{"type":"video","version":"1.0","html":"<iframe src=\"https://www.loom.com/embed/e8405fe2157c418d934710b748976e8f\" frameborder=\"0\" width=\"2560\" height=\"1920\" webkitallowfullscreen mozallowfullscreen allowfullscreen></iframe>","height":1920,"width":2560,"provider_name":"Loom","provider_url":"https://www.loom.com","thumbnail_height":1920,"thumbnail_width":2560,"thumbnail_url":"https://cdn.loom.com/sessions/thumbnails/e8405fe2157c418d934710b748976e8f-ee244b06318dc9f4.gif","duration":906.838,"title":"Automating Alerts for Suspicious Activity in Microsoft Sentinel 🔔","description":"In this video, I walk through a practical sock workflow where I simulate suspicious process activity in Splunk and create an automated alert in Microsoft Sentinel for failed sign-ins. I demonstrate how to generate synthetic process events, visualize suspicious executions, and set up a scheduled alert for failed login attempts that exceed a threshold. The alert triggers automatically for investigation, ensuring we stay proactive against potential threats. I encourage viewers to implement similar detection engineering practices in their environments. Thank you for watching!"}