Microsoft Sentinel, SIEM, SOAR, KQL, SOC Operations: Explore cloud-native security monitoring, threat detection, incident investigation, and automated response workflows.
-
Updated
Jul 14, 2026
Microsoft Sentinel, SIEM, SOAR, KQL, SOC Operations: Explore cloud-native security monitoring, threat detection, incident investigation, and automated response workflows.
A Microsoft Sentinel SOC homelab in Azure, where I built and validated a basic cloud SOC workflow: data onboarding, detection, investigation, and visualization. It demonstrates practical blue-team skills in SIEM operations, KQL-based threat hunting, watchlist enrichment, and workbook reporting.
Microsoft Sentinel cloud SIEM lab - deployed Azure VM, ingested Windows Security Events via AMA, wrote KQL queries to detect brute force attacks and failed logins in real time. Replicates L1 SOC analyst workflows.
Microsoft Sentinel SOC lab using Azure Virtual Machines to investigate Windows Event ID 4625 authentication failures with KQL and identify suspicious IP activity.v
Add a description, image, and links to the microsoft-sentinel-kql topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-sentinel-kql topic, visit your repo's landing page and select "manage topics."