Skip to content

v0.1.0 - Microsoft Sentinel KQL Detection Lab

Latest

Choose a tag to compare

@rubenasuasoto rubenasuasoto released this 06 Jul 10:24

v0.1.0

Initial public release of Microsoft Sentinel KQL Detection Lab.

  • Public mini-SIEM demo on GitHub Pages.
  • Playbooks published in GitBook.
  • Six defensive Sentinel-style KQL analytics across SigninLogs, AuditLogs and SecurityEvent.
  • Synthetic fixtures, local oracle, validation report and CI.
  • Cross-source identity incident scenario connecting Entra and Windows signals.
  • No Azure tenant, Log Analytics workspace, credentials, tokens, production logs or live Sentinel calls.

Demo:
https://rubenasuasoto.github.io/microsoft-sentinel-kql-detection-lab/reports/latest/demo.html

GitBook:
https://2dam-7.gitbook.io/window-sentinel/