Developer Builds AI-Powered SOC Analyst Using Microsoft Sentinel and Google Gemini
A developer has created an agentic Security Operations Center (SOC) analyst that combines Microsoft Sentinel, Azure Log Analytics, and Google Gemini to automate threat-hunting workflows. The system converts natural-language queries into Kusto Query Language (KQL), executes them against Azure Log Analytics, and returns structured findings with MITRE ATT&CK technique mappings. Every table and field selected by the AI model is validated against a strict allow-list before any query runs, preventing hallucinated or unsupported inputs from reaching Azure infrastructure. To enable safe testing without exposing real data, the developer also built utilities to generate synthetic log datasets that can be ingested into test workspaces. The project is ongoing, with planned improvements including multi-step investigation planning, better evidence correlation, and support for additional SIEM platforms.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in