Azure Sentinel Quick-Deploy with Cyb3rWard0g’s Sentinel To-Go – Let’s Catch Cobalt Strike!
ID: d11dfcce-462b-526d-b0f2-b8e197310257
STIX ID: report--d11dfcce-462b-526d-b0f2-b8e197310257
Feed Name: Black Hills Infosec Blog
This blog post demonstrates deploying Azure Sentinel To-Go in Azure and generating Cobalt Strike beacon activity in a controlled lab to practice detection and hunting. It covers configuring resources and log collection (Sysmon, Security, PowerShell, WMI) and using built-in hunting queries—such as Least Common Parent/Child Process Pairs, PowerShell Downloads, and Encoded Commands—to surface lateral movement artifacts (ipconfig reconnaissance, psexec/services for beacon launch, rundll32 execution), along with brief notes on cost and learning value.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
