Computer Science Student — Detection Engineering & SOC Automation
Final-year CS student building practical detection engineering skills across Microsoft Sentinel, Entra ID, and Azure Logic Apps. SC-900 certified; currently working toward SC-200 (targeting Q4 2026). Interested in blue team operations — specifically the gap between "an alert fired" and "a real response happened."
A Sentinel + Entra ID + Logic Apps lab that tests containment at four independent layers of an identity-to-endpoint attack chain — rather than one response bolted on at the end. Includes a Conditional Access control that was deliberately tested to failure and documented as a genuine architectural limitation, not forced to "work."
| # | Scenario | Attack Stops At | Status |
|---|---|---|---|
| 1 | Identity Layer | Password spray → successful login | Built & validated |
| A | Cloud App Access | Sign-in from untrusted location | Built & validated |
| B | VM Logon (risk-based CA) | RDP risk-based Conditional Access | Built — documented limitation |
| C | VM Logon (SOAR) | RDP logon by sprayed account | Built & validated |
| 3 | Execution Layer | Encoded PowerShell execution | Built & validated |
Stack: Microsoft Sentinel · Entra ID (Conditional Access + Identity Protection) · Azure Logic Apps (SOAR) · Sysmon · KQL
→ Full write-up, detection queries, and playbooks
Detection & SIEM: Microsoft Sentinel, KQL, Sysmon, Log Analytics, Data Collection Rules Identity & Access: Entra ID, Conditional Access, Identity Protection Automation: Azure Logic Apps (SOAR), Microsoft Graph API Data & Scripting: Python, SQL, Power BI
- Microsoft SC-900 — Security, Compliance, and Identity Fundamentals
- Microsoft SC-200 — Security Operations Analyst (in progress, targeting Q4 2026)
