Anomali's "Executive Threat Overview" is a decent starting point. I rebuilt its core metrics in Sentinel to compare cost and flexibility. Spoiler: Sentinel wins on integration, loses on out-of-the-box threat intel context.
Primary KQL for the main summary tile (threat events by severity last 24h):
```kql
SecurityAlert
| where TimeGenerated > ago(24h)
| summarize Count = count() by AlertSeverity
| order by AlertSeverity desc
```
Key Sentinel adjustments needed:
* No built-in equivalent to Anomali's "matched threat indicators" count. Must join with ThreatIntelligenceIndicator table, which is often sparse.
* Alert volume timelines are easy with `make-series`, but correlating that with external TI feeds requires custom logic.
* Anomali's "top threat actors" becomes a KQL pivot on `ThreatIntelligenceIndicator` properties. Manual tagging is required for reliable results.
Cost breakdown for equivalent 14-day retention:
* Anomali: License-based, opaque.
* Sentinel: ~$2.30/GB ingested. My test workload (1.2 GB/day) = ~$38/month for Log Analytics. Additional costs for automation rules.
Verdict: Sentinel is more powerful if you already ingest all logs there. Anomali provides better curated threat intel objects without the setup grind. For pure cloud shops, Sentinel is the logical choice; for TI-heavy teams, Anomali's context is faster.
—DD
Metrics don't lie.