Reality looks better in post

Proof we're not bluffing

Here’s the evidence. Brand pieces so bold they’ve been asked to tone it down, demos that could teach a goldfish cloud computing, and digital events that made audiences put down their @#$% phones. Every video here was built to grab attention, spark curiosity, and lodge itself in memory like a souvenir you’re strangely attached to. We’re talking craft, care, and the occasional flourish made purely to amuse ourselves. Proof we’re not bluffing—because who has time to fake this many good videos without winning an award or two?

March 2023
Microsoft Security
Microsoft Defender for Endpoint: EDR in block mode
Demo videos
Full playlist
Sandgate
Enable EDR in block mode to stop threats in real time—even with third-party AV—adding behavior-based blocking that contains attack chains faster in Defender for Endpoint.

This video explains EDR in block mode in Microsoft Defender for Endpoint—how it can actively block malicious behaviors even if Defender Antivirus isn’t your primary AV. It walks through what EDR block mode does, the prerequisites (including cloud-delivered protection), and how enabling it adds real-time stopping power against behavior-based threats that might slip past traditional prevention. The demo illustrates the payoff with an attack chain scenario, showing how behavior detection leads to blocking and containment.

We structured this as a proof-driven feature spotlight: define the gap, show the one-toggle enablement, then land the value with a concrete “what gets stopped” example. The edit keeps the story tight so the viewer remembers the takeaway: faster containment with fewer “we’ll investigate later” moments. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Evaluation lab
Demo videos
Full playlist
Sandgate
Use the Microsoft 365 Defender evaluation lab to test detections safely—run controlled scenarios, review alerts and evidence, and learn how workflows behave before going live.

This demo shows how to use the Microsoft 365 Defender evaluation lab to safely test security features and attacker techniques without risking production environments. It introduces the lab as a controlled sandbox, then walks through launching evaluation scenarios, running simulations, and reviewing the resulting detections, alerts, and investigation artifacts. The emphasis is on learning by doing—seeing what Defender catches, how it presents evidence, and how response workflows behave.

Our goal here was to make the lab feel approachable—less “security science fair,” more “flip the switch and learn.” The screen flow is intentionally linear, with editing that keeps viewers oriented as they move from setup to results, plus a polished final package (captions, audio description, thumbnails) for training and internal enablement.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Discover unmanaged devices
Demo videos
Full playlist
Sandgate
Discover shadow IT with Defender for Cloud Apps—surface cloud app usage, review risk scores and activity, then decide what to sanction, monitor, or block.

This demo introduces Microsoft Defender for Cloud Apps discovery—how to uncover the cloud apps your organization is actually using (including the ones nobody officially invited). It shows how discovery is powered by data sources like Defender for Endpoint device signals and network logs, then walks through reviewing discovered apps, their risk scores, categories, and usage patterns. The video highlights how to pivot from “what apps are in play” to “which ones are risky,” so teams can decide what to sanction, what to monitor, and what to block.

To make this feel actionable (not like a museum tour of dashboards), we built the walkthrough around quick decisions: identify apps, assess risk, take the next step. The visual flow stays tight on the fields admins care about, and the edit keeps things moving so viewers remember the workflow, not the menu path. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Assess and onboard unmanaged devices
Demo videos
Full playlist
Sandgate
Use Microsoft 365 Defender assessments to prioritize security improvements—review recommendations, see impacted assets, and follow guidance to close gaps with the most impact.

This demo walks through security posture assessment in Microsoft 365 Defender—how to evaluate where you stand and what to fix first. It shows how recommendations surface gaps across configurations, devices, and protection settings, then demonstrates reviewing recommendation details, affected assets, and implementation guidance. The focus is on turning assessment into a prioritized plan, not just collecting findings.

We produced this as a “make it measurable” walkthrough: the narrative is built around prioritization and follow-through, with visuals that linger on the parts teams actually use to plan work (impact, scope, remediation steps). The pacing stays brisk, but it’s designed to leave viewers with a clear next action. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Architecture
Animations
Full playlist
Sandgate
A clear architecture tour of Microsoft Defender for Endpoint—portal, sensors, telemetry, response actions, integrations, and APIs—showing how Microsoft 365 Defender delivers protection end to end.

This explainer breaks down the architecture of Microsoft Defender for Endpoint—so security teams understand what’s happening behind the curtain when the alerts start tap-dancing. It walks through the Microsoft 365 Defender portal (dashboards, reports, entity views, fast pivots, and investigation tools like advanced hunting and live response), then shifts to endpoint sensors that gather security events from onboarded devices and send them to the customer tenant over the internet. It calls out the range of endpoint controls generating telemetry—threat and vulnerability management, next-generation protection, attack surface reduction, EDR sensors, and update services—plus response actions like collecting suspicious files, isolating devices, or running AV scans. It also highlights detecting unmanaged devices on the network, safe investigation via a cloud sandbox, integrations with services like Microsoft Sentinel, Defender for Cloud, Information Protection, and Endpoint Manager, and API-based connections to SIEMs, ticketing, custom workflows, and even customer-provided threat intelligence.

