Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Microsoft Sentinel Hands-on-Training For Beginners
Rating: 4.5 out of 5(208 ratings)
4,606 students

Microsoft Sentinel Hands-on-Training For Beginners

Azure Sentinel Security
Created byRyan O'Connell
Last updated 1/2024
English
English [Auto],

What you'll learn

  • Set up working Sentinel Environment for FREE
  • Understand the properties of Analytics Rules and see how to create them
  • Understand and learn basics of KQL (Kusto Query Language)
  • Understand the purpose of Workbooks
  • Learn about the importance of Threat Intelligence
  • Learn about Incident Management in Microsoft Sentinel
  • Discover different options for data ingestion
  • Discover how to use Microsoft Sentinel for Threat Hunting
  • Understand privileges and role assignment for Sentinel
  • Learn how to set up your own training lab for practicing the concepts

Course content

1 section22 lectures1h 28m total length
  • Welcome the the Course0:25

    Kick off your Azure Sentinel journey by learning the basics in this beginner hands-on course, with a warm welcome and thanks for your support.

  • Live-Lab -Deploy a Sentinel Resource Group0:55

    Log into Azure, navigate to resource groups, and create a new resource group named Azure Sentinel Training Lab in Australia East. Review and create to run validation and finalize deployment.

  • Live-Lab - Deploy the Sentinel Log Analytical Workspace2:12

    Deploy an Azure Log Analytics workspace to enable Sentinel, using the Azure portal to create a Log Analytics workspace in the Sentinel Training Lab resource group, and validate before deployment.

  • Live-Lab -Deploy Microsoft Azure Sentinel1:14

    Learn how to set up Microsoft Sentinel by selecting or creating a workspace, adding it to Microsoft Sentinel, and starting a free trial for hands-on training in the console.

  • Live-Lab - Deployment of Sentinel & Sentinel Training Solution2:54

    Learn how to install and deploy the Microsoft sentinel training lab solution, configure the training workspace and resource group, and understand deployment times from five to thirty minutes.

  • Live-Lab - Sentinel RBAC5:12

    Apply Sentinel rbac at the resource group level to assign roles such as reader, responder, and contributor, detailing who can view, manage incidents, edit analytic rules, and configure data connectors.

  • Live-Lab - Azure Sentinel Data Activity Connector Setup7:56

    Learn to use Azure Sentinel data connectors to ingest logs from diverse sources via Content Hub, install and connect the Azure Activity Data Connector, troubleshoot connectivity, and configure diagnostics.

  • Live-Lab - Pulsedive Sentinel Threat Intelligence Data Connector Setup8:33

    Set up the Microsoft Threat Intelligence connector in Sentinel and link Pulse Dive to ingest threat indicators such as IPs, domains, URLs, and file hashes for real-time threat context.

  • Sentinel Analytic Rule Types3:35

    Explore sentinel analytic rule types, including scheduled, near real-time, fusion, and anomaly rules. See how machine learning behavior analytics and threat intelligence enhance detections.

  • Live-Lab - Create a Sentinel Scheduled Analytics Rule3:07

    Create a scheduled query rule in the analytics blade to monitor audit logs for added users, set 5-minute automatic runs, zero threshold, and save.

  • Live -Lab - Create Sentinel Near-Real-Time Rule (NTR)2:16

    Create a near real-time rule in Microsoft Sentinel by configuring an NRT query rule, enabling analytics, incident settings, and saving a validated rule for near real-time alerts.

  • Live-Lab - Create a Fusion Rule1:53

    Enable the fusion rule in Microsoft Sentinel by using the fusion template in the analytics blade, then create, review, and save the multi-stage attack detection rule for the lab.

  • Live-Lab - ML Behavior Analytics Rule (RDP & SSH)2:13

    Create ML behavior analytics rules for RDP and SSH in Microsoft Sentinel using templates, enable them, and allow seven days to build a normal activity profile before they kick in.

  • Live-Lab - Create an Automation Rule4:12

    Create and configure an automation rule in Microsoft Sentinel to trigger on new user additions, set active status, high severity, assign an owner, and tag automated for ongoing incident analytics.

  • Live-Lab - Create a Watchlist and Update the List5:06

    Create and update Azure Sentinel watch lists by importing a CSV of IP addresses and using IOCs in detection rules, with allow lists to reduce alerts.

  • Live-Lab - Integrate a Watchlist into Sentinel Analytic Rules4:03

    learn to integrate an IP watchlist into Azure Sentinel by installing a high count by client IP and port rule from Content Hub, editing KQL, and enabling automated responses.

  • Live-Lab-Threat Hunting13:17

    Learn to conduct Azure Sentinel threat hunting with predefined queries, templates, and hunts, perform automation, investigation, and remediation, and escalate findings into incidents for SoC analysis.

  • Live-Lab - ATT&CK Framework in Sentinel6:38

    Discover how the mighty attack (Miter Attack) in Microsoft Sentinel maps threats, investigates attack paths, and uses analytics and rules to detect and defend against intrusions.

  • Live-Lab - Enable UEBA & Create a Custom Anomaly Rule in Sentinel7:48

    Enable UEBA in Azure Sentinel, link Entra ID, and build baseline profiles to detect unusual user and entity behavior; create and promote custom anomaly rules into production.

  • KQL Intro4:06

    Explore basic KQL queries in Azure Sentinel logs to pull security incidents from the last 48 hours, then summarize by classification and render as bar or pie charts.

  • How to Delete a Sentinel Workspace0:44

    Learn how to delete a Microsoft Sentinel workspace in this beginners hands-on training module efficiently.

  • Course Completed0:33

    Complete the basic Azure Sentinel training to gain a foundational understanding and build on your new knowledge for future courses.

Requirements

  • Free Azure Subscription
  • Basic Understanding of Microsoft Azure Cloud
  • Basic Understanding of Cyber Security

Description

This Microsoft Sentinel Hands-on course is setup with a completely FREE Microsoft Lab training Lab Solution.  This course is designed for beginners to get you up and running with Azure Sentinel. The course covers everything from setting up  the Azure Training Solutions Lab account to basic management of the platform with live-hands on demonstrations.

Throughout this course, you will learn how to create and manage Microsoft Sentinel, including the creation of log analytics workspace. You will also explore how to work with incidents and workbooks, as well as how to use the platform's analytics rules, and data connectors to detect and respond to potential threats.

The course also includes an overview of basic Cyber Security Overview,  entity behavior analytics, threat intelligence and management, playbooks, Scheduled Analytic Rules, Data, Connectors, Alerts, Anomaly Detection, Workspaces, Deployment, Microsoft Sentinel roles and permissions.

The course features various hands on labs to get you up and running wit Azure Sentinel that will help you to better understand how to use the platform. You will learn how to create a Pulse-Dive user account (API-TAXII),  analytics rules, investigate incidents, hunt for threats, and more.

Join me on this journey to get hands on experience in Azure with Microsoft Sentinel and level up in your career!

Who this course is for:

  • Have you been tasked with setting up Microsoft Sentinel in your environment?
  • Are you looking to become proficient in Microsoft Sentinel?
  • Cybersecurity Engineer, Cybersecurity Analyst, Security Engineer, System Administrator, Cloud Engineer
  • Anyone responsible for managing and maintaining the security of an organization