Home
Microsoft Sentinel
Microsoft Sentinel Hub
A structured walk through Microsoft Sentinel — one topic per capability, each with an explanation, architecture, practical examples, KQL, and investigation scenarios.
In development
This section is being built out. Here’s what it will hold:
- Introduction, architecture, and the Log Analytics workspace
- Data connectors, tables and logs, and KQL
- Analytics rules, incidents, and the investigation graph
- Threat hunting, workbooks, and entity behaviour
- Automation rules, Logic Apps, and SOAR
- Detection engineering end to end
Sourced from 25 how-to guides — one per Sentinel blade — already written against a live workspace.