Microsoft Sentinel Security Monitoring & Controls Analytics
PowerShell event collection and authentication analytics, with a synthetic data walkthrough.
- Context
- Academic Windows-event monitoring project
- My role
- PowerShell collection/enrichment and Sentinel dashboard development
- Status
- Academic workflow built; synthetic public demonstration below
- Deliverable
- Authentication monitoring, trend analysis and repeatable evidence
Decision & evidence
Investigate the sequence, not just the count
Authentication failures become more useful when grouped by source and examined alongside successful logons. The demonstration below turns that distinction into a specific investigation question.
A burst of failures followed by a success is a reason to investigate. Account-owner confirmation and surrounding activity are still needed before concluding that access was malicious.
Synthetic lab demonstration · 24 fictional events
Authentication signals with investigation context
This portfolio visualization uses a small synthetic dataset, not an employer log or a screenshot of the original Sentinel dashboard. It covers 09:00–09:25 UTC on 1 October 2026; all identities and addresses are fictional.
- Remote logons
- 24
- Failed
- 18
- Successful
- 6
Finding & next action
198.51.100.20 has 12 failed remote logons followed by one successful logon for LAB-ANALYST. That sequence deserves investigation; the events alone cannot distinguish an attack from a legitimate user recovering access.
Next step: confirm the activity with the account owner, correlate endpoint and session evidence, and review access controls before recommending containment.
Inspect the PowerShell example
$events = Get-Content ./sentinel-events.json -Raw | ConvertFrom-Json
$rdp = $events | Where-Object { $_.LogonType -eq 10 }
$rdp | Where-Object EventID -eq 4625 |
Group-Object IpAddress | Select-Object Name, CountCounts are calculated from the downloadable 24-event fixture. Event 4625 denotes a failure, 4624 a success; LogonType 10 selects remote-interactive logons. This sample is illustrative, not a detection benchmark.
Overview
Developed a PowerShell workflow to collect and enrich Windows Event Viewer data, and built a Microsoft Sentinel dashboard to analyze RDP brute-force activity.
Objective
Make authentication telemetry useful for security analysis, continuous control assessment and repeatable evidence collection.
My contribution
- Developed a PowerShell workflow for collecting and enriching Windows Event Viewer data.
- Built a Microsoft Sentinel dashboard to analyze RDP brute-force activity and validate security events.
- Transformed telemetry into trends, control insights and risk-reporting outputs.
Technical approach
- Used repeatable PowerShell collection and enrichment to prepare Windows event data for analysis.
- Connected authentication monitoring with dashboard views that support event validation, trend analysis and evidence collection.
Scope & considerations
Authentication events need context before they become security conclusions. The work connects event validation with repeatable evidence collection and control assessment in an academic setting.
Outcome
Demonstrates SIEM investigation, PowerShell automation, authentication telemetry, controls analytics and security-data visualization.