A honeypot environment built on Azure + Microsoft Sentinel to simulate real-world attack scenarios for threat detection & SOC learning.
π Get started by following this detailed guide:
π clouddecoy.pdf
- Simulates attacker behavior using an intentionally exposed VM.
- Collects security events via Microsoft Sentinel.
- Visualizes attacker geolocation with a live threat map.
- Great for hands-on blue team training!
- βοΈ Microsoft Azure
- π§ Microsoft Sentinel
- π Log Analytics Workspace
- πͺ€ Honeypot via Open RDP VM
- π Custom Watchlist + Attack Map
β Donβt forget to star the repo if this helped you!