Azure security engineer

Tarunteja Desireddy

I design and run security operations on Microsoft Sentinel — detection pipelines, analytics rules, and automated response, built end to end from the log source to the containment playbook.

Microsoft Sentinel Normalize · CEF Detect · Suricata IPS Collect · honeypot

Overview

I'm a security engineer working in Azure. I run a detection-and-response stack end to end: Microsoft Sentinel over live telemetry, an internet-facing honeypot feeding a normalised CEF pipeline, a tuned analytics ruleset, and SOAR automation that triages and contains incidents with no human in the loop.

I work from the threat backwards. Every detection maps to a technique, every rule is validated against real data before it ships, and negative testing comes first — trigger the 403, confirm the gap, then close it. Every control is documented with the threat it addresses and how to verify it.

Selected work

Internet-facing honeypot → Microsoft Sentinel

Cowrie · Suricata IPS · nftables · CEF · KQL

A deliberately exposed SSH decoy catching genuine attacker traffic, normalised into CommonSecurityLog through a four-layer pipeline. The attackers are real; only the target is fake.

  • Suricata run inline as true IPS (NFQUEUE), with fail-open safety and a deadman switch on every risky change
  • Custom Python CEF converters for the firewall and shell layers — parsed fields, not regex scraping
  • Every trace of "honeypot / lab" scrubbed from the logs so an analyst working the incident can't tell it's a decoy — down to the platform-populated _ResourceId column, which needed a full VM rebuild under a new identity

Automated incident response

Logic Apps · Microsoft Graph · AbuseIPDB / VirusTotal

A playbook that polls for active incidents, extracts the source IP from alert evidence, reputation-checks it, then blocks and closes as true/false positive with an investigation comment — no human approval step.

  • First backlog run: 47 of 50 incidents processed, classifications separating sensibly
  • Found and fixed a block pipeline that had been silently 404-ing — it only failed on the runs that actually mattered, so it looked healthy

Analyst detection ruleset & training

Microsoft Sentinel · KQL · Entra ID

Ten analytics rules covering SSH brute force, unexpected interactive sessions, sensitive-credential-file access, port scans and network-scan-then-login correlation — each tuned against live data, not a 200 OK. Plus a 30-day structured training programme delivered to a small analyst group.

Skills

Microsoft Sentinel
KQL
Microsoft Defender
Microsoft Entra ID
Conditional Access
Azure networking / NSG
Logic Apps / SOAR
Threat intelligence
Honeypots & deception
Incident response
CEF / Syslog pipelines
Azure CLI / Graph API

Certifications

Contact