Midnight is a theme for GitHub Pages.
Platform: Microsoft Azure / Microsoft Entra ID / Microsoft Defender XDR / Security Copilot
Focus: Cloud environment setup, identity configuration, and incident investigation using Microsoft security tools
This lab demonstrates:
All activities were performed in an isolated, non-production environment.
Configured a cost management budget to control Azure spending and prevent unexpected charges.

Set up budget alerts to trigger notifications when spending thresholds are reached.

Created a dedicated resource group to logically organize cloud resources used in the lab.

Provisioned a workspace to enable centralized logging and integration with security tools.

Configured tenant settings to allow appropriate access across Azure services.

Assigned Owner role to the user to enable full administrative control for lab configuration.

Provisioned Microsoft Security Copilot and verified its availability for investigation workflows.

Selected high severity incident #185856 for investigation.

Investigated suspicious Remote Desktop activity associated with the incident.

Used Security Copilot to generate a summary of the affected device, improving investigation speed.

Analyzed details of the user associated with the compromised asset.

Identified unexpected script execution originating from the user’s device.

Decoded a suspicious PowerShell command to reveal underlying behavior.

Investigated related:
to understand full attack scope.

Detected usage of mimikatz.exe, indicating credential dumping activity.

Used Security Copilot to enrich findings and accelerate analysis.



Generated and executed KQL queries to identify additional malicious activity.

Correlated additional alerts uncovered during advanced hunting.

All activities were performed in a controlled lab environment using simulated data.