Skip to content
View AdeleyeJoshua's full-sized avatar

Highlights

  • Pro

Block or report AdeleyeJoshua

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AdeleyeJoshua/README.md

Joshua Adeleye

Computer Science Student — Detection Engineering & SOC Automation

LinkedIn SC-900

Final-year CS student building practical detection engineering skills across Microsoft Sentinel, Entra ID, and Azure Logic Apps. SC-900 certified; currently working toward SC-200 (targeting Q4 2026). Interested in blue team operations — specifically the gap between "an alert fired" and "a real response happened."


Featured Project

A Sentinel + Entra ID + Logic Apps lab that tests containment at four independent layers of an identity-to-endpoint attack chain — rather than one response bolted on at the end. Includes a Conditional Access control that was deliberately tested to failure and documented as a genuine architectural limitation, not forced to "work."

# Scenario Attack Stops At Status
1 Identity Layer Password spray → successful login Built & validated
A Cloud App Access Sign-in from untrusted location Built & validated
B VM Logon (risk-based CA) RDP risk-based Conditional Access Built — documented limitation
C VM Logon (SOAR) RDP logon by sprayed account Built & validated
3 Execution Layer Encoded PowerShell execution Built & validated

Stack: Microsoft Sentinel · Entra ID (Conditional Access + Identity Protection) · Azure Logic Apps (SOAR) · Sysmon · KQL

Full write-up, detection queries, and playbooks


Skills

Detection & SIEM: Microsoft Sentinel, KQL, Sysmon, Log Analytics, Data Collection Rules Identity & Access: Entra ID, Conditional Access, Identity Protection Automation: Azure Logic Apps (SOAR), Microsoft Graph API Data & Scripting: Python, SQL, Power BI

Certifications

  • Microsoft SC-900 — Security, Compliance, and Identity Fundamentals
  • Microsoft SC-200 — Security Operations Analyst (in progress, targeting Q4 2026)

📫 LinkedIn

Pinned Loading

  1. sc200-defense-in-depth-lab sc200-defense-in-depth-lab Public

    SOC detection engineering lab: Sentinel, Conditional Access, and SOAR containment across an identity-to-endpoint kill chain