Microsoft Sentinel Home SOC Lab
Azure VM as a honeypot, forwarded live attack logs to Sentinel, built a real-time attack map. Created automated incident response workflows using Logic Apps; alerts fired within minutes. Wrote KQL rules targeting failed RDP logins (Event ID 4625), enriched attacker IPs with GeoIP watchlist data, automated metadata logging to a custom Sentinel table via Logic App.