Turning Microsoft Sentinel Alerts into Analyst-Ready Incidents with AI
Planned follow-up covering Logic Apps, Sentinel incidents, alert enrichment, MITRE mapping, and automated triage summaries.
./bɑːtBat Otgonbayar
Technical notes, lab builds, investigations, and lessons learned from identity, cloud security, Microsoft Sentinel, PowerShell automation, and blue-team projects.
I exposed a Windows VM to the public internet, wired it into Microsoft Sentinel, and analyzed 26,066 failed logons from 253 source IPs. This writeup focuses on telemetry, detections, attacker behavior, and the assumptions the data challenged.
Setting up a complete Active Directory environment using VMware Workstation Pro, Windows Server, networking configuration, and a first domain controller.
Continuation of the Active Directory home lab series, covering a more realistic internal structure with organizational units, bulk user creation, and security groups for the fictional Secora environment.
A companion script collection for the AD lab series, including bulk user creation, inactive-user cleanup, ACL/security auditing, authentication-event review, system health reporting, secure backup auditing, and endpoint hardening.
Planned follow-up covering Logic Apps, Sentinel incidents, alert enrichment, MITRE mapping, and automated triage summaries.