Skip to content

Latest commit

Β 

History

21 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 

Repository files navigation

Microsoft Security Stack

A Microsoft security operations portfolio demonstrating Sentinel, Defender XDR, Defender for Endpoint and Defender for Office 365 across threat detection, hunting, phishing investigation and incident response.

🎯 Objective

To demonstrate enterprise security operations capabilities across Microsoft Sentinel and Defender XDR through detection engineering, threat hunting, investigation and incident response.

πŸ“Š Projects

πŸ“Œ Project Sequence: The projects demonstrate progressively broader security operations capabilities, covering SIEM-based threat hunting, email security, adversary emulation, endpoint detection, and end-to-end incident investigation using Microsoft security technologies.

S.No Project Title Link
1. SOC Threat Hunting with Microsoft Sentinel View Project
2. Email Security & Phishing Analysis in Microsoft Defender View Project
3. Attack Emulation and SOC Investigation Using Microsoft Security Tools View Project
4. Microsoft Defender XDR: Phishing-Led Multi-Stage Attack Simulation & End-to-End SOC Investigation View Project

πŸ› οΈ Capabilities Demonstrated

This portfolio demonstrates SOC operations across identity, endpoint, email, and cloud security using the Microsoft Security Stack.

  • Microsoft Sentinel: Applied KQL-based detection, log analysis, data correlation, threat hunting, and incident investigation.
  • Microsoft Defender XDR & Defender for Endpoint: Investigated endpoint alerts, correlated security signals, analyzed attack paths, and identified malicious activity.
  • Microsoft Defender for Office 365: Analyzed phishing campaigns through email headers, URLs, attachments, and payload indicators.
  • Microsoft Entra ID: Assessed authentication activity, identity risks, and Conditional Access controls.

Across these projects, I correlated telemetry across security layers, mapped adversary behavior to MITRE ATT&CK, and applied structured SOC investigation and response workflows.

πŸ›‘οΈ Security Capabilities

  • Microsoft Sentinel (SIEM) – Log ingestion, data correlation, KQL-based detection, threat hunting, and incident management
  • Microsoft Defender XDR – Cross-domain threat detection, incident correlation, investigation, and response
  • Microsoft Defender for Endpoint (EDR) – Endpoint detection, investigation, threat hunting, and response
  • Microsoft Defender for Office 365 – Email threat protection, phishing analysis, and threat investigation
  • Microsoft Entra ID – Identity monitoring, authentication analysis, risky sign-in investigation, and Conditional Access
  • Microsoft Intune – Endpoint management and device compliance concepts

🧰 Tools

About

A Microsoft security operations portfolio demonstrating threat detection, threat hunting, incident investigation, and response across identity, endpoint, email, and cloud security using Microsoft Sentinel, Defender XDR, Defender for Endpoint, Defender for Office 365, and Entra ID.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors