This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
-
Updated
Jun 30, 2026 - PowerShell
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
TerraSigma - Modern Detection Engineering for the Cloud-Native SIEM Microsoft Sentinel
Sigma Queries turned into KQL for Defender using pysigma - Automated
Private repository for Sentinel related documentation, gists, scripts and code snippets which might be useful for implementation, tuning and troubleshooting
This file presents deployment code of virtual network implementation within the Microsoft Azure cloud environment and its integration with Microsoft Sentinel as SIEM system to provide automated solutions for various security scenarios.
Project shows how to build a mini honeypot with Azure, ingest log files from real traffic into Microsoft Sentinel using Law Analytics Workspace . Also showing how to respond to incidents on Sentinel Dashboard. Writing KQL scripts , Using NIST 800-53 Access Control and NIST 800-61 Incidnet Response to harden environment.
Repos supporting LogServ integration in Microsoft Sentinel
Managing Microsoft Sentinel with Azure Lighthouse
Explore threat hunting commands with Microsoft Sentinel to detect and investigate threats more efficiently.
Cloud-based SOC project using Microsoft Sentinel for log ingestion, threat detection, and security incident investigation.
A practical Cyber Threat Intelligence (CTI) series demonstrating how public threat advisories are transformed into actionable detection, investigation, and response within an enterprise security environment.
This repository provides Analytics Rule of Microsoft Sentinel to support Structured Format about Azure Firewall.
Get Azure Monitor QoS log (Mdsd) for Linux
The objective of this lab is to set up Microsoft Sentinel. A virtual machine will be created in the cloud and configured as a honeypot. This setup will allow monitoring and logging of various attacks. The ultimate goal is to create a map displaying the origin of the attacks.
🚀 Automate Sigma rule conversion to KQL and Terraform for Microsoft Sentinel, streamlining detection management with infrastructure-as-code.
Azure Vnetフローログを分析し、Microsoft Sentinel のブック機能で可視化することを学べる演習コンテンツです。
Hands-on Microsoft Sentinel incident response labs covering detection, investigation, and response using KQL, Defender telemetry, and NIST 800-61 methodology.
To associate your repository with the microsoftsentinel topic, visit your repo's landing page and select "manage topics."