SentinelOPS is an engineering project for reducing the distance between an alert firing and an analyst making a defensible decision. It focuses on high-signal triage, transparent enrichment, and runbooks that are useful under pressure—not another dashboard full of disconnected widgets.
Project signal
3 layers
telemetry, detection, response
Core stack
Python · FastAPI · Sigma · OpenSearch
Architecture
Normalizes endpoint, identity, and network events while recording source health and collection latency.
Maps versioned detection logic to a common schema and attaches ATT&CK context before alerting.
Presents enrichment, confidence signals, and the right response playbook in a single case view.
Capabilities
Operational views
These interface snapshots define the key evidence surfaces for the project. They are intentionally designed around investigation context rather than decorative dashboards.
View 01
Normalizes endpoint, identity, and network events while recording source health and collection latency.
View 02
Maps versioned detection logic to a common schema and attaches ATT&CK context before alerting.
View 03
Presents enrichment, confidence signals, and the right response playbook in a single case view.
Roadmap
Continue exploring
Home Lab
A repeatable Windows and Linux monitoring lab for testing telemetry, adversary behavior, and detections before production use.
Detection Engineering
A practical rule-development workflow that connects hypotheses, sample telemetry, test cases, and release decisions.
Threat Hunting
A hypothesis-led investigation framework for turning ATT&CK-informed questions into repeatable hunts and measurable improvements.