
Explore Microsoft Sentinel fundamentals and gain hands-on skills by building labs, creating detection rules, investigating incidents, and automating tasks to advance in cloud security and SOC roles.
Build a Microsoft Sentinel lab, connect data sources, and create analytics rules with Kusto to investigate incidents. Explore watchlists, dashboards, and automation for proactive threat detection and response.
Pavel, a cyber security consultant, guides you through building a Microsoft Sentinel lab and shares expertise in securing hybrid environments and cloud-based security with hands-on insights.
Learn how to create a resource group in azure to organize a complete microsoft sentinel deployment, including log analytics workspace, dashboards, and automations, and manage it under a single subscription.
Create a log analytics workspace to store log data for Microsoft Sentinel. Use the same subscription and region, and choose a valid name with letters or digits and hyphens.
Create hands-on labs to practice Microsoft Sentinel skills while navigating the shift to a unified security portal, moving between Azure and Defender portals as features migrate in 2026.
Explore the incidents tab in threat management to view detected security incidents with severity, status, and related entities, then learn how to create and investigate an incident.
Configure data connectors to ingest and normalize data into Sentinel, and set analytics rules that run periodically to detect threats, and build watchlists from external data for correlation.
Explore Microsoft Sentinel pricing, including 31 days of free data ingestion up to 10 GB per day, pay-as-you-go rates, data retention up to two years, archiving, and basic locks.
Link to Pricing Calculator
https://azure.microsoft.com/en-us/pricing/calculator/
Learn the principle of least privilege for Microsoft Sentinel by assigning roles such as reader, responder, contributor, logical operator, and logic app contributor in a portal demo.
Discover data connectors in Microsoft Sentinel, enabling easy integration of data sources—cloud providers like AWS and GCP, third-party solutions, and threat intelligence feeds—via predefined configurations and standard log formats.
Connect data connectors in Microsoft Sentinel, including Azure activity, to ingest subscription events and logs; the demo covers prerequisites, policy assignment, workspaces, remediation, and the content hub.
Compare native data connectors with Content Hub connectors in Microsoft Sentinel, a centralized hub for pre-built detection queries, workbooks, and third-party connectors that enhance parsing, enrichment, and collaboration.
Navigate to content hub in Microsoft Sentinel to explore data connectors and solutions. Install the training lab to populate data and learn threat intelligence.
Install must-have Microsoft Sentinel solutions in Content Hub, configure data connectors, and ingest logs and incidents by filtering for Microsoft support and selecting Microsoft Defender, Office 365, and Windows events.
Explore how threat intelligence ingests data into Microsoft Sentinel to enhance threat detection and investigation. Integrate third party feeds from vendors and open source intelligence to strengthen security posture.
Enable threat intelligence in Azure Sentinel by adding a data connector and providing proxy server information, set friendly name, API route, collection ID, username, password, and API key, then wait.
Access workspace settings to view usage and costs, then set data retention to 90 days, apply per-table policies, and enable daily caps for on-prem and azure activity logs.
Explore analytics rules in Microsoft Sentinel for automated threat detection from collected data. Learn how Kusto Query Language and machine learning analyze security events, network traffic, and user behavior.
Explore the analytics rules dashboard in Microsoft Sentinel, create schedule and near real time queries with data sources, query language, and filters, and manage incidents, templates, and anomalies.
Examine a Microsoft Sentinel analytics rule that flags IP addresses with failed sign-ins to disabled accounts, where a successful sign-in occurs elsewhere, using Kusto query language and 557 error code.
Learn how to create an analytics rule from a template in Microsoft Sentinel, selecting Azure activity data, configuring the query, enrichment, scheduling, incident and alert grouping, and optional automation.
Leverage the fusion correlation engine to detect multi-stage attacks with machine learning across signals from multiple products, producing low volume, high fidelity incidents in Microsoft Sentinel.
Identify, analyze, and respond to security incidents using Microsoft Sentinel’s unified incident management to triage and investigate threats, with manual or analytics rule-driven incident creation.
Review incident information for a new medium-severity incident in Azure Sentinel, check evidence and entities, then assign an owner, use tags, and start the investigation.
