Home›Detection Engineering›Sentinel, end to end
Series
Sentinel, end to end
Microsoft Sentinel as a platform, built from the ground up — the data foundation, detection, and response. Three parts, best read in order. Every piece is one trade between coverage, speed, and cost.
How Sentinel is built: from the loading dock to the lake
The data foundation — subscription and workspace, RBAC, the Defender portal, connectors and DCRs, table tiers and retention, and the data lake economics that quietly decide your bill.
Read →How Sentinel detects: rules, alerts, incidents, and the hunt
Turning tables into a SIEM — analytics rules (templates vs custom, and why a rule is more than its KQL), rule types, watchlists, the alert-to-incident chain and honest grouping, hunting, notebooks, and entity behaviour.
Read →How Sentinel responds: the reflex and the muscle
Turning incidents into action — automation rules vs playbooks (Logic Apps), auto-enrichment as the highest-leverage automation, remediation, and where to keep a human on the trigger.
Read →