frankkofiawen/Microsoft-Sentinel-SOC-Lab

GitHub: frankkofiawen/Microsoft-Sentinel-SOC-Lab

一个基于 Microsoft Sentinel 的安全运营中心实验室,演示云原生 SIEM 的部署、日志摄取、KQL 检测规则编写和事件调查的完整流程。

Stars: 0 | Forks: 0

# 🛡️ Microsoft Sentinel SOC 实验室 ![状态](https://img.shields.io/badge/Status-In%20Progress-yellow?style=for-the-badge) ![平台](https://img.shields.io/badge/Platform-Microsoft%20Sentinel-blue?style=for-the-badge) ![语言](https://img.shields.io/badge/KQL-Kusto-blueviolet?style=for-the-badge) ![许可证](https://img.shields.io/badge/License-MIT-green?style=for-the-badge) ## 📖 概述 本项目演示了 Microsoft Sentinel 安全运营中心 (SOC) 实验室的设计与实现。 该实验室展示了如何: - 部署 Microsoft Sentinel - 配置 Log Analytics Workspace - 收集 Windows 安全事件 - 编写 Kusto Query Language (KQL) 查询 - 创建 Analytics Rules - 调查安全事件 - 执行 Threat Hunting - 将检测结果映射到 MITRE ATT&CK 框架 目标是模拟一级 / 二级 SOC 分析师使用 Microsoft Sentinel 的日常工作职责。 ## 🏗️ 实验室架构 *架构图即将发布。* ## 🎯 学习目标 - 部署云原生 SIEM - 摄取 Windows 事件日志 - 调查安全告警 - 构建检测规则 - 执行 Threat Hunting - 开发 KQL 查询 - 记录调查过程 - 应用 MITRE ATT&CK 映射 ## 🛠️ 技术 - Microsoft Sentinel - Azure Log Analytics Workspace - Azure Monitor Agent - Microsoft Defender - Windows 11 - Kusto Query Language (KQL) - MITRE ATT&CK ## 📂 仓库结构 | 文件夹 | 用途 | |---------|---------| | KQL | Threat Hunting 查询 | | Analytics-Rules | 检测规则 | | Workbooks | 仪表板 | | MITRE-Mapping | ATT&CK 映射 | | Playbooks | 自动化 | | docs | 文档 | | images | 截图 | ## 🚧 当前状态 本项目正在积极开发中。 即将添加的内容包括: - Microsoft Sentinel 部署 - Windows VM 接入 - KQL Threat Hunting - Analytics Rules - 事件调查 - Workbooks - MITRE ATT&CK 映射 - 自动化 Playbooks ## 👤 作者 **Frank Kofi Awen** 初级 SOC 分析师 | 网络安全分析师
标签:AMSI绕过, KQL, Microsoft Sentinel, 威胁检测, 安全实验室, 安全运营中心, 网络映射