Erick Cisneros
ContactResume
Directory
Overview
Experience
Investigations & Tooling
The Trophy Case
Education
Contact Me
Direct Inquiries
Back to Security Investigations & Tooling
PRJ-2025-SW01

Sentinel Geo-Visualizations

STATUS: ACTIVE / MAINTAINED

ANALYST: Erick Cisneros Ruballos

DATETIME: Rolling Deployment

A collection of advanced Microsoft Sentinel workbooks designed for threat hunting and security monitoring. By correlating log data with geographic information, these dashboards provide powerful visual intelligence for SOC operations.

Microsoft SentinelAzureKQLData VisualizationThreat Intelligence
See Full Report on GitHub
Architecture Overview

Executive Summary

Transforming raw log infrastructure data into actionable geographic intelligence is critical to tracing distributed threat patterns across the globe. These tailored Azure Sentinel workbooks enable analysts to actively profile an environment, moving past standard alerts and into visual threat hunting based on regional anomalies.

By unifying telemetry from disparate sources — like Entra ID Sign-ins, Azure Activity Logs, and Network Security Group flows — cross-correlated against Threat Intelligence watchlists, the SOC gains an immediate view into anomalous behaviors that standard logic rules may miss.

PROJECT TYPETHREAT HUNTING
PLATFORMMicrosoft Sentinel
CORE TECHKQL
FOCUSGeo-Visualizations
Dashboards & Correlators

Workbook Implementations

NODE 1AzureNetworkAnalytics_CL

Malicious Network Flow

Maps the geographic origins of network traffic flagged as 'MaliciousFlow' in Azure Network Analytics logs. Uses embedded IP geolocation watchlists to enrich raw flows.

NODE 2AzureActivity

Resource Provisioning Mapping

Tracks and maps global origins from which Azure resources are physically being provisioned. Exposes anomalous cloud deployment patterns from compromised accounts.

NODE 3Syslog / SecurityEvent

VM Authentication Failures

Comprehensive mapping of authentication failures across virtual machine infrastructure. Rapidly flags coordinated, distributed, geographic brute-force attacks against RDP/SSH.

NODE 4SigninLogs (Failed)

AAD Failed Sign-ins

Visualizes geographic regions sourcing persistent Azure Active Directory (Entra ID) authentication failures to catch targeted identity credential abuse.

NODE 5SigninLogs (Success)

AAD Successful Sign-in Baseline

Maps global locations of successful Azure AD authentications. This establishes a highly visual geographic baseline for user access. Critical for subsequent Unlikely Travel anomaly detection.

Log Ingestion

Core Telemetry & Datasets

Identity & Access Telemetry
Entra ID AuditingSigninLogs
Windows HostsSecurityEvent
Linux ServersSyslog
Infrastructure & Network
Resource Control LogsAzureActivity
NSG Flow LogsAzureNetworkAnalytics_CL
Threat IntelligenceThreatIntelligenceIndicator
Query Construction

KQL Threat Hunt Logic

Map Logic 1: Auth Failure Aggregations
KQL Query
// Example logic powering the AAD Failed Sign-ins map
SigninLogs
| where ResultType != 0
| summarize FailureCount = count() by IPAddress, LocationDetails.countryOrRegion, LocationDetails.geoCoordinates.latitude, LocationDetails.geoCoordinates.longitude
| where isnotempty(LocationDetails_geoCoordinates_latitude)
| project IPAddress, FailureCount, Latitude = LocationDetails_geoCoordinates_latitude, Longitude = LocationDetails_geoCoordinates_longitude
| sort by FailureCount desc
Map Logic 2: Malicious Flow Extraction
KQL Query
AzureNetworkAnalytics_CL
| where FlowType_s == "MaliciousFlow"
| extend GeoData = geo_info_from_ip_address(DestIP_s)
| summarize Hits = count() by DestIP_s, tostring(GeoData.country), tostring(GeoData.latitude), tostring(GeoData.longitude)
| project IPAddress=DestIP_s, Hits, Latitude=GeoData_latitude, Longitude=GeoData_longitude

Strategic SOC Operations Use Cases

  • 1Deploy the AAD Sign-in baselines immediately to project shift-handoff threat visual summaries across global analyst teams.
  • 2Integrate Malicious Network Flow maps onto high-visibility SOC wallboards for active triage of global botnet infrastructure scanning Azure boundaries.
  • 3Leverage Resource Authorization logs geospatially in Management Reporting to provide high-level security posture geographic assessment to leadership.
  • 4Periodically audit Conditional Access application constraints by comparing allowed-sign-ins against expected geo-fence baselines globally.
© 2026 Erick Cisneros Ruballos
LinkedIn•GitHub•Direct Email