KeMeT Tech
Field notes

Writeups from the engineers shipping the code.

Production-grade patterns, post-mortems, and migration playbooks. Real numbers from real engagements, written so a senior engineer at your shop can apply them in a week.

azure ·17sentinel ·12siem ·9detection engineering ·8kql ·7ai-agents ·6microsoft purview ·6compliance ·5azure sentinel ·5detection-engineering ·5
Sep 27, 2026

Kimi K2 Thinking: Evaluating a Trillion-Parameter Reasoning Model

Kimi K2 Thinking is an open-source trillion-parameter reasoning model from Moonshot AI. Here is how we assess it and wire it into agentic pipelines before trusting it with production workloads.

#ai-agents#open-source#reasoning-models#llm-evaluation
6 min · Read →
Sep 27, 2026

Azure Landing Zone Accelerator: What It Deploys and Where It Hurts

The Azure Landing Zone Accelerator gives you a CAF-aligned multi-subscription scaffold in one shot. Here is what it actually creates, where it breaks, and how to extend it safely.

#azure#landing-zone#cloud-architecture#governance#bicep
6 min · Read →
Sep 26, 2026

Microsoft Purview Login: The Two-Plane Auth Problem and How to Solve It

Getting into purview.microsoft.com is half the fight. Covers Entra ID RBAC, Collection roles, service principal auth, and Conditional Access gaps that silently block catalog access.

#microsoft purview#azure#data governance#entra id#identity
6 min · Read →
Sep 26, 2026

DeepSeek V4 Flash 0731: What We Know and How to Evaluate It

DeepSeek V4 Flash 0731 landed mid-summer as the lighter sibling to V4 Pro. Here is how to evaluate it before betting a production workload on it.

#deepseek#llm-evaluation#ai-agents#inference
6 min · Read →
Sep 25, 2026

Microsoft Purview Pricing: Two Bills, One Platform, No Clear Map

Microsoft Purview bundles two historically separate products with different billing models. Here is how to read both bills before you commit.

#microsoft purview#data governance#azure#compliance#cost management
6 min · Read →
Sep 25, 2026

Claude Code MCP: Wiring External Tools Into Your Engineering Loop

Model Context Protocol turns Claude Code into a multi-tool agent that can query APIs, databases, and CI systems. Here is how to register and secure MCP servers in production.

#ai-agents#claude-code#mcp#devops
6 min · Read →
Sep 24, 2026

What Microsoft Purview Actually Is, and What It Is Not

Microsoft Purview covers two distinct product families under one brand. Understanding the split before you buy or deploy saves months of rework.

#microsoft purview#data governance#compliance#azure#sentinel
5 min · Read →
Sep 24, 2026

Gemini 3.1 Pro: Evaluation Notes Before You Commit to Production

The Gemini 3 family has expanded fast across Flash, Pro, and Deep Think tiers. Here is how we evaluate the Pro variant before routing production traffic to it on Vertex AI.

#gemini#vertex-ai#llm-evaluation#ai-agents#google-cloud
5 min · Read →
Sep 23, 2026

Microsoft Purview Message Encryption: What Actually Works in Production

Purview Message Encryption replaces classic OME with sensitivity-label-driven controls. Here is how to configure it, audit it, and stop it from breaking partner mail flows.

#purview#email-encryption#microsoft-365#information-protection#compliance
6 min · Read →
Sep 23, 2026

AI Agent Platforms for Engineering Teams: Infrastructure Over Hype

Most teams pick a coding agent and miss the platform layer. Here is how we scope, wire, and cost-model the infrastructure that makes agents survive a real codebase.

#ai-agents#coding-agents#platform-engineering#cloud-architecture
6 min · Read →
Aug 26, 2026

MiniMax M2.5: 80.2% SWE-bench Verified and How to Actually Test It

MiniMax M2.5 posts 80.2% on SWE-bench Verified, putting it in contention for agentic coding pipelines. Here is how to evaluate it against your real workloads before committing.

