Heider Albadawi
SC-100, SC-400, SC-200, SC-300, AZ-500
Heider leads Detection Engineering, specialising in Microsoft Sentinel analytics, KQL development and security architecture. His expertise spans SIEM optimisation, analytics rule development and the Microsoft security stack, supported by SC-100 (Cybersecurity Architect) and SC-400 (Information Protection Administrator) alongside SC-200, SC-300 and AZ-500.
2 articles
The Difference Between SIEM and Log Management
Every SIEM contains a log manager. No log manager contains a SIEM. What each one is for, why the distinction gets blurred, and which you actually need.
SIEMBest SIEM Tools in 2022 — And What Has Changed Since
Most of the 2022 SIEM shortlist has since been acquired, merged or absorbed. What actually changed, what did not, and how to choose one now.
Talk to the people
who do the work.
A demo against your own estate rather than a canned one, run by an analyst rather than a salesperson.