Building a Cloud SIEM Honeypot, Part 1
Azure VM exposure, Sentinel telemetry, Windows Event ID 4625, KQL detections, and real-world brute-force observations.
I'm Bat Otgonbayar, a cybersecurity practitioner focused on identity, cloud security, Microsoft 365, Sentinel, and PowerShell automation. This site is where I document hands-on labs, investigations, and lessons learned from real technical projects.
I exposed a throwaway Windows VM to the public internet, wired it into Microsoft Sentinel, and analyzed what showed up: failed logons, source IP concentration, username patterns, and one telemetry detail that challenged my assumptions.
Azure VM exposure, Sentinel telemetry, Windows Event ID 4625, KQL detections, and real-world brute-force observations.
Windows Server 2025, VMware Workstation Pro, host-only networking, and the foundation for a practical identity lab.
Creating 30 users, organizing OUs, and building security groups to turn the Secora lab into a more realistic identity environment.
Reusable PowerShell scripts for bulk user creation, inactive-account cleanup, ACL auditing, authentication review, secure backup auditing, and system health reporting.
I'm a detail-oriented cybersecurity practitioner with experience across identity management, access controls, Microsoft 365, endpoint support, and IT infrastructure. I like practical security projects that leave behind something useful: detections, scripts, diagrams, notes, or a repeatable process someone else can learn from.
My focus areas include Active Directory, Microsoft Entra ID, Intune, Microsoft Sentinel, Splunk, KQL, PowerShell, Azure, Okta, and security automation.