Microsoft Sentinel practice lab
This is a Microsoft Sentinel style lab with KQL-like queries. It is not an Azure subscription and it does not query your Log Analytics workspace. The dummy tables are SecurityEvent and SigninLogs. You can list the workspace, open incidents, read analytics rules, and inspect watchlists. Queries run on that practice data only.
Treat a query that returns rows as a look at the built-in sample, not as evidence from a SOC. If a field name differs from a production workspace you know, stay with the columns this lab prints. The side panel lists the commands that work.
Guest mode needs no Azure login. Do not paste a tenant ID, client secret, or workspace key. Name the table in the query. SecurityEvent and SigninLogs do not share columns. If the lab returns no rows, check the table name against the side panel before you rewrite the query. Sign-in on the simulator only keeps this workspace.
Common questions
Which tables have data?
Dummy SecurityEvent and SigninLogs, plus incidents, analytics rules, and watchlists.
Is this Kusto against Azure?
No. The queries are answered by the practice data in the browser.
Can I hunt my company's sign-ins?
No. SigninLogs here is sample data.
What should I open first?
show workspace, then show incidents and show analytics rules.
SIEM lab with KQL-style queries against dummy SecurityEvent / SigninLogs tables, incidents, and analytics rules.