Windows Authentication Detection Lab
Sigma-style Windows authentication detections over synthetic Security Event scenarios.
Primary walkthrough: AUTH-003-POS
A public entry point for Windows authentication, Microsoft Entra ID and Microsoft Sentinel KQL detection labs.
Sigma-style Windows authentication detections over synthetic Security Event scenarios.
Primary walkthrough: AUTH-003-POS
Defensive Microsoft Entra sign-in and audit detections using only synthetic events.
Primary walkthrough: ENTRA-003-POS
Sentinel-style KQL analytics correlating synthetic SigninLogs, AuditLogs and SecurityEvent rows.
Primary walkthrough: SENT-006-POS
Review repeated Windows logon failures followed by a success.
Review repeated MFA denials followed by a successful sign-in.
Correlate Entra and Windows signals into one synthetic incident.
Start the dynamic replay experience with
uv run identitylab live, then open the local
Identity Detection Live Lab.
Recommended scenario: SENT-006-POS, the cross-source identity incident that correlates Entra and Windows signals.
Use this hub as the future VM landing page. Clone the three labs as
sibling directories, run each validation command, and keep evidence
under each lab's reports/latest directory.