<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/e8405fe2157c418d934710b748976e8f&quot; frameborder=&quot;0&quot; width=&quot;2560&quot; height=&quot;1920&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1920</height><width>2560</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1920</thumbnail_height><thumbnail_width>2560</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/e8405fe2157c418d934710b748976e8f-ee244b06318dc9f4.gif</thumbnail_url><duration>906.838</duration><title>Automating Alerts for Suspicious Activity in Microsoft Sentinel 🔔</title><description>In this video, I walk through a practical sock workflow where I simulate suspicious process activity in Splunk and create an automated alert in Microsoft Sentinel for failed sign-ins. I demonstrate how to generate synthetic process events, visualize suspicious executions, and set up a scheduled alert for failed login attempts that exceed a threshold. The alert triggers automatically for investigation, ensuring we stay proactive against potential threats. I encourage viewers to implement similar detection engineering practices in their environments. Thank you for watching!</description></oembed>