AzureMicrosoft SentinelKQLThreat DetectionVNet
Enterprise Cloud Security Monitoring & SIEM Detection Lab
Full-cycle Azure cloud defense lab simulating multi-tier network isolation, Microsoft Sentinel log ingestion, and automated threat hunting rules.
A complete hands-on defense lab designed to simulate enterprise SOC workflows in Microsoft Azure. The architecture demonstrates segmented virtual networks, centralized telemetry aggregation, custom detection engineering using Kusto Query Language (KQL), and incident triage.
Architecture Topology
The lab topology isolates compromised workload subnets from management planes using Azure Network Security Groups (NSGs).
flowchart LR
Internet((Public Internet))
subgraph VNet ["Azure Virtual Network (10.0.0.0/16)"]
subgraph DMZ ["DMZ Subnet (10.0.1.0/24)"]
Bastion["Bastion / Jump Box"]
end
subgraph AppSubnet ["App Workload Subnet (10.0.2.0/24)"]
WebVM["Ubuntu 22.04 LTS (Docker)"]
end
end
subgraph SIEM ["Telemetry Plane"]
LogAnalytics["Log Analytics Workspace"]
Sentinel["Microsoft Sentinel SIEM"]
end
Internet -->|SSH Port 22| Bastion
Bastion -->|Internal RDP/SSH| WebVM
WebVM -.->|Syslog & AMA Agent| LogAnalytics
LogAnalytics --> Sentinel
Detection Engineering with KQL
To identify potential brute-force attempts and credential access anomalies, custom analytics rules were deployed to monitor failed authentication logs:
// Identify brute-force authentication attempts across Linux hosts
Syslog
| where Facility == "auth" and SyslogMessage has "Failed password"
| parse SyslogMessage with * "invalid user " TargetUser " from " SourceIP " port" *
| summarize FailedCount = count() by SourceIP, TargetUser, bin(TimeGenerated, 5m)
| where FailedCount >= 5
| project TimeGenerated, SourceIP, TargetUser, FailedCount
| sort by FailedCount desc
Key Implementation Highlights
- VNet Segmentation: Virtual Network peered subnets with granular NSG ingress/egress filtering rules.
- Log Aggregation: Azure Monitor Agent (AMA) streaming authentication, kernel audit logs, and firewall traffic.
- Investigation Matrix: Triage playbook covering event timeline reconstruction and alert verification.