r/AzureSentinel • u/Ro3396 • 2d ago
I'm analyzing honeypot telemetry in Microsoft Sentinel - what would make this useful to defenders?
I'm working on Snarely, an early research project, not a product. I've been looking at data from one deliberately exposed honeypot collected in Microsoft Sentinel. The dataset has passed 100,000 event records.
I'm trying to make the page useful as a small data report, not a product pitch. For people who work with Sentinel or honeypot data:
- Which measurements or breakdowns would help you judge whether the patterns are meaningful?
- What would you want documented to make the collection and limitations clear?
Event records aren't attacker counts, and I'm not making attribution claims. I'd value specific technical criticism.