天穹哨兵
原名:building-cloud-siem-with-sentinel
通过配置多云数据连接器、编写KQL查询及构建自动化响应剧本,部署Microsoft Sentinel作为云原生SIEM/SOAR。适用于多云SOC建设、遗留SIEM迁移或PB级威胁狩猎,不适用于仅需AWS安全服务或端点EDR的场景。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-21
- TRACE 评分
- 3.4 / 5
内容概览
- When establishing a centralized security operations center for multi-cloud environments - When migrating from legacy SIEM platforms (Splunk, QRadar) to cloud-native architecture - When building automated incident response workflows for cloud-specific threats - When performing large-scale threat hunting across petabytes of security telemetry - When integrating threat intelligence feeds with cloud security log analysis Do not use for AWS-only environments where Security Hub and GuardDuty suffice, for endpoint detection requiring EDR capabilities (use Defender for Endpoint), or for compliance posture monitoring (see building-cloud-security-posture-management). - Azure subscription with Microsoft Sentinel enabled on a Log Analytics workspace - Data connector permissions for target log sources (AWS CloudTrail, Azure Activity, GCP) - Logic Apps or Azure Functions for automated response playb…