Logging & Monitoring
Collect the right signals, enrich them with context, and turn telemetry into action across Microsoft and AWS.
Overview
Logging and monitoring form the backbone of detection engineering. Strong telemetry enables identity protection,
Zero Trust enforcement, incident response, and threat hunting. This pillar focuses on OS, cloud, and network signals,
plus advanced detection rules in Microsoft Sentinel, AWS GuardDuty, and other cloud-native tools.
Completed Labs
No completed labs yet — this pillar is currently being built.
In Progress Labs
Intune Monitoring — Device & User Activity
In Progress
Endpoint Defender Security Policies + Monitoring
In Progress
AWS Monitoring with CloudWatch
In Progress
NIDS/HIDS Alerts
In Progress
Capturing Network Traffic
In Progress
Incident Response Procedures
In Progress
Autopsy Forensics Investigation
In Progress
Advanced Logging & Monitoring Labs
Cloud-native detection engineering and real-time telemetry processing.