Objectives Overview:
-Locate Microsoft Windows Security Virus and Threat Protection Settings
-Run Microsoft Windows Defender Antivirus Quick Scan
-Configure Microsoft Windows Firewall Rules
Objectives Overview
-Used custom PowerShell script to extract meta data from windows event viewer to be forwarded to third party API to derive geolocation data
-Configured Log Analytics Workspace in Azure to ingest custom logs containing geographic information e.g. country
-Configured Custom Field in Log analytics workspace with the intent of mapping geo data In azure sentinel
-Configured Azure Sentinel (Microsoft’s cloud SIEM) workbook to display global attack data (RDP brute force) on world map according to physical location and magnitude of attacks.
Objectives Overview
-Creating users and assigning them with appropriate privileges
-Reset users password and Unlocking users accounts
-Connecting users to domain