v0.1.0
Initial public release of Microsoft Sentinel KQL Detection Lab.
- Public mini-SIEM demo on GitHub Pages.
- Playbooks published in GitBook.
- Six defensive Sentinel-style KQL analytics across SigninLogs, AuditLogs and SecurityEvent.
- Synthetic fixtures, local oracle, validation report and CI.
- Cross-source identity incident scenario connecting Entra and Windows signals.
- No Azure tenant, Log Analytics workspace, credentials, tokens, production logs or live Sentinel calls.
Demo:
https://rubenasuasoto.github.io/microsoft-sentinel-kql-detection-lab/reports/latest/demo.html