Focus area
Sentinel/KQL
SOC-ready detections, hunting queries, and workbooks.
Move past ‘enable logs’—collect the right signals, normalise data, and arm responders with KQL building blocks tied to runbook steps.
Featured runbook
SailPoint ISC to Sentinel: watching the system that grants access
An Azure-native, self-hosted pipeline that ships SailPoint Identity Security Cloud audit events into Microsoft Sentinel — why the governance layer is where detection belongs, and the design decisions that keep the pipeline itself Tier 0.
Read now
Need context?
Jump into the guided path, or browse everything if you’re after something specific.
Explore other focus areas
Hop between landing zones, identity, networking, and more.