We produced this as a clarity-first animation built to make a technical system feel understandable in one sitting. We shaped the story into a clean three-part structure (portal, sensors, tenant/service) so the viewer always knows where they are, then reinforced each concept with visuals that clarify instead of clutter. Professional voiceover and supportive music keep the pace confident, while sound design and timing make the terminology land cleanly—no mumbling acronyms, no “wait, what was that?” rewinds. After streamlined review loops, we delivered the full package with closed captions, audio description, and thumbnails—ready to educate, reassure, and reduce friction for busy security teams.

false
March 2023
Microsoft Security
Microsoft Defender for Endpoint: Deploy Mobile Threat Defense
Demo videos
Full playlist
Sandgate
Deploy Defender for Endpoint mobile MTD—integrate with Intune, assign the Defender app to users, complete onboarding, and start enforcing access based on mobile risk signals.

This demo walks through deploying Microsoft Defender for Endpoint on mobile devices as part of a Mobile Threat Defense (MTD) rollout—so iOS and Android devices report risk signals you can enforce with Intune and Conditional Access. It covers the core deployment path: integrate Defender for Endpoint with Microsoft Endpoint Manager (Intune), assign the Defender app to users or device groups, and ensure users complete the required onboarding steps so the device begins reporting threat status. The video also touches on what “good” looks like after deployment—devices showing up with risk signals flowing, and the organization ready to apply compliance policies and access controls based on that risk.

We produced this as a rollout-friendly walkthrough designed for admins who need the shortest path from “we bought it” to “it’s working.” The narration calls out the order of operations, the visuals focus on the handful of settings that matter, and the edit keeps the pace brisk while still showing the checkpoints that confirm success. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender Vulnerability Management
Demo videos
Full playlist
Sandgate
Use Defender Vulnerability Management to reduce exposure—prioritize recommendations, request remediation via Endpoint Manager or ServiceNow, track exceptions, and monitor vulnerable software fast.

Microsoft Defender Vulnerability Management offers intelligent assessments, risk-based prioritization, and built-in mitigation and remediation tools—all from the Microsoft 365 Defender portal. This video stays focused on the dashboard experience: it explains the Exposure score (lower is better) and what goes into it (weaknesses, breach likelihood, device value, and alerts), then shows how to improve that score using top security recommendations sorted by exposure impact. It highlights quick context you get directly in the recommendations list—active alerts and threat insights like publicly available exploit kits—then drills into a recommendation to review impacted devices, addressed vulnerabilities, and the software page (including where an app is installed and the expected user impact based on 30 days of machine analysis). The tour also covers Microsoft Secure Score for Devices (configuration-focused hardening recommendations), requesting remediation tickets in Microsoft Endpoint Manager or ServiceNow, creating scoped time-bound exceptions with justification, tracking remediation progress and exceptions, using Exposure distribution to jump into filtered device inventory, and reviewing Top vulnerable software plus the Inventories page for weaknesses, active threats, and exposed device counts. It closes by calling out an add-on with expanded capabilities like consolidated inventories, blocking vulnerable app versions, and compliance monitoring against benchmarks and custom baselines.

We produced this as a paced, clarity-first demo that turns a dense admin dashboard into a story you can follow—without losing the technical substance. In preproduction we mapped the narrative arc, then in production we captured clean UI with professional voiceover and music that supports momentum. In post, we tightened the flow around the moments that matter—impact, evidence, and next steps—so your audience comes away remembering how to act, not just what they saw. After review rounds, we deliver the finished video with closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft Defender for Cloud Apps: Protecting cloud apps in Microsoft 365 Defender
Demo videos
Full playlist
Sandgate
Meet Microsoft Defender for Cloud Apps—discover shadow IT, monitor SaaS activity, assess risk, and apply controls that improve visibility and reduce cloud-app exposure.

This demo introduces Microsoft Defender for Cloud Apps (often referred to as “MDA”) and how it strengthens visibility and control over SaaS usage in your organization. It highlights discovering cloud apps in use (shadow IT), assessing risk, monitoring activity, and applying governance controls to reduce exposure. The video positions MDA as a way to connect signals across your security stack—so you can detect risky app behavior, investigate incidents with richer app context, and take action through policies that help prevent data loss or unwanted access patterns.

We produced this as a straightforward platform overview—built to make a broad product feel concrete. We shaped the story around real outcomes (visibility, risk reduction, control), used clean UI capture and steady narration to keep it approachable, and edited for momentum so viewers can absorb the “what” and “why” quickly. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft 365 Defender: Unpacking JSON in KQL
Demo videos
Full playlist
Sandgate
Unpack JSON in Advanced Hunting—use parse_json/todynamic and bag_unpack to turn fields like AdditionalFields into readable columns, avoid name collisions with prefixes, and hunt faster.

