© 2026 Hashnode
Repo: github.com/Kajal-Dhanjal/sentinel-detection-lab Part 6 caught AI tooling launching. The natural next question was what happens once it's running—specifically, where does it talk to? This is the

Repo: github.com/Kajal-Dhanjal/sentinel-detection-lab Five detections in, every one of them pointed at a fairly traditional attacker: brute force, malicious PowerShell, registry persistence, recon, an

https://github.com/Kajal-Dhanjal/sentinel-detection-lab Part 4 ended on this note: moving off the endpoint entirely and into identity, starting with attackers registering their own MFA methods on com

https://github.com/Kajal-Dhanjal/sentinel-detection-lab This is Part 4 of the series where I build a Microsoft Sentinel detection engineering lab from scratch and write down what actually happened —

Part 3 of a series on building a detection engineering lab in Microsoft Sentinel. This post: registry persistence, a textbook false positive, and the single most important lesson in detection engineer

Part 1 of a series on building a detection engineering lab in Microsoft Sentinel from scratch. This post: writing my first detection, and the parsing bug that taught me more than the detection itself.

Part 2 of a series on building a detection engineering lab in Microsoft Sentinel. This post: hunting malicious PowerShell with Sysmon, and the difference between volume detections and signature detect
