A hands-on Azure security portfolio focused on cloud security fundamentals, identity protection, threat detection, monitoring, and incident response.
This repository documents practical security projects designed to demonstrate the skills expected of a SOC Analyst or Azure Cloud Security Analyst, including securing Azure resources, analysing security events, investigating threats, and improving cloud security posture.
This portfolio focuses on:
- Building practical Azure security experience
- Understanding core Azure security concepts and services
- Implementing identity and access security controls
- Deploying security monitoring and detection capabilities
- Investigating security incidents using Microsoft security tools
- Documenting security decisions, findings, and lessons learned
The projects follow the lifecycle of securing and monitoring an Azure environment:
Azure Foundation → Identity Security → Network Security → Security Monitoring & Threat Detection → Attack Simulation → Incident Response
Establishing the core Azure environment required for security monitoring and investigation.
Focus areas:
- Azure resource configuration
- Log Analytics
- Microsoft Sentinel deployment
- Security telemetry collection
- KQL validation
Securing Azure identities and access controls using Microsoft Entra ID.
Focus areas:
- Authentication security
- Role-based access control (RBAC)
- Conditional Access
- Least privilege principles
Implementing Azure networking security controls.
Focus areas:
- Network segmentation
- Network Security Groups
- Azure Firewall
- Secure connectivity
Building security visibility and detection capabilities.
Focus areas:
- Microsoft Sentinel
- Microsoft Defender
- Security alerts
- Log analysis
- Detection engineering
Performing controlled attack scenarios to understand attacker behaviour and validate security controls.
Focus areas:
- Credential access
- Execution techniques
- Privilege escalation
- Defence evasion
- Lateral movement
Investigating security incidents using a SOC workflow.
Focus areas:
- Alert triage
- Investigation
- IOC analysis
- Incident documentation
- Response recommendations
- Microsoft Azure
- Microsoft Entra ID
- Microsoft Sentinel
- Microsoft Defender for Cloud
- Microsoft Defender for Office 365
- Azure Monitor
- Log Analytics Workspace
- KQL
- PowerShell
The goal of this portfolio is to demonstrate practical Azure security knowledge through hands-on implementation, investigation, and documentation.
Each project focuses on understanding not only how security controls are configured, but also why they are implemented and how they support real-world cloud security operations.