#ai-agents#open-weight-models#coding-llm#evaluation#minimax
6 min · Read →
Aug 26, 2026

MiniMax M2.1 for Coding and Complex Tasks: An Honest Field Evaluation

MiniMax M2.1 targets multi-language programming and real-world reasoning. Here is how to evaluate it honestly and where it fits in an agent stack.

#minimax#open-weight-models#coding-agents#model-evaluation
6 min · Read →
Aug 26, 2026

Microsoft Purview DLP: From Policy Noise to Detection That Holds

Most Purview DLP deployments generate alert volume without detection value. Here is how we scope, tune, and wire signals into Sentinel so they mean something.

#microsoft purview#dlp#sentinel#detection engineering#compliance
7 min · Read →
Aug 26, 2026

Defender for Cloud Pricing: What the Azure Portal Doesn't Tell You

Microsoft Defender for Cloud's modular pricing routinely surprises teams. Here is how the plans are structured, where bills balloon, and how to audit your exposure before it hits finance.

#azure#security#cloud-cost#defender#cspm
7 min · Read →
Aug 25, 2026

Microsoft Defender for Cloud: From Licensed to Operational

Most Azure tenants have Defender for Cloud enabled but not working. Here is how we close that gap and get real signal into Defender XDR and Sentinel.

#defender for cloud#azure#xdr#detection engineering#cloud security
6 min · Read →
Aug 24, 2026

Microsoft Purview Information Protection: What Actually Ships vs. What Demos

A field guide to deploying Purview sensitivity labels and auto-labeling at scale. Covers label taxonomy, DLP tuning, Sentinel correlation, and the gaps Microsoft won't put in a slide deck.

#microsoft purview#information protection#dlp#sensitivity labels
7 min · Read →
Aug 23, 2026

Defender for Cloud Apps: What Actually Works in Production

A field engineer's view of MDCA deployment, session policy pitfalls, and KQL detections that catch what the defaults miss. Real config, real numbers.

#defender for cloud apps#casb#detection engineering#microsoft sentinel#zero trust
6 min · Read →
Aug 21, 2026

Azure Log Analytics Workspace: What Nobody Warns You About

LAW is not just a data sink. How you design tables, DCRs, and retention tiers determines whether you get actionable signal or a five-figure monthly bill.

#azure#log analytics#sentinel#monitoring#kql
6 min · Read →
Aug 20, 2026

Azure Landing Zone Architecture: What We Actually Deploy

Most teams treat Azure landing zones as a checkbox. This field note covers the hierarchy, policy, and network decisions that determine whether your zone holds up under production load.

#azure#cloud-architecture#landing-zone#governance#bicep
6 min · Read →
Aug 19, 2026

Azure Log Analytics Workspace Pricing: What Actually Drives Your Bill

Log Analytics Workspace billing has three independent meters running at once. Knowing which one dominates your spend is the first step to controlling it.

#azure#sentinel#log-analytics#cost-optimization#monitoring
6 min · Read →
Aug 18, 2026

Azure Sentinel and GitHub: Detection-as-Code That Actually Ships

Wire GitHub audit logs into Microsoft Sentinel and manage your KQL analytics rules as versioned Bicep, deployed via GitHub Actions. No more portal drift.

#azure sentinel#github#detection engineering#kql#gitops
5 min · Read →
Aug 17, 2026

Microsoft Sentinel Certification: What SC-200 Tests vs. What You Need

SC-200 is the exam that actually validates Sentinel depth, but passing it and operating a production workspace are different skills. Here is what the gap looks like.

#sentinel#detection-engineering#azure#certification#siem
5 min · Read →
Aug 16, 2026

KQL Query Examples for Threat Detection in Microsoft Sentinel

Production-tested KQL patterns for Sentinel detection engineering: join cost, time-series baselining, lateral movement detection, and where AI-to-KQL tooling actually helps.