Demonstrates incident conclusion steps in Microsoft Sentinel: zoom, pan, remove alerts, investigate, and close incidents by selecting a classification such as true positive, benign positive, suspicious, or false positive.
Learn how threat hunting in Microsoft Sentinel detects threats in logs, events, and alerts by analyzing patterns and indicators of compromise with behavioral analytics, machine learning, and threat intelligence integration.
Investigate the SolarWinds Solorigate incident by examining the backdoor in SolarWinds Orion, analyzing IOCs, and correlating DNS queries to identify affected devices and pursue threat hunting.
Learn how to hunt for infected hosts in Microsoft Sentinel by running a Solorigate query, bookmarking findings, linking them to incidents, and adding threat intelligence for future defense.
Explore the hunting dashboard in Microsoft Sentinel: create and filter queries, map entities to tactics, view live stream and bookmarks, and monitor active queries.
Learn how watch lists in Microsoft Sentinel enable proactive threat monitoring by using indicators of compromise, such as IP addresses, domains, and file hashes, to tailor security operations.
Create and manage a watchlist in microsoft sentinel by uploading a csv of ip addresses, configuring a search key, and applying rules to monitor activity.
Learn to update watchlists in Microsoft Sentinel, including item and bulk updates, add or delete IP addresses, and view logs with SQL queries to inform analytics-driven incidents.
Create and adjust an analytics rule in Microsoft Sentinel using a watchlist to whitelist IP addresses, test with current data, and save the changes for effective incident management.
Create and customize workbooks in Microsoft Sentinel to visualize security log data with charts and metrics, monitor real-time data, and track incidents, detections, and response times.
Navigate the Azure portal to create and customize workbooks for Sentinel, using templates or from scratch, add metrics and queries, and review ingestion and cost details across resources.
Explore five automation options in Sentinel, from simple automation rules to playbooks triggered by incidents, alerts, or entities, and learn to tailor automated workflows for incident response.
Demonstrate creating automation rules from the incident dashboard in Microsoft Sentinel, with pre-populated conditions, a trigger on incident creation, and a one-day expiration.
Explore the playbook designer in Microsoft Sentinel, configure a trigger-driven automation with Logic App designer, authorize API connections, enable manage identity, and set automated responses for incidents.
Demonstrate building a ChatGPT-driven playbook from scratch in Azure cloud to automate incident enrichment in Microsoft Sentinel using an incident trigger and a GPT-3 prompt.
Demo: assign the Microsoft Sentinel responder role to a playbook, enabling it to create incidents, add comments, and run automation workflows with least privilege.
Create an automation rule in Microsoft Sentinel to enrich incidents with a ChatGPT playbook when an incident is created, including conditions, actions, rule expiration, and execution order.
Demonstrates manual incident creation in Microsoft Sentinel and tests automation with a ChatGPT playbook for real-time incident enrichment in a SIEM environment.
Explore an alternative option for ChatGPT integration with Microsoft Sentinel by deploying OpenAI technologies inside Azure to keep data secure and train OpenAI with your own data for personalized recommendations.
This Microsoft Sentinel (formerly known as Azure Sentinel) course with completely FREE Lab is designed to help IT professionals understand and utilize the Microsoft Sentinel platform for threat detection and response. The course covers everything from setting up a FREE Azure account to managing and automating the platform with hands on demonstration.
Throughout this course, you will learn how to create and manage Microsoft Sentinel, including the creation of log analytics workspace. You will also explore how to work with incidents and workbooks, as well as how to use the platform's analytics rules, watchlists, and connectors to detect and respond to potential threats.
The course also includes an overview of user and entity behavior analytics, playbook settings, health monitoring as well as a discussion of Microsoft Sentinel roles and permissions.
You will also learn about threat intelligence, including how to register for threat intelligence feeds and enable threat intelligence in Microsoft Sentinel.
The course features various hands on labs that will help you to better understand how to use the platform. You will learn how to create analytics rules, investigate incidents, hunt for threats, and implement automation. Additionally, you will explore additional functionalities as Jupyter Notebooks or Sentinel as Code to make the platform even more effective.
Join me on this journey to get hands on experience in Azure with Microsoft Sentinel and level up in your career!