Mapping Cyberattack Patterns and Detection: An Azure Sentinel Approach
摘要
Global cyberattacks, orchestrated by diverse actors, continually exploit system vulnerabilities, with Remote Desktop Protocol (RDP) as a preferred entry point. This research introduces an innovative, proactive approach using Microsoft Azure Sentinel, a cloud-based SIEM solution. It employs a Vulnerable Windows Virtual Machine (Honeypot) for attack monitoring, leverages Network Security Groups (NSGs) for traffic management, and centralizes event logs in Log Analytics Workspaces (LAW). PowerShell enriches logs with geographical context through IPGeolocation.io. Microsoft Sentinel, configured with custom rules, detects global cyber threats. Results highlight the approach’s effectiveness in understanding and responding to global cyberattacks, including brute force attack analysis, distribution across countries, and username targeting. This research emphasizes the importance of proactive strategies in addressing evolving challenges in cybersecurity.