This tutorial shows how to extract useful fields from JSON strings in Advanced Hunting using Kusto Query Language. It explains JSON basics (key-value pairs in quotes, lists in brackets) and points out that most hunting columns are scalar, but some—like AdditionalFields—contain packed JSON that’s hard to work with in a grid. The demo converts the JSON string into a dynamic value using parse_json (also known as todynamic), then uses dotted notation to extend individual members into new columns (for example, pulling out ClassName, ClassId, DeviceId, DeviceDescription, and VendorIds). It also notes an important limitation: you can’t summarize/aggregate on dynamic values, but you can convert back to string with tostring when needed. To make the extraction cleaner, it demonstrates bag_unpack as a simpler way to expand all members into columns, and solves duplicate-column-name errors by using the bag_unpack prefix parameter (adding a prefix like AdditionalFields to each unpacked field).

We produced this as a compact “learn one trick, unlock a lot” tutorial. The visuals are deliberately close on the result grid and query edits so viewers can follow the transformation from unreadable blob to usable columns, and the pacing slows briefly on the two gotchas that actually bite people (dynamic type behavior and name collisions). Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft 365 Defender: Unified submissions
Demo videos
Full playlist
Sandgate
Manage Defender submissions in one place—enable user reporting, review message details, submit emails/attachments/URLs/files to Microsoft for analysis, and track results end-to-end.

This demo tours the new unified Submissions experience in the Microsoft 365 Defender portal—the single Submissions page where SecOps can manage user-reported messages plus admin submissions for emails, email attachments, URLs, and files. It starts on the User reported messages tab (Explorer-like list view), then shows the required configuration to enable user reporting and decide where reports go (Microsoft, a mailbox you choose, or both—along with the note that submissions sent to Microsoft include the message as-is). From an individual reported message, it reviews the details pane (reported message details, delivery details, threat type, delivery action, plus extracted URLs and attachments) and calls out whether the item has been converted to an admin submission. It then moves into the admin submission tabs—Emails (submit by network message ID or upload an email file, flag false positive/negative, and optionally allow similar emails temporarily), Email attachments (upload the file), URLs (submit and track analysis), and Files (upload up to 500 MB, categorize as malware/unwanted software/clean, choose priority with a limit of three high-priority submissions per day, add notes, and submit).

We produced this as a “one page, all submissions” walkthrough that keeps the interface—and the decision points—easy to absorb. The script is built around the real sequence analysts follow (review, validate, submit, track), the screen capture stays tight on the fields that matter, and the edit trims away navigation drift so viewers come away knowing exactly where to go and what levers to pull. Final delivery includes closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft 365 Defender: Threat analytics
Demo videos
Full playlist
Sandgate
Use Threat analytics in Microsoft 365 Defender to spot active threats, read analyst reports, review incidents and impacted assets, and follow mitigations via Defender Vulnerability Management.

Threat analytics in Microsoft 365 Defender is presented as built-in threat intelligence that helps security teams respond to emerging, high-risk threats without spelunking through five different portals and a haunted spreadsheet. The video shows where to find it (top nav, plus a home-page card that flags threats active on your network) and what you get when you open a threat: a short summary, an Alerts over time view spanning active and resolved alerts, and posture insights that include email detections and mitigations alongside endpoint data. It then walks through the analyst report from the Microsoft Threat Intelligence team—deep-dive analysis that can include attack-chain diagrams, MITRE techniques, recommended mitigations, detection details, and sometimes Advanced Hunting queries—before exploring the threat-specific tabs: Related incidents, Impacted assets (devices and mailboxes with trending charts), Prevented email attempts (delivery actions/locations), and Exposure and mitigations with links into Microsoft Defender Vulnerability Management for secure configuration and vulnerability insights.

We produced this as a “read, assess, act” demo that keeps the workflow crisp: understand the threat, see your exposure, and move straight into remediation. In preproduction we shaped the narrative around what security teams actually need in the moment, in production we captured clean screens with professional voiceover and paced music, and in post we trimmed the noise so the tabs, charts, and next steps land quickly. The result is a walkthrough that helps viewers turn threat intel into action—faster incident handling, clearer asset impact, and a tighter feedback loop on mitigations—delivered with closed captions, audio description, and thumbnails.

false
March 2023
Microsoft Security
Microsoft 365 Defender: Using Advanced Hunting
Demo videos
Full playlist
Sandgate
Get started with Advanced hunting in Microsoft 365 Defender—query cross-domain telemetry with KQL, pivot from incidents into hunts, and uncover related activity faster.

This demo introduces Advanced hunting in Microsoft 365 Defender as the place you go when you need answers that dashboards can’t give you yet. It frames hunting as proactive investigation—querying raw telemetry across endpoints, identity, email, cloud apps, and more—then walks through the Advanced hunting experience: choosing from built-in schemas/tables, writing KQL queries, and iterating quickly using the results grid. The video highlights common analyst moves like filtering by time window, pivoting from entities and incident evidence into hunts, and using query results to scope an investigation, validate hypotheses, and uncover related activity that may not have been surfaced as an incident.

We produced this as an on-ramp that makes hunting feel approachable rather than intimidating. Preproduction shaped the story around how analysts actually work (start broad, refine, follow the evidence), production captured clean screens with steady, plain-English narration, and post kept the pace brisk while still letting key concepts land. Final delivery includes closed captions, audio description, and thumbnails.

true
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.