32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more
-
Updated
Aug 1, 2026
32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more
Cloud-based SOC environment using Microsoft Sentinel, Azure Arc, KQL, and Windows Security Events for threat detection and incident monitoring.
A Microsoft Sentinel SOC homelab in Azure, where I built and validated a basic cloud SOC workflow: data onboarding, detection, investigation, and visualization. It demonstrates practical blue-team skills in SIEM operations, KQL-based threat hunting, watchlist enrichment, and workbook reporting.
This repository contains demos and guides on how to setup Sentinel for Cloud. These demos are intended as a guide. For official guidance, support, or more detailed information, please refer to Microsoft's official documentation or contact Microsoft directly.
Add a description, image, and links to the microsoft-sentinel-workbook topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-sentinel-workbook topic, visit your repo's landing page and select "manage topics."