cybermar8
← Featured projects

Azure Honeypot / Sentinel SIEM Lab

An intentionally exposed Windows 10 VM in Azure, used to capture real internet-borne brute-force RDP attempts, then analyzed end-to-end with Microsoft Sentinel: KQL queries, GeoIP enrichment, and a workbook mapping where the traffic actually came from.

Microsoft AzureMicrosoft Sentinel KQLLog AnalyticsGeoIP

Setup

The VM was deliberately weakened to attract real attack traffic rather than simulate it:

1. Windows 10 VM deployed in Azure 2. NSG configured to allow all inbound traffic 3. Windows Firewall disabled on the VM 4. Failed RDP logon attempts land in Windows Security Event Logs 5. Logs centralized into a Log Analytics Workspace via Microsoft Sentinel 6. KQL queries run against the SecurityEvent table 7. GeoIP watchlist imported to enrich attacker IPs with location 8. Sentinel workbook built to visualize attack origins geographically

What the data showed

Querying SecurityEvent | where EventID == '4625' (Windows' failed-logon event) surfaced brute-force RDP attempts from across the open internet within hours of the VM going live. The GeoIP-enriched workbook mapped them by volume:

OriginAttempts
Jordanów, Poland20,700
Tilburg, Netherlands16,500
Ranchos, Argentina2,250
Maarn, Netherlands1,470
Vilobí del Penedès, Spain1

Screenshots

Windows Security Event Viewer showing failed RDP logon attempts
Windows Security Event Log — failed RDP logon attempts.
Azure Network Security Group allow-all inbound rules
The NSG's intentionally permissive inbound rules.
KQL query against SecurityEvent for EventID 4625
Querying SecurityEvent for EventID 4625 (failed logon) in Sentinel Logs.
GeoIP-enriched query results
GeoIP-enriched results — attacker IPs resolved to locations.
Sentinel workbook attack map
The Sentinel workbook's geographic attack map.