
Develop practical skills in microsoft sentinel for SC 200 by exploring cloud-native siem concepts, detection and response through hands-on exercises based on publicly available resources and official microsoft documentation.
Explore the course outline for Microsoft Sentinel, covering architecture, environment setup, data integration, analytics, threat intel, incident response, threat hunting, and workbook data retention.
Microsoft Sentinel is a cloud-native siem that collects data from diverse sources to detect and investigate threats with built-in machine learning, then automates response via playbooks and Azure Logic Apps.
Understand the architecture of sentinel, including data connectors, a log analytics workspace, Kusto query language, and built-in workbooks for threat hunting, incident management, and threat intelligence.
Learn prerequisites for setting up Sentinel, including an Azure subscription, a subscription ID, and contributor or owner access to create a log analytics workspace on the resource group or subscription.
Create a personal Azure portal account on portal.azure.com, start the free trial, and complete verification with your details to access Azure services before charges begin after the 30-day trial.
Set up Microsoft Sentinel by creating a resource group and a log analytics workspace, deploy the Sentinel workspace, and install the training lab solution with a 31 days free trial.
Take a guided tour of the Microsoft Sentinel dashboard, exploring the new and old overviews, incidents, alerts, data connectors, analytics, logs, hunting, notebooks, and automation features.
Create a new user in the Azure portal, assign the security admin role, and grant access on the Sentinel resource group and Log Analytics workspace using role-based access control.
Assign and remove roles in microsoft sentinel to grant reader access at the resource group and workspace levels, showing how security admins control incidents and hunting permissions.
Explore content hub and data connectors in azure sentinel; install log4j2 solution with analytics rules, hunting queries, watch list, and playbooks, then see how connectors link sentinel to log sources.
Install the Azure activity data connector in Microsoft Sentinel, configure diagnostic settings to send logs to a Central India Log Analytics workspace, and verify connectivity with a test resource group.
Install and connect Microsoft Defender XDR to Microsoft Sentinel, enable Azure Activity Logs, configure data connectors and analytics rules, and explore Defender for Cloud options and licensing notes.
Plan and enable VM logs by setting up four labs (two Windows, two Linux), deploy agents and data collection rules, and enable logs across multiple VMs in one click.
Create two Azure virtual machines (Windows and Linux) within a resource group, selecting size, standard HDD or premium SSD, and spot discount, then configure Linux SSH keys.
Create a data collection rule in log analytics to collect windows event logs and linux syslog from the VMs and route to the Sentinel workspace.
Enable Linux VM logs in Sentinel by configuring the data collection rule and Linux log source, then verify logs and their severity in the Sentinel logs.
Discover KQL basics for querying log analytics in Microsoft Sentinel, and learn to run, save, share, and export queries, including using threat intelligence indicators and security events tables.
Enable analytics rules in Microsoft Sentinel by following a step by step guide in the Content Hub, choosing Azure Activity analytics rules, configuring logic, scheduling, and alerts.
Create a custom analytics rule in Microsoft Sentinel by configuring a scheduled query rule, writing a syslog-based query to detect root access, and saving to generate alerts and incidents.
Learn how threat intelligence powers Microsoft Sentinel by using threat indicators or IOCs, sources like open CTIs and MISP, and how to upload or bulk import indicators via data connectors.
Install the threat intelligence content hub in Microsoft Sentinel, then enable the data connectors and analytics rules. Explore Defender threat intelligence and configure connectors to ingest indicators and log sources.
See how Defender-based threat intelligence indicators grow over time, configure a threat intelligence source, and import indicators with a template, while previewing 38 analytics rules and import errors.
Demonstrates importing bulk indicators from JSON and CSV templates, naming sources, and using manage imports to verify JSON is fully imported and CSV appears after refresh.
Add a single IOC in threat intelligence by using the add new option, detailing a domain, malware website tag, confidence, time window, and kill chain phase.
Explore how Microsoft Sentinel uses kql kusto query language to search logs, understand common and defender xdr tables, and locate table names in log analytics to support investigations.
Identify, investigate, and respond to security incidents to minimize impact and restore operations quickly. Master the incident management cycle—identify, respond, resolve, and learn—plus ownership, monitoring, tracking, and communication.
Investigate high-severity incidents in Microsoft Sentinel from scratch, triage alerts, research Solorigate indicators, and block malicious domains and IPs while updating threat intelligence for leadership.
Investigate medium severity incidents in Microsoft Sentinel by following SOP-driven workflows, analyzing events and host IPs, and tracing root-user activity, including suspicious inbox rules and compromised email indicators.
Investigate low severity incidents by reviewing full details, examining IPs and events in the timeline, and confirming actions with IAM engineers on account disablement by an administrator.
Create automation rules in Microsoft Sentinel to automatically close incidents when created, using conditions on incident provider and analytics tool name, with actions like change status and run the playbook.
Explore threat hunting in Microsoft Sentinel within the SOC workflow, using hypothesis-driven queries, validate findings against data, and take action; leverage new hunt options, live streams, and bookmarks across logs.
Learn to run hunting queries in Microsoft Sentinel and create a new hunting rule for double file extension using regex, including query design and entity mapping.
