Sentinel Geo-Visualizations
STATUS: ACTIVE / MAINTAINED
ANALYST: Erick Cisneros Ruballos
DATETIME: Rolling Deployment
A collection of advanced Microsoft Sentinel workbooks designed for threat hunting and security monitoring. By correlating log data with geographic information, these dashboards provide powerful visual intelligence for SOC operations.
Executive Summary
Transforming raw log infrastructure data into actionable geographic intelligence is critical to tracing distributed threat patterns across the globe. These tailored Azure Sentinel workbooks enable analysts to actively profile an environment, moving past standard alerts and into visual threat hunting based on regional anomalies.
By unifying telemetry from disparate sources — like Entra ID Sign-ins, Azure Activity Logs, and Network Security Group flows — cross-correlated against Threat Intelligence watchlists, the SOC gains an immediate view into anomalous behaviors that standard logic rules may miss.
Workbook Implementations
Malicious Network Flow
Maps the geographic origins of network traffic flagged as 'MaliciousFlow' in Azure Network Analytics logs. Uses embedded IP geolocation watchlists to enrich raw flows.
Resource Provisioning Mapping
Tracks and maps global origins from which Azure resources are physically being provisioned. Exposes anomalous cloud deployment patterns from compromised accounts.
VM Authentication Failures
Comprehensive mapping of authentication failures across virtual machine infrastructure. Rapidly flags coordinated, distributed, geographic brute-force attacks against RDP/SSH.
AAD Failed Sign-ins
Visualizes geographic regions sourcing persistent Azure Active Directory (Entra ID) authentication failures to catch targeted identity credential abuse.
AAD Successful Sign-in Baseline
Maps global locations of successful Azure AD authentications. This establishes a highly visual geographic baseline for user access. Critical for subsequent Unlikely Travel anomaly detection.
Core Telemetry & Datasets
| Entra ID Auditing | SigninLogs |
| Windows Hosts | SecurityEvent |
| Linux Servers | Syslog |
| Resource Control Logs | AzureActivity |
| NSG Flow Logs | AzureNetworkAnalytics_CL |
| Threat Intelligence | ThreatIntelligenceIndicator |
KQL Threat Hunt Logic
// Example logic powering the AAD Failed Sign-ins map
SigninLogs
| where ResultType != 0
| summarize FailureCount = count() by IPAddress, LocationDetails.countryOrRegion, LocationDetails.geoCoordinates.latitude, LocationDetails.geoCoordinates.longitude
| where isnotempty(LocationDetails_geoCoordinates_latitude)
| project IPAddress, FailureCount, Latitude = LocationDetails_geoCoordinates_latitude, Longitude = LocationDetails_geoCoordinates_longitude
| sort by FailureCount descAzureNetworkAnalytics_CL
| where FlowType_s == "MaliciousFlow"
| extend GeoData = geo_info_from_ip_address(DestIP_s)
| summarize Hits = count() by DestIP_s, tostring(GeoData.country), tostring(GeoData.latitude), tostring(GeoData.longitude)
| project IPAddress=DestIP_s, Hits, Latitude=GeoData_latitude, Longitude=GeoData_longitudeStrategic SOC Operations Use Cases
- 1Deploy the AAD Sign-in baselines immediately to project shift-handoff threat visual summaries across global analyst teams.
- 2Integrate Malicious Network Flow maps onto high-visibility SOC wallboards for active triage of global botnet infrastructure scanning Azure boundaries.
- 3Leverage Resource Authorization logs geospatially in Management Reporting to provide high-level security posture geographic assessment to leadership.
- 4Periodically audit Conditional Access application constraints by comparing allowed-sign-ins against expected geo-fence baselines globally.