Building Cloud Siem With Sentinel

Use when this skill covers deploying Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations. It details configuring data connectors for multi-cloud log ingestion, writing KQL detection queries, building automated response playbooks with Logic Apps, and leveraging the Sentinel data lake for petabyte-scale threat hunting across AWS, Azure, and GCP security telemetry.

oyi77 1466b2d 4.1 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/building-cloud-siem-with-sentinel commit 1466b2dd90

Frequently asked questions

npx skillmds add oyi77/building-cloud-siem-with-sentinel