End-to-end Microsoft Sentinel SOC lab: KQL detections and threat hunts for SSH brute force (T1110) and malicious PowerShell (T1059.001).
-
Updated
Jul 29, 2026
End-to-end Microsoft Sentinel SOC lab: KQL detections and threat hunts for SSH brute force (T1110) and malicious PowerShell (T1059.001).
Awesome Kusto Query Language (KQL)
Hybrid SIEM evaluation — Microsoft Sentinel + KQL, live-compared against an existing Wazuh SOC lab
SOC Phishing Email Investigation & Automated Response using Microsoft Sentinel, KQL, MITRE ATT&CK and SOAR, N8N
Data Analyst
Information Security Analyst
Application of the HITS Threat Hunting Framework incorporating agentic AI for delivery across Sentinel, Defender and the wider Microsoft ecosystem
To associate your repository with the kql-microsoft-sentinel topic, visit your repo's landing page and select "manage topics."