A Microsoft security operations portfolio demonstrating Sentinel, Defender XDR, Defender for Endpoint and Defender for Office 365 across threat detection, hunting, phishing investigation and incident response.
To demonstrate enterprise security operations capabilities across Microsoft Sentinel and Defender XDR through detection engineering, threat hunting, investigation and incident response.
π Project Sequence: The projects demonstrate progressively broader security operations capabilities, covering SIEM-based threat hunting, email security, adversary emulation, endpoint detection, and end-to-end incident investigation using Microsoft security technologies.
| S.No | Project Title | Link |
|---|---|---|
| 1. | SOC Threat Hunting with Microsoft Sentinel | View Project |
| 2. | Email Security & Phishing Analysis in Microsoft Defender | View Project |
| 3. | Attack Emulation and SOC Investigation Using Microsoft Security Tools | View Project |
| 4. | Microsoft Defender XDR: Phishing-Led Multi-Stage Attack Simulation & End-to-End SOC Investigation | View Project |
This portfolio demonstrates SOC operations across identity, endpoint, email, and cloud security using the Microsoft Security Stack.
- Microsoft Sentinel: Applied KQL-based detection, log analysis, data correlation, threat hunting, and incident investigation.
- Microsoft Defender XDR & Defender for Endpoint: Investigated endpoint alerts, correlated security signals, analyzed attack paths, and identified malicious activity.
- Microsoft Defender for Office 365: Analyzed phishing campaigns through email headers, URLs, attachments, and payload indicators.
- Microsoft Entra ID: Assessed authentication activity, identity risks, and Conditional Access controls.
Across these projects, I correlated telemetry across security layers, mapped adversary behavior to MITRE ATT&CK, and applied structured SOC investigation and response workflows.
- Microsoft Sentinel (SIEM) β Log ingestion, data correlation, KQL-based detection, threat hunting, and incident management
- Microsoft Defender XDR β Cross-domain threat detection, incident correlation, investigation, and response
- Microsoft Defender for Endpoint (EDR) β Endpoint detection, investigation, threat hunting, and response
- Microsoft Defender for Office 365 β Email threat protection, phishing analysis, and threat investigation
- Microsoft Entra ID β Identity monitoring, authentication analysis, risky sign-in investigation, and Conditional Access
- Microsoft Intune β Endpoint management and device compliance concepts