Saravanagithub10/Azure-CloudGuard

GitHub: Saravanagithub10/Azure-CloudGuard

基于 Microsoft Sentinel 构建 Azure 云安全监控与事件响应项目,演示从 Syslog 日志采集到威胁检测和自动化通知的完整 SIEM 流程。

Stars: 0 | Forks: 0

# Azure CloudGuard Azure CloudGuard 是一个 Azure 安全监控与 Incident Response 项目,旨在展示使用 Microsoft Azure 服务进行真实世界云安全操作的流程。该项目模拟了如何使用 Microsoft Sentinel 收集、分析、检测安全事件并实现自动化响应。 # 项目目标 - 配置 Azure Monitor Agent (AMA) - 使用 Data Collection Rules (DCR) 收集 Linux Syslog 日志 - 将日志存储在 Azure Log Analytics Workspace 中 - 在 Microsoft Sentinel 中创建自定义 Analytics Rules - 自动生成 Security Incidents - 使用 Logic Apps 触发自动化响应 - 针对检测到的 Incident 发送邮件通知 - 使用 Kusto Query Language (KQL) 进行调查 # 架构 ![CloudGuard 架构](https://static.pigsec.cn/wp-content/uploads/repos/cas/3d/3d7fc98cac6c6be56222e3c0f961cf140892a4ff3d68abcbc8e511ea47346689.png) # 使用的 Azure 服务 | 服务 | 用途 | |----------|----------| | Azure Virtual Machine | 生成 Linux Syslog 日志 | | Azure Monitor Agent | 收集遥测数据 | | Data Collection Rule | 定义日志收集规则 | | Log Analytics Workspace | 存储收集的日志 | | Microsoft Sentinel | SIEM 与 Incident 管理 | | Analytics Rules | 检测可疑活动 | | Automation Rules | 触发响应工作流 | | Logic Apps | 自动化邮件通知 | | Outlook Connector | 发送 Incident 邮件 | # 项目工作流 ``` Linux VM │ ▼ Azure Monitor Agent │ ▼ Data Collection Rule │ ▼ Log Analytics Workspace │ ▼ Microsoft Sentinel │ ▼ Analytics Rule │ ▼ Security Incident │ ▼ Automation Rule │ ▼ Logic App │ ▼ Email Notification ``` # 截图 ## Resource Group ![Resource Group](https://static.pigsec.cn/wp-content/uploads/repos/cas/91/917eff05ad7ae141a7133b3b676114db6aeea29a946de3ca54341ca59406e821.png) ## Azure Virtual Machine ![Virtual Machine](https://static.pigsec.cn/wp-content/uploads/repos/cas/41/41dfbdabd8bf07ca40bc1cad3fafbac5a70f654b381bf8c743ad32c924e4c54b.png) ## Data Collection Rule ![DCR](https://static.pigsec.cn/wp-content/uploads/repos/cas/8c/8cbd983291153a0a10b269bffceb67325da9917f67ad700b7ec203cff49721fe.png) ## Log Analytics Workspace ![LAW](https://static.pigsec.cn/wp-content/uploads/repos/cas/60/60eacc5ae8bab131bf6c9abe4dc7665343d4555305f5ea498e659dd05056fdf3.png) ## KQL Query 验证 ![KQL](https://static.pigsec.cn/wp-content/uploads/repos/cas/82/823279fadcd82ea15fc9b97cc735f26667099ef59f00839fabadacab8c6e3dd1.png) ## Sentinel Analytics Rule ![Analytics Rule](https://static.pigsec.cn/wp-content/uploads/repos/cas/2c/2ca2b0bf46159c51d5bbec7938f8db79a4bdee77432e14afd995f76f7f718161.png) ## Security Incident ![Incident](https://static.pigsec.cn/wp-content/uploads/repos/cas/c5/c5fd4607cdbe329e42362aaef7aa4b3c09d378cc5558fd18fbee293c1a7cc897.png) ## Automation Rule ![Automation Rule](https://static.pigsec.cn/wp-content/uploads/repos/cas/23/23007cf2e27657036d79d677cf640c1462c7daccff0ca6bab7d466c06365edc6.png) ## Logic App ![Logic App](https://static.pigsec.cn/wp-content/uploads/repos/cas/89/898740d87fbc97de494dd8e4d06c8d3f43952725929e8b4f5879a123fb2422ca.png) ## Logic App 运行历史 ![Run History](https://static.pigsec.cn/wp-content/uploads/repos/cas/78/78e45a403a453d9d4f694e16217a8b81fac6604801ff8b5d43a79deae578fa74.png) ## 邮件通知 ![Email Notification](https://static.pigsec.cn/wp-content/uploads/repos/cas/0d/0d74af516788486702a32974e21a538a9b8e59db62e3e28d03da987ed0ed3517.png) # KQL 验证 Query ``` Syslog | where TimeGenerated > ago(24h) | project TimeGenerated, Computer, Facility, ProcessName, SyslogMessage | order by TimeGenerated desc ``` # 展示的技能 - Microsoft Azure - Microsoft Sentinel - Azure Monitor - Azure Monitor Agent - Data Collection Rules - Log Analytics Workspace - Kusto Query Language (KQL) - Logic Apps - Security Incident 管理 - 云安全监控 - Security Operations (SOC) # 未来改进 - Teams 通知 - Azure Functions 集成 - Defender for Cloud 集成 - Playbook 增强 - 多种 Detection Rules - Threat Intelligence 集成 # 作者 **Saravanan K** 云与 Azure 安全爱好者 LinkedIn: https://linkedin.com/in/saravanankannan10 GitHub: https://github.com/Saravanagithub10
标签:Azure, KQL, Microsoft Sentinel, 安全运营, 扫描框架, 自动化响应