. (85 words) - [Why smart building security requires 24/7 monitoring to detect threats quickly and protect always-on building systems.](/content/learning-hub/learning-post/in-house-vs-managed-smart-building-security/index.html): Compare in-house and managed security models for smart buildings and BMS, including skills, cost, coverage, and operational trade-offs. (81 words) - [Why Smart Building Security Requires 24/7 Monitoring](/content/learning-hub/learning-post/ot-iot-smart-building-soc/index.html): Learn how SOCs for OT, IoT, and smart buildings differ from IT SOCs, including monitoring tools, analyst skills, and response models. (80 words) - [OT and BMS Convergence](/content/learning-hub/learning-post/smart-building-cybersecurity-risks/index.html): Explore key cybersecurity risks in smart buildings, from IoT exposure to IT lateral movement, and how to secure connected facilities. (87 words) - [How smart building threat detection and monitoring identifies abnormal behavior using passive, protocol-aware security monitoring.](/content/learning-hub/learning-post/securing-smart-buildings-framework/index.html): Framework to help facilities teams secure smart buildings, reduce cyber risk, and protect BMS, HVAC, and access systems. (80 words) - [Threat Hunting in Microsoft Sentinel](/content/learning-hub/learning-post/microsoft-sentinel-detection-rules-explained/index.html): Learn how Microsoft Sentinel detection rules turn security telemetry into alerts, incidents, and actionable threat insights. (84 words) - [Best Practices for SOC Monitoring in Microsoft Sentinel](/content/learning-hub/learning-post/sentinel-threat-hunting-techniques/index.html): Learn how threat hunting in Microsoft Sentinel helps security teams proactively uncover hidden threats beyond automated detections. (83 words) - [Impossible Travel Detection in Microsoft Sentinel](/content/learning-hub/learning-post/what-is-microsoft-sentinel/index.html): Learn what Microsoft Sentinel is, how its architecture works, and how it supports modern threat detection and security operations. (82 words) - [Key Cybersecurity Risks in Smart Buildings](/content/learning-hub/learning-post/smart-building-security-guide/index.html): Smart building security protects building systems from cyber threats disrupting operations, safety, and business continuity. (88 words) - [Learn how impossible travel detection works in Microsoft Sentinel](/content/learning-hub/learning-post/sentinel-soc-monitoring-best-practices/index.html): Best practices for SOC monitoring in Microsoft Sentinel, focusing on alert quality, triage consistency, automation, and response efficiency. (82 words) - [Smart Building Security](/content/learning-hub/learning-post/building-management-system-bms-cybersecurity/index.html): Learn what a Building Management System (BMS) is, how it works, and why BMS platforms are a growing cybersecurity risk. (85 words) - [Common IoT Vulnerabilities](/content/learning-hub/learning-post/why-iot-devices-are-targeted/index.html): Learn why IoT devices are prime targets for cybercriminals, how attackers exploit them, and the risks this creates for businesses. (88 words) - [Why smart building security requires 24/7 monitoring to detect threats quickly and protect always-on building systems.](/content/learning-hub/learning-post/why-it-security-fails-smart-buildings/index.html): Why IT security fails in smart buildings and what security teams must do to protect building automation systems securely. (86 words) - [IoT Security Overview](/content/learning-hub/learning-post/what-is-iot-security/index.html): Learn what IoT security is, why it matters for businesses, and how to protect connected devices across IT, OT, and IoT environments. (89 words) - [What is an Incident Response Policy?](/content/learning-hub/learning-post/what-is-incident-response/index.html): Learn what incident response is, why it matters, and how frameworks and best practices help contain and recover from attacks. (88 words) - [Incident Response Framework](/content/learning-hub/learning-post/nist-incident-response-framework/index.html): Understand the NIST incident response framework, its four phases, roles, and how to apply it in modern security operations. (82 words) - [Overview](/content/learning-hub/learning-post/incident-response-soc-xdr/index.html): Learn how incident response, SOC operations, and XDR work together to detect, contain, and resolve security incidents. (85 words) - [Security Operations Center (SOC)](/content/learning-hub/learning-post/in-house-soc-vs-managed-soc-which-is-right-for-you/index.html): Compare in-house and managed SOC models to find the right fit for cost, scalability, expertise, and 24/7 security coverage. (110 words) - [Learn how XDR works](/content/learning-hub/learning-post/what-is-xdr-extended-detection-and-response/index.html): Learn what XDR is, why it exists, and how it improves threat detection, investigation, and response across modern environments. (81 words) - [Key Differences in Security Domains](/content/learning-hub/learning-post/common-iot-vulnerabilities/index.html): Explore the most common IoT vulnerabilities, how attackers exploit them, and the controls organizations use to reduce exposure. (88 words) - [Incident Response: Understanding Failures and Solutions](/content/learning-hub/learning-post/common-incident-response-mistakes/index.html): Learn the most common incident response mistakes and how to avoid delays, confusion, and increased business impact. (88 words) - [Discover why XDR matters](/content/learning-hub/learning-post/how-xdr-reduces-mttd-mttr/index.html): Learn how XDR helps reduce MTTD and MTTR by improving detection speed, investigation, and automated response (83 words) - [Security Operations Center (SOC)](/content/learning-hub/learning-post/how-to-build-a-modern-soc-people-process-and-technology.html): Learn how people, process, and technology come together to build a modern, cloud-native SOC designed for faster detection and response. (116 words) - [Classify & Protect Sensitive Data](/content/learning-hub/learning-post/8-key-benefits-of-adopting-mxdr-for-enterprise-security.html) (34 words) - [Microsoft XDR Overview](/content/learning-hub/learning-post/why-xdr-matters-siem-vs-edr-limitations/index.html): Discover why XDR matters and how it overcomes the detection and response limitations of traditional SIEM and EDR tools. (80 words) - [Security Operations Center (SOC)](/content/learning-hub/learning-post/4-essential-security-operations-center-frameworks-every-soc-should-use.html): Learn how NIST CSF, MITRE ATT&CK, Cyber Kill Chain, and the Unified Kill Chain strengthen your SOC’s detection and response. (111 words) - [Microsoft XDR Overview](/content/learning-hub/learning-post/what-is-managed-xdr-mxdr/index.html): Learn what Managed XDR (MXDR) is and why organizations use it for 24/7 detection, response, and SOC outcomes. (80 words) - [Security Operations Center (SOC)](/content/learning-hub/learning-post/soc-as-a-service-the-smarter-way-to-secure-your-business.html): Discover how SOC as a Service delivers 24/7 monitoring, expert detection, and rapid response without the cost of running an internal SOC. (107 words) - [Microsoft XDR Overview](/content/learning-hub/learning-post/how-xdr-works-from-detection-to-automated-response/index.html): Learn how XDR works across telemetry, detection, investigation, and automated response to stop modern cyberattacks faster. (83 words) - [Explore the Core SOC Frameworks](/content/learning-hub/learning-post/what-is-a-security-operations-center-soc/index.html): Learn what a Security Operations Center (SOC) is, how it works, key components, models, and why it’s essential for modern cyber defense. (106 words) - [Classify & protect sensitive data](/content/learning-hub/learning-post/5-essential-tools-powering-microsoft-mxdr-solutions.html) (34 words) - [Classify & protect sensitive data](/content/learning-hub/learning-post/what-is-mxdr-and-why-it-matters-for-modern-cybersecurity.html) (34 words) - [Microsoft Sentinel Data Lake](/content/microsoft-sentinel-evolution-defender-portal/index.html): Learn how Microsoft Sentinel’s move to the Defender portal delivers a unified SOC experience for better detection and faster response. (93 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives