Susheel Thapa
Skip to content
>_ST
AzureMicrosoft SentinelKQLThreat DetectionVNet

Enterprise Cloud Security Monitoring & SIEM Detection Lab

Full-cycle Azure cloud defense lab simulating multi-tier network isolation, Microsoft Sentinel log ingestion, and automated threat hunting rules.

Azure Sentinel SIEM Detection Lab Architecture

A complete hands-on defense lab designed to simulate enterprise SOC workflows in Microsoft Azure. The architecture demonstrates segmented virtual networks, centralized telemetry aggregation, custom detection engineering using Kusto Query Language (KQL), and incident triage.

Architecture Topology

The lab topology isolates compromised workload subnets from management planes using Azure Network Security Groups (NSGs).

    flowchart LR
  Internet((Public Internet))
  subgraph VNet ["Azure Virtual Network (10.0.0.0/16)"]
      subgraph DMZ ["DMZ Subnet (10.0.1.0/24)"]
          Bastion["Bastion / Jump Box"]
      end
      subgraph AppSubnet ["App Workload Subnet (10.0.2.0/24)"]
          WebVM["Ubuntu 22.04 LTS (Docker)"]
      end
  end

  subgraph SIEM ["Telemetry Plane"]
      LogAnalytics["Log Analytics Workspace"]
      Sentinel["Microsoft Sentinel SIEM"]
  end

  Internet -->|SSH Port 22| Bastion
  Bastion -->|Internal RDP/SSH| WebVM
  WebVM -.->|Syslog & AMA Agent| LogAnalytics
  LogAnalytics --> Sentinel
  

Detection Engineering with KQL

To identify potential brute-force attempts and credential access anomalies, custom analytics rules were deployed to monitor failed authentication logs:

// Identify brute-force authentication attempts across Linux hosts
Syslog
| where Facility == "auth" and SyslogMessage has "Failed password"
| parse SyslogMessage with * "invalid user " TargetUser " from " SourceIP " port" *
| summarize FailedCount = count() by SourceIP, TargetUser, bin(TimeGenerated, 5m)
| where FailedCount >= 5
| project TimeGenerated, SourceIP, TargetUser, FailedCount
| sort by FailedCount desc

Key Implementation Highlights

  • VNet Segmentation: Virtual Network peered subnets with granular NSG ingress/egress filtering rules.
  • Log Aggregation: Azure Monitor Agent (AMA) streaming authentication, kernel audit logs, and firewall traffic.
  • Investigation Matrix: Triage playbook covering event timeline reconstruction and alert verification.