Defensive Identity Lab Hub

A public entry point for Windows authentication, Microsoft Entra ID and Microsoft Sentinel KQL detection labs.

Open hub documentation

Synthetic lab only. No production logs, credentials, tenants, tokens, malware, offensive simulations or host-changing actions.
3connected labs
17defensive detections
SENT-006-POSend-to-end incident

Labs

Endpoint authentication

Windows Authentication Detection Lab

Sigma-style Windows authentication detections over synthetic Security Event scenarios.

Primary walkthrough: AUTH-003-POS

AUTH-001 AUTH-002 AUTH-003 AUTH-004 AUTH-005
Cloud identity

Microsoft Entra Detection Lab

Defensive Microsoft Entra sign-in and audit detections using only synthetic events.

Primary walkthrough: ENTRA-003-POS

ENTRA-001 ENTRA-002 ENTRA-003 ENTRA-004 ENTRA-005 ENTRA-006
SIEM correlation

Microsoft Sentinel KQL Detection Lab

Sentinel-style KQL analytics correlating synthetic SigninLogs, AuditLogs and SecurityEvent rows.

Primary walkthrough: SENT-006-POS

SENT-001 SENT-002 SENT-003 SENT-004 SENT-005 SENT-006

Recommended walkthrough

  1. 1
    AUTH-003-POS - Windows authentication sequence

    Review repeated Windows logon failures followed by a success.

  2. 2
    ENTRA-003-POS - Cloud identity authentication sequence

    Review repeated MFA denials followed by a successful sign-in.

  3. 3
    SENT-006-POS - Cross-source Sentinel incident

    Correlate Entra and Windows signals into one synthetic incident.

Live Lab

Start the dynamic replay experience with uv run identitylab live, then open the local Identity Detection Live Lab.

Recommended scenario: SENT-006-POS, the cross-source identity incident that correlates Entra and Windows signals.

Local VM preparation

Use this hub as the future VM landing page. Clone the three labs as sibling directories, run each validation command, and keep evidence under each lab's reports/latest directory.

Read the public VM guide