Skip to content

Repository files navigation

Azure Security Portfolio

A hands-on Azure security portfolio focused on cloud security fundamentals, identity protection, threat detection, monitoring, and incident response.

This repository documents practical security projects designed to demonstrate the skills expected of a SOC Analyst or Azure Cloud Security Analyst, including securing Azure resources, analysing security events, investigating threats, and improving cloud security posture.


Portfolio Objectives

This portfolio focuses on:

  • Building practical Azure security experience
  • Understanding core Azure security concepts and services
  • Implementing identity and access security controls
  • Deploying security monitoring and detection capabilities
  • Investigating security incidents using Microsoft security tools
  • Documenting security decisions, findings, and lessons learned

Portfolio Structure

The projects follow the lifecycle of securing and monitoring an Azure environment:

Azure Foundation → Identity Security → Network Security → Security Monitoring & Threat Detection → Attack Simulation → Incident Response


Projects

1. Azure Foundation

Establishing the core Azure environment required for security monitoring and investigation.

Focus areas:

  • Azure resource configuration
  • Log Analytics
  • Microsoft Sentinel deployment
  • Security telemetry collection
  • KQL validation

2. Identity Security

Securing Azure identities and access controls using Microsoft Entra ID.

Focus areas:

  • Authentication security
  • Role-based access control (RBAC)
  • Conditional Access
  • Least privilege principles

3. Network Security

Implementing Azure networking security controls.

Focus areas:

  • Network segmentation
  • Network Security Groups
  • Azure Firewall
  • Secure connectivity

4. Security Monitoring & Threat Detection

Building security visibility and detection capabilities.

Focus areas:

  • Microsoft Sentinel
  • Microsoft Defender
  • Security alerts
  • Log analysis
  • Detection engineering

5. Attack Simulation

Performing controlled attack scenarios to understand attacker behaviour and validate security controls.

Focus areas:

  • Credential access
  • Execution techniques
  • Privilege escalation
  • Defence evasion
  • Lateral movement

6. Incident Response

Investigating security incidents using a SOC workflow.

Focus areas:

  • Alert triage
  • Investigation
  • IOC analysis
  • Incident documentation
  • Response recommendations

Technologies Used

  • Microsoft Azure
  • Microsoft Entra ID
  • Microsoft Sentinel
  • Microsoft Defender for Cloud
  • Microsoft Defender for Office 365
  • Azure Monitor
  • Log Analytics Workspace
  • KQL
  • PowerShell

Goal

The goal of this portfolio is to demonstrate practical Azure security knowledge through hands-on implementation, investigation, and documentation.

Each project focuses on understanding not only how security controls are configured, but also why they are implemented and how they support real-world cloud security operations.

About

Hands-on Azure security portfolio demonstrating practical cloud security skills across identity protection, network security, security monitoring, threat detection, and incident response. This repository documents real-world security configurations, investigations, and defensive security practices using Microsoft security technologies.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors