<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sentinel on MEDDAH Mohamed</title><link>https://meddah.systems/tags/sentinel/</link><description>Recent content in Sentinel on MEDDAH Mohamed</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Sat, 01 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://meddah.systems/tags/sentinel/index.xml" rel="self" type="application/rss+xml"/><item><title>Adversary Simulation &amp; Detection Engineering Lab</title><link>https://meddah.systems/post/infrastructure/adversary-simulation-lab/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://meddah.systems/post/infrastructure/adversary-simulation-lab/</guid><description>&lt;blockquote&gt;
&lt;p&gt;🚧 &lt;strong&gt;Full write-up coming soon.&lt;/strong&gt; Detailed documentation, attack chain diagrams, and detection rule breakdowns are being written up.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="overview"&gt;&lt;a href="#overview" class="header-anchor"&gt;&lt;/a&gt;Overview
&lt;/h2&gt;&lt;p&gt;This lab executes 5 complete adversarial attack chains across 13 MITRE ATT&amp;amp;CK techniques, with each attack paired with engineered KQL detection rules in Microsoft Sentinel and a coverage gap analysis.&lt;/p&gt;
&lt;h2 id="attack-chains"&gt;&lt;a href="#attack-chains" class="header-anchor"&gt;&lt;/a&gt;Attack Chains
&lt;/h2&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Chain&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;th&gt;ATT&amp;amp;CK ID&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Phishing-to-Domain Compromise&lt;/td&gt;
&lt;td&gt;Spearphishing, Credential Dumping&lt;/td&gt;
&lt;td&gt;T1566, T1003&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Entra ID Identity Attacks&lt;/td&gt;
&lt;td&gt;Pass-the-PRT, Token Theft&lt;/td&gt;
&lt;td&gt;T1528, T1550&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cloud Misconfiguration Exfil&lt;/td&gt;
&lt;td&gt;Abuse Elevation Control Mechanism&lt;/td&gt;
&lt;td&gt;T1548&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;On-Prem to Cloud Lateral Movement&lt;/td&gt;
&lt;td&gt;PRT Abuse via AADInternals&lt;/td&gt;
&lt;td&gt;T1550.001&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Backdoor Service Principal&lt;/td&gt;
&lt;td&gt;Persistence via Application&lt;/td&gt;
&lt;td&gt;T1098.001&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="stack"&gt;&lt;a href="#stack" class="header-anchor"&gt;&lt;/a&gt;Stack
&lt;/h2&gt;&lt;p&gt;&lt;code&gt;Azure&lt;/code&gt; &lt;code&gt;Terraform&lt;/code&gt; &lt;code&gt;Microsoft Sentinel&lt;/code&gt; &lt;code&gt;KQL&lt;/code&gt; &lt;code&gt;Containerlab&lt;/code&gt; &lt;code&gt;Sysmon&lt;/code&gt; &lt;code&gt;Mimikatz&lt;/code&gt; &lt;code&gt;Impacket&lt;/code&gt; &lt;code&gt;AADInternals&lt;/code&gt; &lt;code&gt;ROADtools&lt;/code&gt; &lt;code&gt;Python&lt;/code&gt; &lt;code&gt;PowerShell&lt;/code&gt;&lt;/p&gt;
&lt;h2 id="status"&gt;&lt;a href="#status" class="header-anchor"&gt;&lt;/a&gt;Status
&lt;/h2&gt;&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Attack chains designed and executed&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; KQL detection rules written&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Coverage gap analysis completed&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Full write-up in progress&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>