End-to-end build log — honeypot → MISP → Azure Sentinel. Dockerized threat intel platform, Azure Function App ingestion, and custom KQL detections. Full write-up with screenshots.