Skip to content
Home

Microsoft Sentinel

Microsoft Sentinel Hub

A structured walk through Microsoft Sentinel — one topic per capability, each with an explanation, architecture, practical examples, KQL, and investigation scenarios.

In development

This section is being built out. Here’s what it will hold:

  • Introduction, architecture, and the Log Analytics workspace
  • Data connectors, tables and logs, and KQL
  • Analytics rules, incidents, and the investigation graph
  • Threat hunting, workbooks, and entity behaviour
  • Automation rules, Logic Apps, and SOAR
  • Detection engineering end to end

Sourced from 25 how-to guides — one per Sentinel blade — already written against a live workspace.