Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 

Repository files navigation

Azure Sentinel Logo

Azure Sentinel (SIEM) Tutorial with Map of Live Cyber Attacks

This tutorial outlines the implementation of a SIEM within Azure Virtual Machines.

Environments and Technologies Used

  • Microsoft Azure Sentinel (Virtual Machines/Compute)
  • Remote Desktop

Operating Systems Used

  • Windows 10 (21H2)

High-Level Deployment and Configuration Steps

  • Setup Resources in Azure
  • Create Log Analytics Workspace
  • Enable gathering VM logs in Security Center
  • Setup Azure Sentinel
  • Create custom fields/extract fields from raw custom log data
  • Setup map in sentinel with Latitude and Longitude (or country)

Deployment and Configuration Steps

Disk Sanitization Steps

Create a Resource Group and VM


Disk Sanitization Steps

Create a new NIC by clicking advanced


Disk Sanitization Steps

Remove the default NIC


Disk Sanitization Steps

Add Inbound Rules


Disk Sanitization Steps

Create the VM


Disk Sanitization Steps

Create a Logs Analytics Workspace


Disk Sanitization Steps

Name the Analytics Workspace


Disk Sanitization Steps

Turn on Microsoft Defender


Disk Sanitization Steps

Turn SQL Servers Off for the honeypot and click save


Disk Sanitization Steps

Refresh the page and install Data Collections


Disk Sanitization Steps

Go to environment settings and open Azure Subscription and click on the honeypot


Disk Sanitization Steps

Click on Data Collection and select All Events and save


Disk Sanitization Steps

Go back to log analytics workspace to connect it to the VM


Disk Sanitization Steps

Open the log analytics workspace and click on virtual machines on the left


Disk Sanitization Steps

Click on the VM created in the beginning


Disk Sanitization Steps

Click connect


Disk Sanitization Steps

Setup Sentinel


Disk Sanitization Steps

Choose the honeypot


Disk Sanitization Steps

Go back to main page on Azure and click on the VM


Disk Sanitization Steps

Copy the public IP Address


Disk Sanitization Steps

Open remote desktop and log into the machine with credentials that were created int he beginning. Purposefully put in the wrong password on the first try.


Disk Sanitization Steps

Initial password input was wrong. This will be logged for us to see.


Disk Sanitization Steps

Once logged in, go to Event Viewer


Disk Sanitization Steps

Go to Windows Logs and Security on the left


Disk Sanitization Steps

vHere we can see our login failure


Disk Sanitization Steps

You can double click to see the details of that log


Disk Sanitization Steps

Now try to login again but this time put in the wrong username and password.


Disk Sanitization Steps

Login attempt with wrong username


Disk Sanitization Steps

Now an IP address shows from the attempted login.


Disk Sanitization Steps

Open the firewall on the VM. wf.msc in the search bar


Disk Sanitization Steps

Click on Windows Defender Firewall properties


Disk Sanitization Steps

Ping the VM's IP Address and notice that echo requests are allowed and we are getting return messages


Disk Sanitization Steps

Turn off the Domain, Public and Private firewalls and click apply


Disk Sanitization Steps

Launch Powershell ISE and copy and paste the Log Exporter script


Disk Sanitization Steps

Make an account on ipgeolocation.io and copy and paste your API key into the script


Disk Sanitization Steps

The script is a loop that runs perpetually and looks through the event viewer and security log and grabs the IP addresses of failed logins and geo locates them and creates a new log file


Disk Sanitization Steps

The file will be created in the ProgramData file that you will have to access manually.


Disk Sanitization Steps

Run the script to see the failed logon file being created from the failed attempts earlier


Disk Sanitization Steps

Go to log analytics workspaces


Disk Sanitization Steps

Go to custom logs and add a custom log


Disk Sanitization Steps

Copy and paste the logs within the VM file


Disk Sanitization Steps

Create a text file on your computer and paste the logs and save it on your desktop to upload to the custom logs on Azure


Disk Sanitization Steps

Upload the custom log


Disk Sanitization Steps

Hit next and it should look like this


Disk Sanitization Steps

Direct the custom log on Azure to be fetched from the file on the VM


Disk Sanitization Steps

Name the custom log


Disk Sanitization Steps

Head over to Log analytics workspaces and to the honeypot logs on the bottom left. Run a search query on the log file to show the failed attempts.


Disk Sanitization Steps

Right click and click extract fields from.


Disk Sanitization Steps

Highlight the fields to extract them


Disk Sanitization Steps

Check to see if the extraction is properly trained and save


Disk Sanitization Steps

Repeat steps for logitude and modify incorrect data to train the algorithm


Disk Sanitization Steps

Repeat steps for destination host


Disk Sanitization Steps

Repeat steps for username


Disk Sanitization Steps

Repeat steps for sourcehost


Disk Sanitization Steps

Repeat steps for State


Disk Sanitization Steps

Repeat steps for Country


Disk Sanitization Steps

Repeat steps for label


Disk Sanitization Steps

Finally finish up with timestamp


Disk Sanitization Steps

Run the query again and notice the created custom fields. On subsequent logs, they will be properly parsed out


Disk Sanitization Steps

Click on custom logs and custom fields to see the fields


Disk Sanitization Steps

Go back to Azure Sentinel


Disk Sanitization Steps

Add a new Workbook on the left


Disk Sanitization Steps

Add a new workbook and edit


Disk Sanitization Steps

Remove the default widgets


Disk Sanitization Steps

Edit and run query with a map visualization. Choose country as location info


Disk Sanitization Steps

Set map settings and labels


Disk Sanitization Steps

Set additional map setting and labels. Now observe as you track the hackers from around the world!


Disk Sanitization Steps

Roughly 30 minutes after lab has been completed


Disk Sanitization Steps

Roughly 7 hours after lab was complete


Disk Sanitization Steps

Approximately 12 hours after lab completion


About

End-to-end Microsoft Sentinel SIEM setup in Azure with Log Analytics workspace and detection rules."

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors