Create a SIEM in Azure

Create a SIEM in Azure

Create resource group - RG-Soc-lab

image

Create Virtual Network

image

Create the VM for the Honey Pot

image
image

Open the NSG (Network Security Group) to the internet.

image

Create an inbound rule allowing all traffic.

image

RDP into the machine and disable Windows Defender.

image

Create a log repo - log analytics workspace.

image

Create a sentinel instance and Link LAW (Log Analytics Workspace)

Create heat map

image