
Explore Microsoft Sentinel to master threat detection and security information and event management in Azure, ingest data from multiple sources, build analytics rules and workbooks, and automate incident response.
Explore Microsoft Sentinel, a scalable cloud-native SIEM and security orchestration platform that delivers security analytics, threat intelligence, proactive hunting, and automated response across on-premise and multi-cloud environments.
Understand security information and event management (SIM) as a tool that collects and queries logs from various systems, detects anomalies, and generates alerts and incidents to support security operations.
Explore how Microsoft Sentinel, a cloud-native SIEM, centralizes security data across cloud environments, enables automated remediation and advanced analytics, and integrates with Azure services for unified threat intelligence.
Explore four quiz questions that reinforce how Microsoft Sentinel provides an end-to-end security operations solution, including visibility, analytics, hunting, incident management, and automation, with KQL queries and Log Analytics.
Explore prerequisites and system requirements for Microsoft Sentinel, including an Azure subscription, permissions, Azure Active Directory, data sources, a Log Analytics workspace, connectivity, and Azure deployment with data connectors.
Configure Azure Sentinel by creating an active Azure subscription, creating a resource group, assigning roles (Owner, Contributor, or Reader), and provisioning a Log Analytics workspace in the Azure portal.
Learn to configure data connectors and data sources in Microsoft Sentinel after deployment. Ingest data from Microsoft and non-Microsoft sources via connectors and APIs, with permissions and setup steps.
Answer a four-question quiz to test Sentinel knowledge. Learn about data sources for visibility, Azure Monitor, ownership to delegate roles, and viewing events over time in the overview pane.
Collect and ingest data from various sources into Microsoft Sentinel by configuring data connectors. Enable UEBA and analytics rules to detect incidents using Azure activity and Microsoft Entra ID.
Explore how Azure Monitor collects telemetry data from diverse sources and feeds Microsoft Sentinel for security analytics, automated response, and advanced threat detection.
Learn to configure custom data connectors in Microsoft Sentinel, from CCP and Log Analytics agent to Logic Apps and Azure Functions, with practical portal steps.
Configure custom data connectors in Microsoft Sentinel by selecting a pre-existing connector and adjusting its settings, then monitor activity via Sentinel console logs to discover security threats.
Explore Microsoft Sentinel workbooks for data visualization and interactive dashboards, using templates or custom workbooks, with prerequisites and permissions to enable security analytics and monitoring.
Learn to build custom workbooks for data visualizations in Microsoft Sentinel using templates from the Content Hub, customize with edits, and manage saving, sharing, and auto refresh.
Learn how to monitor and manage Microsoft Sentinel workbooks with Azure Monitor, using templates or from scratch, to create interactive dashboards from Log Analytics and other data sources.
Learn to create and customize Microsoft Sentinel workbooks in the Azure portal, using templates or custom edits, manage workbook reader or contributor permissions, and set auto-refresh.
Test your understanding of Microsoft Sentinel workbooks and dashboards through four questions on drilling down into data points and using log analytics queries for security data.
Explore how analytics rules in Microsoft Sentinel enable early threat detection, automation, and customization with built-in and custom rules for proactive security.
Create custom analytics rules in Microsoft Sentinel by using templates or building your own, to detect suspicious activity and automatically generate incidents for investigation.
Learn to fine-tune and manage analytics rules in Microsoft Sentinel, using machine learning insights, testing rules, integrating threat intelligence, and optimizing queries to reduce false positives and improve detection.
Wraps up module five with a four-question quiz on tuning performance, validating rules with the test rule feature, automating incident response via custom analytics rules, and using Kusto query language.
Discover how Microsoft Sentinel detects security incidents and uses a full-featured case management platform, incident details page, and automation rules to triage and respond.
Classify and investigate incidents in Microsoft Sentinel by aggregating alerts into a single incident from analytics rules, then manage the investigation through the incident detail page with permissions and ownership.
Automate incident response in Microsoft Sentinel with playbooks, using templates or custom automations, tested before deployment, and triggered by automation rules to remediate and isolate threats.
Master how playbooks trigger automatically on conditions, what a logic app does as an automated workflow, and how severity levels support incident management in Microsoft Sentinel.
Learn proactive threat hunting in Microsoft Sentinel by collecting data, applying analytics rules and kql queries, and following a continuous improvement workflow.
