The Azure Sandbox – Purple Edition
ID: c448dbc5-b9cb-5d47-8054-304b6384abad
STIX ID: report--c448dbc5-b9cb-5d47-8054-304b6384abad
Feed Name: Black Hills Infosec Blog
This blog post outlines setting up an Azure-based purple-team lab using ARM templates (DC, workstation, Linux), connecting VMs to Log Analytics and Microsoft Sentinel, and generating telemetry with BadBlood, PowerUp, and HostRecon to validate detections. It demonstrates building KQL queries for PowerShell-related events, saving searches, and creating alerts, showcasing a streamlined threat-hunting lifecycle from simulation through detection and reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