#kql#sentinel#detection-engineering#threat-hunting#azure
5 min · Read →
Aug 15, 2026

Azure Sentinel Training That Actually Produces Detection Engineers

Most Sentinel training stops at dashboards and query basics. Here is the path that turns analysts into engineers who write, tune, and own detections at scale.

#azure sentinel#microsoft sentinel#kql#detection engineering#siem
6 min · Read →
Aug 14, 2026

Microsoft Sentinel SIEM: What We've Learned Deploying It in Production

Microsoft Sentinel (formerly Azure Sentinel) is a capable cloud-native SIEM, but ingestion costs and workspace design decisions made early will determine whether it stays affordable. Here's what to get right upfront.

#azure#sentinel#siem#detection-engineering#security
6 min · Read →
Aug 13, 2026

What Is Microsoft Sentinel: A SIEM You Actually Operate in Production

Microsoft Sentinel is a cloud-native SIEM and SOAR built on Log Analytics. Here is what it costs, how it ingests data, and where it breaks in the real world.

#sentinel#siem#azure#detection-engineering#security
7 min · Read →
Aug 12, 2026

Microsoft Purview Compliance Portal: What Actually Works in Production

A field guide to deploying DLP, Communication Compliance, and audit log pipelines from the Purview portal. Covers licensing walls, classifier gaps, and Sentinel integration.

#microsoft purview#compliance#sentinel#dlp#detection engineering
6 min · Read →
Jun 22, 2026

Azure Log Analytics Workspace: Design Decisions That Matter at Scale

A Log Analytics Workspace is the foundation of every Azure monitoring and SIEM deployment. Get the workspace topology and cost controls wrong early and you pay for it for years.

#azure#log-analytics#sentinel#monitoring#kql
7 min · Read →
Jun 20, 2026

Microsoft Sentinel Training: What Actually Matters in the Field

Most Sentinel courses teach the portal tour. This field note covers what engineers need to operate Sentinel at production scale: KQL, rule testing, cost control, and detection gaps.

#sentinel#detection#kql#azure#siem
6 min · Read →
Jun 11, 2026

Microsoft Sentinel Pricing: What You Actually Pay and How to Cut It

Sentinel bills on two layers most teams never model together. Here is how commitment tiers, free connectors, and Basic Logs interact — with real numbers.

#sentinel#azure#siem#detection-engineering#cost-optimization
6 min · Read →
Jun 10, 2026

Terraform Azure Storage Accounts: Footguns and Production Config

The azurerm_storage_account resource ships with permissive defaults on every security-relevant attribute. Here is how we configure it correctly before production.

#terraform#azure#infrastructure#iac
5 min · Read →
Jun 8, 2026

Azure Sentinel Connectors: What Actually Works in Production

Getting data into Microsoft Sentinel is where most SIEM rollouts quietly fail. This field note covers connector types, AMA migration pitfalls, and DCR routing that holds up under real ingestion load.

#microsoft sentinel#azure sentinel#detection engineering#siem#cloud security
6 min · Read →
May 23, 2026

Microsoft Azure Sentinel in 2026: the portal cutover is five weeks out

The Azure portal for Microsoft Sentinel retires July 1, 2026. This field note covers what breaks if you wait, the query migration already past due, and the new detection capabilities shipping this year.

#azure sentinel#microsoft sentinel#siem#kql#detection engineering
6 min · Read →
May 22, 2026

Migrating Azure Sentinel off MMA: a field guide for production environments

MMA retires August 2024. Here's the AMA + DCR/DCE pattern we used to move fourteen custom connectors with zero ingestion gaps and half the operating cost.

#azure sentinel#siem#log analytics#ama#migration
4 min · Read →
May 21, 2026

Six AI-agent and RAG patterns we keep yanking out of production

Vector retrieval that returns garbage, prompt injection by way of a CSV upload, runaway token bills. Patterns to avoid, with the fix that actually shipped.

#ai agents#rag#llm#security
3 min · Read →