Use KQL for threat hunting in Microsoft Sentinel, build analytics queries and proactive detection rules with pre-built and custom analytics, and integrate threat intelligence while continuously monitoring data.
Review four quiz questions on threat hunting in Microsoft Sentinel, highlighting proactive detection and response, Kusto query language, automation benefits, and threat intelligence feeds for contextual alerts.
Explore monitoring compliance with security policies in Microsoft Sentinel through built-in dashboards, continuous monitoring, automated checks, and Azure policy and Security Center integration for enforcement and audits.
Create tailored reports in microsoft sentinel with azure workbooks, templates, and kusto queries, and integrate sentinel with azure security center to enhance security monitoring and compliance.
Master compliance monitoring in Microsoft Sentinel through the module eight quiz, focusing on policy enforcement, adherence tracking with compliance policies, data retention, and third-party integration with Azure Security Center.
Automate security tasks in Microsoft Sentinel with Logic Apps and playbooks, enabling incident enrichment, automated responses, and orchestration across security tools and feeds.
Learn to create custom automation workflows in Microsoft Sentinel using Logic Apps and orchestrate tasks with Azure Functions, enabling incident response, threat hunting, and security operations.
Wraps up module nine with a four-question quiz on Microsoft Sentinel automation, covering goals to boost security operations efficiency, Azure Logic Apps for automated workflows, and playbooks and Azure Functions.
Explore advanced Kql queries in Microsoft Sentinel, including time series analysis and anomaly detection, while integrating third-party solutions and managing multi-cloud environments across AWS, Azure Monitor, and Google Cloud Security.
Test your understanding of integrating third party security solutions with Microsoft Sentinel, using connectors, logic apps, and Azure Functions to ingest data and build workflows.
Become a Microsoft Sentinel professional and learn one of employer's most requested skills nowadays!
This comprehensive course is designed so Security Analysts, Security Operations Center (SOC) Teams, Cloud Security Engineers, IT Professionals, SOAR managers, Cybersecurity Enthusiasts, Azure Administrators... can learn Sentinel from scratch to use it in a practical and professional way. Never mind if you have no experience in the topic, you will be equally capable of understanding everything and you will finish the course with total mastery of the subject.
After several years working in IT, we have realized that nowadays mastering Microsoft Sentinel for providing advanced security analytics and threat detection capabilities is very necessary in cloud, hybrid cloud, on-premises, multi-cloud, and enterprise environments. Knowing how to use this tool can give you many job opportunities and many economic benefits, especially in the world of cybersecurity.
The big problem has always been the complexity to perfectly understand Sentinel (including SOAR and SIEM) requires, since its absolute mastery is not easy. In this course we try to facilitate this entire learning and improvement process, so that you will be able to carry out and understand your own projects in a short time, thanks to the step-by-step, detailed and hands-on examples of every concept.
With almost 7 exclusive hours of video, this comprehensive course leaves no stone unturned! It includes both practical exercises and theoretical examples to master Azure Sentinel SIEM. The course will teach you how to effectively monitor, detect, investigate, and respond to cybersecurity threats using Microsoft Sentinel in various cloud and on-premises environments in a practical way, from scratch, and step by step.
We will start with the setup of the needed work environment on your computer, regardless of your operating system and computer.
Then, we'll cover a wide variety of topics, including:
Introduction to Sentinel and course dynamics
Understand its role in Azure's security ecosystem
Learn deployment prerequisites and configuration steps
Explore methods for ingesting security data
Build custom dashboards for data visualization
Develop and manage custom rules for threat detection
Detect and respond to security incidents
Utilize KQL for proactive threat detection
Monitor compliance and generate reports
Automate security tasks with Logic Apps and Functions
Explore machine learning and Azure integration
Optimize performance and resource utilization
Mastery and application of absolutely ALL the functionalities of Sentinel
Quizzes, Practical exercises, complete projects and much more!
In other words, what we want is to contribute our grain of sand and teach you all those things that we would have liked to know in our beginnings and that nobody explained to us. In this way, you can learn to build and manage a wide variety of projects and make versatile and complete use of Sentinel One. And if that were not enough, you will get lifetime access to any class and we will be at your disposal to answer all the questions you want in the shortest possible time.
Learning Microsoft Sentinel has never been easier. What are you waiting to join?