<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Sertaç Canbey</title>
    <description>The latest articles on DEV Community by Sertaç Canbey (@sertacanbey).</description>
    <link>https://dev.to/sertacanbey</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4169182%2Fb23d1da9-c71a-4b52-89b8-d338baced203.png</url>
      <title>DEV Community: Sertaç Canbey</title>
      <link>https://dev.to/sertacanbey</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/sertacanbey"/>
    <language>en</language>
    <item>
      <title>I built an open-source, 100% local Microsoft Entra Security Analyzer</title>
      <dc:creator>Sertaç Canbey</dc:creator>
      <pubDate>Wed, 07 Oct 2026 14:46:53 +0000</pubDate>
      <link>https://dev.to/sertacanbey/i-built-an-open-source-100-local-microsoft-entra-security-analyzer-14jj</link>
      <guid>https://dev.to/sertacanbey/i-built-an-open-source-100-local-microsoft-entra-security-analyzer-14jj</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;

&lt;p&gt;Working with Microsoft Entra ID (Azure AD) sign-in logs to hunt down distributed password sprays or track MFA gaps can be a nightmare. There are great SaaS tools out there, but I was always uncomfortable granting third-party cloud services read-access to my entire company's directory and audit logs.&lt;/p&gt;

&lt;p&gt;So over the last few months, I built &lt;strong&gt;IDSignal&lt;/strong&gt; — an open-source, zero-cloud dependency security analyzer. It runs entirely locally on your own machine (or via Docker in your private network). Your tenant data never leaves your environment.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fii9tt8tsbw9ohgp3dcsd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fii9tt8tsbw9ohgp3dcsd.png" alt="Dashboard Preview" width="799" height="388"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  What it does automatically:
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;Hunts Password Sprays:&lt;/strong&gt; Unmasks distributed attacks (Event 50126) and groups them by threat actor IPs.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Spots MFA Gaps:&lt;/strong&gt; Pinpoints users who do not have MFA configured or active on their accounts.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Calculates Risk Scores:&lt;/strong&gt; Combines active threats + missing security controls to give each user an explainable priority score.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Interactive Dashboard:&lt;/strong&gt; A really fast, local UI to filter through the noise instantly.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Quick Start (Docker)
&lt;/h3&gt;

&lt;p&gt;I’ve made it incredibly easy to spin up. If you have Docker, it's just one command:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;docker run &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="nt"&gt;--name&lt;/span&gt; idsignal &lt;span class="nt"&gt;-v&lt;/span&gt; idsignal_data:/app/data &lt;span class="nt"&gt;-p&lt;/span&gt; 4317:4317 ghcr.io/sertacanbey/idsignal:latest
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I’d love for the community to tear it apart, test it, and give me some brutally honest feedback.&lt;/p&gt;

&lt;p&gt;GitHub Repo: &lt;br&gt;
&lt;a href="https://github.com/SertaCanbey/IDSignal" rel="noopener noreferrer"&gt;https://github.com/SertaCanbey/IDSignal&lt;/a&gt;&lt;br&gt;
Live Demo: &lt;br&gt;
&lt;a href="https://idsignal.org" rel="noopener noreferrer"&gt;https://idsignal.org&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Let me know what you think!&lt;/p&gt;

</description>
      <category>showdev</category>
      <category>opensource</category>
      <category>security</category>
      <category>docker</category>
    </item>
  </channel>
</rss>
