天穹哨兵

原名:building-cloud-siem-with-sentinel

通过配置多云数据连接器、编写KQL查询及构建自动化响应剧本,部署Microsoft Sentinel作为云原生SIEM/SOAR。适用于多云SOC建设、遗留SIEM迁移或PB级威胁狩猎,不适用于仅需AWS安全服务或端点EDR的场景。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-21
TRACE 评分
3.4 / 5

内容概览

- When establishing a centralized security operations center for multi-cloud environments - When migrating from legacy SIEM platforms (Splunk, QRadar) to cloud-native architecture - When building automated incident response workflows for cloud-specific threats - When performing large-scale threat hunting across petabytes of security telemetry - When integrating threat intelligence feeds with cloud security log analysis Do not use for AWS-only environments where Security Hub and GuardDuty suffice, for endpoint detection requiring EDR capabilities (use Defender for Endpoint), or for compliance posture monitoring (see building-cloud-security-posture-management). - Azure subscription with Microsoft Sentinel enabled on a Log Analytics workspace - Data connector permissions for target log sources (AWS CloudTrail, Azure Activity, GCP) - Logic Apps or Azure Functions for automated response playb…

查看 SKILL 详情