logo

The Azure Sandbox – Purple Edition 

ID: c448dbc5-b9cb-5d47-8054-304b6384abad

STIX ID: report--c448dbc5-b9cb-5d47-8054-304b6384abad

Feed Name: Black Hills Infosec Blog

Date Published: 2022-02-08

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post outlines setting up an Azure-based purple-team lab using ARM templates (DC, workstation, Linux), connecting VMs to Log Analytics and Microsoft Sentinel, and generating telemetry with BadBlood, PowerUp, and HostRecon to validate detections. It demonstrates building KQL queries for PowerShell-related events, saving searches, and creating alerts, showcasing a streamlined threat-hunting lifecycle from simulation through detection and reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.