Learn how Microsoft Sentinel enables security orchestration, automation and response (SOAR) to automate recurring enrichment, remediation, and automatically close benign-positive incidents using automation rules.
Create and automate incident rules in Microsoft Sentinel using soar, set triggers on creation, apply conditions, run playbooks, and assign owners to streamline triage.
Welcome to the comprehensive Microsoft Sentinel (formerly Azure Sentinel) course, meticulously designed to equip IT professionals with the skills and knowledge needed to leverage the full potential of the Microsoft Sentinel platform for robust threat detection and response. This course offers FREE access to hands-on labs, ensuring you gain practical, real-world experience.
What You'll Learn:-
Getting Started with Microsoft Sentinel
Account Setup: Learn how to create a FREE Azure account and set up Microsoft Sentinel from scratch.
Initial Configuration: Understand the process of setting up and managing your Log Analytics Workspace, the cornerstone of Microsoft Sentinel.
Deep Dive into Log Analytics and KQL
Log Analysis with KQL: Master the Kusto Query Language (KQL) for powerful log analysis to uncover critical insights.
Creating Queries: Develop custom queries to filter and analyze log data effectively.
Data Connectors
Integration: Learn to connect various data sources to Microsoft Sentinel, ensuring comprehensive visibility across your environment.
Connector Configuration: Configure and manage data connectors for seamless data ingestion.
Analytics Rule Creation
Development and Management: Develop and manage analytics rules to detect potential threats accurately and efficiently.
Enabling Rules: Enable and configure built-in rules and create custom rules tailored to your organization's specific needs.
Alerts Management: Learn how to manage and respond to alerts generated by analytics rules.
Incident Investigation and Management
Incident Handling: Learn best practices for investigating incidents, identifying root causes, and managing response workflows.
Incident Triage: Prioritize and triage incidents based on severity and potential impact.
Response Strategies: Develop effective response strategies to mitigate threats and minimize impact.
Threat Hunting
Proactive Hunting: Engage in proactive threat hunting to identify and mitigate potential threats before they cause harm.
Hunting Queries: Develop and execute hunting queries to discover hidden threats.
Threat Hunting Techniques: Learn various threat hunting techniques and methodologies to stay ahead of adversaries.
Workbooks
Visualization: Create and manage insightful workbooks for effective data visualization and analysis.
Custom Dashboards: Build custom dashboards to monitor and report on security metrics.
Sharing and Collaboration: Learn how to share workbooks and collaborate with team members.
Playbooks
Automation with Playbooks: Implement sophisticated automation strategies using playbooks to streamline threat response and reduce manual intervention.
Playbook Development: Create and manage playbooks for automated incident response.
Integration with Logic Apps: Leverage Azure Logic Apps to enhance playbook functionality.
SOAR and Automation
SOAR Capabilities: Utilize Security Orchestration, Automation, and Response (SOAR) capabilities to automate repetitive tasks and improve incident response efficiency.
Automated Remediation: Implement automated remediation actions to swiftly address detected threats.
Workflow Automation: Design and manage automated workflows to enhance operational efficiency.
Watchlists
Management: Create and manage watchlists to filter and prioritize critical alerts.
Use Cases: Understand various use cases for watchlists in threat detection and response.
Dynamic Watchlists: Learn how to create and update dynamic watchlists based on real-time data.
Leveraging User and Entity Behavior Analytics (UEBA)
UEBA: Utilize user and entity behavior analytics to identify anomalous activities and enhance security monitoring.
Behavioral Insights: Gain insights into user and entity behaviors to detect potential insider threats.
Anomaly Detection: Implement anomaly detection techniques to identify unusual patterns and activities.
Enhancing Threat Intelligence Capabilities
Threat Intelligence Feeds: Register for and integrate threat intelligence feeds to stay ahead of emerging threats.
Using Threat Intelligence: Leverage threat intelligence within Microsoft Sentinel to improve detection and response efforts.
Custom Threat Intelligence: Create and manage custom threat intelligence indicators.
Practical Hands-On Labs
Real-World Scenarios: Engage in hands-on labs that simulate real-world scenarios, from creating analytics rules to investigating incidents and hunting for threats.
Advanced Functionalities: Explore advanced functionalities such as Jupyter Notebooks and Sentinel as Code to maximize the platform's capabilities.
Lab Exercises: Participate in lab exercises to reinforce learning and apply theoretical knowledge.
Comprehensive Overview of Roles and Permissions
Security Management: Understand the various roles and permissions in Microsoft Sentinel to manage access effectively and enhance overall security.
Role-Based Access Control (RBAC): Implement RBAC to ensure appropriate access controls.
Permission Management: Manage and assign permissions to users and groups based on their roles.
Why Choose This Course?
By the end of this course, you will have acquired hands-on experience and in-depth knowledge of Microsoft Sentinel, making you a proficient professional in the realm of cybersecurity. Whether your goal is to advance your career or bolster your organization's security posture, this course provides you with the essential tools and expertise.
Join Us!
Take the plunge into the world of Microsoft Sentinel and transform your cybersecurity skills. With a blend of practical labs, real-world scenarios, and expert guidance, this course is your pathway to mastering threat detection and response with Microsoft Sentinel.
Enroll now and embark on your journey to becoming a Microsoft Sentinel expert!