All projects
Case study 08 / 08Academic

Microsoft Sentinel Security Monitoring & Controls Analytics

PowerShell event collection and authentication analytics, with a synthetic data walkthrough.

Security monitoring & analytics
Context
Academic Windows-event monitoring project
My role
PowerShell collection/enrichment and Sentinel dashboard development
Status
Academic workflow built; synthetic public demonstration below
Deliverable
Authentication monitoring, trend analysis and repeatable evidence

Decision & evidence

Investigate the sequence, not just the count

Authentication failures become more useful when grouped by source and examined alongside successful logons. The demonstration below turns that distinction into a specific investigation question.

A burst of failures followed by a success is a reason to investigate. Account-owner confirmation and surrounding activity are still needed before concluding that access was malicious.

Synthetic lab demonstration · 24 fictional events

Authentication signals with investigation context

This portfolio visualization uses a small synthetic dataset, not an employer log or a screenshot of the original Sentinel dashboard. It covers 09:00–09:25 UTC on 1 October 2026; all identities and addresses are fictional.

Remote logons
24
Failed
18
Successful
6
Failed remote logons by source Count · synthetic fixture
192.0.2.104
198.51.100.2012
203.0.113.302

Finding & next action

198.51.100.20 has 12 failed remote logons followed by one successful logon for LAB-ANALYST. That sequence deserves investigation; the events alone cannot distinguish an attack from a legitimate user recovering access.

Next step: confirm the activity with the account owner, correlate endpoint and session evidence, and review access controls before recommending containment.

Inspect the PowerShell example
$events = Get-Content ./sentinel-events.json -Raw | ConvertFrom-Json
$rdp = $events | Where-Object { $_.LogonType -eq 10 }
$rdp | Where-Object EventID -eq 4625 |
    Group-Object IpAddress | Select-Object Name, Count

Counts are calculated from the downloadable 24-event fixture. Event 4625 denotes a failure, 4624 a success; LogonType 10 selects remote-interactive logons. This sample is illustrative, not a detection benchmark.

01

Overview

Developed a PowerShell workflow to collect and enrich Windows Event Viewer data, and built a Microsoft Sentinel dashboard to analyze RDP brute-force activity.

02

Objective

Make authentication telemetry useful for security analysis, continuous control assessment and repeatable evidence collection.

03

My contribution

  • Developed a PowerShell workflow for collecting and enriching Windows Event Viewer data.
  • Built a Microsoft Sentinel dashboard to analyze RDP brute-force activity and validate security events.
  • Transformed telemetry into trends, control insights and risk-reporting outputs.
04

Technical approach

  • Used repeatable PowerShell collection and enrichment to prepare Windows event data for analysis.
  • Connected authentication monitoring with dashboard views that support event validation, trend analysis and evidence collection.
05

Scope & considerations

Authentication events need context before they become security conclusions. The work connects event validation with repeatable evidence collection and control assessment in an academic setting.

06

Outcome

Demonstrates SIEM investigation, PowerShell automation, authentication telemetry, controls analytics and security-data visualization.

07

Technologies

  • Microsoft Sentinel
  • PowerShell
  • Windows Event Viewer
  • SIEM
  • RDP
  • Security Analytics
  • Control Monitoring
Next case studyEnterprise Cybersecurity Home LabView all eight projects