Wrote KQL analytics rules for real-time threat detection covering: privilege escalation, suspicious PowerShell execution, lateral movement via RDP and SMB, anomalous Azure AD sign-ins, and malware execution patterns. Automated incident response using Azure Logic Apps.