Series · 8 parts

Building a Sentinel detection lab

How I built a Sentinel lab from scratch, licensing walls and all.

View the lab on GitHub

  1. Part 1 ·

    Catching Brute Force (and the Bug That Flagged the Wrong Account)

    Writing my first detection, and the parsing bug that taught me more than the detection itself.

  2. Part 2 ·

    Suspicious PowerShell, and Why Some Detections Need No Threshold

    Hunting malicious PowerShell with Sysmon, and the difference between volume detections and signature detections.

  3. Part 3 ·

    My Detection Flagged Legitimate Windows Behavior. Here's How I Tuned It Without Going Blind

    Registry persistence, a textbook false positive, and the single most important lesson in detection engineering.

  4. Part 4 ·

    Catching Reconnaissance, and the Case-Sensitivity Bug That Made It Look Broken

    The first detection in the lab that looks for a pattern of behavior, and the case-sensitivity bug that made it look broken.

  5. Part 5 ·

    MFA Registration, a Missing License, and the First Detection That Talks Back

    Attackers registering their own MFA methods to keep access after a password reset, and the first detection that talks back.

  6. Part 6 ·

    Shadow AI and the Detection That's Honest About What It Hasn't Proven Yet

    AI tooling showing up on endpoints with nobody in IT knowing it's there.

  7. Part 7 ·

    The Detection That Taught Me My Own Telemetry's Blind Spot

    Where AI tooling talks to once it's running, and the most useful failure in the lab so far.

  8. Part 8 ·

    Watching for Agents, Not Just Attackers

    The same process-lineage technique, pointed at a different actor: not a human attacker, an AI agent.