Portfolio / Azure

Sentinel Analytics Rule & Automated Response

Status: Verified
#Microsoft Sentinel #Detection Engineering #MITRE ATT&CK #KQL

Introducing This Project

Building on the risk-tiered geo-map, I converted the “Critical” risk tier into a live, scheduled Sentinel analytics rule with entity mapping (so Sentinel correctly identifies the accounts and IPs involved) and MITRE ATT&CK technique tagging for each triggered alert.

Tools and Concepts

Microsoft Sentinel analytics rules, entity mapping, MITRE ATT&CK technique tagging, detection engineering lifecycle (from workbook to live rule).

Project Reflection

This project took my detection logic from a passive visualization into an active, alerting control — the natural next step in a real detection engineering workflow. I also documented a finding where the shared cyber-range environment blocked a safe IAM test action, which became a useful lesson in testing detections within constrained lab environments.

View full write-up on GitHub →

Next Phase

Continue exploring projects

Return to Portfolio
© 2026 Sahil K.
Cloud Portfolio | Built with Astro & Tailwind