
Chart a Microsoft cybersecurity career from AZ 900 and SC 900 foundations through AZ 500 and SC 200 to SC 100, with hands-on labs and specialization like SC 300/SC 400.
Explore how the security operations center protects confidentiality, integrity, and availability and delivers rapid incident response through threat hunting, vulnerability management, malware analysis, and forensics with Microsoft 365 Defender.
Embark on the SC-200 certification journey to become a SOC analyst, mastering Microsoft Sentinel, Defender for Cloud, and Microsoft 365 Defender, while sharpening collaboration and soft skills.
Review the May 2022 update for SC-200, noting rebranding from cloud app security to Defender for Cloud Apps (MCAS) and that modules two and three remain unchanged.
listen to an upbeat music interlude in sc-200: microsoft security operations analyst, titled reviews - thank you.
Explore the 2024 cyber security forecast for the SC-200 Microsoft security operations analyst course, outlining key implications for security operations.
Define security threats and common threats, explain the evolving threat landscape across emails, identities, endpoints, and applications, and show how Microsoft 365 Defender protects users, devices, and data.
Explore how Microsoft 365 Defender enables cross-domain threat detection and response, correlating signals from identities, endpoints, and apps into incidents, with autohealing and advanced hunting.
Learn Microsoft 365 Defender Suite protects endpoints, emails, identities, and cloud apps with Defender for Endpoint, Defender for Office 365, Defender for Identity, Azure Active Directory, and Cloud App Security.
Explore how attackers perform reconnaissance, credential theft, and privilege escalation, then trace patient zero and long undetected breaches along a cybersecurity incident timeline.
Engage in a guided, interactive Microsoft 365 Defender demonstration to detect security risks, investigate attacks, and prevent harmful activity, while exploring the Defender Portal’s alerts and navigation.
Develop an investigator mindset as a security operations analyst and manage incidents across Defender for Endpoint, Defender for Identity, and Defender for Office 365 in the Microsoft 365 Defender portal.
Create your lab with a free Microsoft 365 Defender trial to practice threat hunting, incident management, and advanced hunting as you train for security operations analyst work in Defender portal.
Explore the Microsoft 365 Defender Portal as a unified security operations hub. Learn to investigate alerts, manage incidents, configure policies, and leverage secure score and threat tracker across Defender products.
Microsoft 365 Defender aggregates related alerts into incidents to reveal attack timeline, scope, and affected devices, users, and mailboxes; automate investigation and remediation, and prioritize from the incident portal.
Microsoft 365 Defender correlates and aggregates data from cloud apps, endpoints, and identities, triggers alerts, and surfaces incidents for analysis, with a 30-day default retention.
Use Tor browser to simulate anomalous login activity, observe IP location changes, and trigger Microsoft Defender incidents for hands-on security operations labs.
Learn to manage incidents in the Defender portal, view incident details, link related records, assign incidents or alerts, and reclassify alerts to refine incident naming.
Explore how alerts drive incidents in Microsoft 365 Defender, navigate the alert queue, and filter by severity, status, sources, and assets to manage and investigate alerts.
Explore MITRE attack framework and the cyber kill chain, and learn how Microsoft 365 Defender aligns with them to investigate incidents using alerts, assets, and automated investigations.
Explore advanced hunting, a query-based threat hunting tool that inspects 30 days of raw event and entity data from static and dynamic sources, refreshed every 15 minutes and consolidated daily.
Explore the advanced hunting schema in Microsoft 365 Defender, learn to navigate tables and columns, use view references and sample queries in Kusto Language, and prepare for custom detection rules.
Learn the basics of the Kusto query language for security operations, including where, summarize, order by, join, count, top, limit, project, and extend, with Azure Active Directory sign-in events.
Microsoft threat experts provide proactive threat hunting and monitoring to identify risks, analyze alerts, and deliver fast context for SOC response within the Defender Security Center.
Explore the capabilities of Microsoft Defender for Office 365 and Defender for Endpoint, learn to simulate attacks within your network, and remediate risks in your environment.
Microsoft Defender for Office 365 provides cloud-based email filtering that protects against malware and phishing, with rich reporting, URL tracing, automation for investigation and remediation, and user training via simulations.
Discover Microsoft Defender for Office 365's threat tracker, threat explorer, and attack simulator to anticipate threats, analyze real-time data, and simulate spear phishing, credential harvesting, and password spray.
Learn to safeguard your organization with Defender for Office 365 by configuring threat policies, anti phishing rules, impersonation protection, and responding to attacks through policy driven actions and attack simulation.
Explore how the Microsoft 365 Defender portal generates email and collaboration reports, including mailflow status, spoof detection, and URL protection, with daywise views and investigation-ready details, plus favorites for access.
Explore attack simulation in Microsoft 365 Defender to test credential harvest, malware attachments, and drive-by URLs; train users and generate actionable SOC reports.
Explore the components and capabilities of Microsoft Defender for Identity, configure sensors, and remediate risks while learning how it identifies suspicious user activity and advanced attacks along the kill chain.
Discover how Microsoft Defender for Identity uses cloud and on-premises signals, learning-based analytics, insider actions, and user behavior to monitor, detect threats, protect credentials, and provide a clear incident timeline.
Create a Defender for Identity instance in the Defender portal, meet prerequisites (EMS E5 license and global administrator), then install sensors on domain controllers and connect Active Directory.
install the azure advanced threat protection sensor on a domain controller by selecting language and entering the access key, then verify in the azure portal and set update controls.
Demonstrate attacker techniques on domain joined Windows 10 device and controller, enumerate users and groups with net commands, harvest admin credentials, and detect activity using Mimikatz, Microsoft Defender, and MCAs.
Investigate alerts in Microsoft 365 Defender by tracing timelines, device and user activity, then use advanced hunting in the Kusto platform to uncover threats and risk.
Deploy Microsoft Defender for Identity sensors on domain controllers to capture and parse event logs and network traffic, then send data to the cloud service and resolve Active Directory entities.
Protect your identities and applications with Azure AD Identity Protection, which provides advanced detection and remediation of identity-based risks across Azure Active Directory.
Use Azure Active Directory Identity Protection to detect, investigate, and remediate identity-based risks, distinguishing user risks from sign-in risks (unusual behavior, leaked credentials, unusual locations, malware IP addresses).
Configure azure active directory premium p2 identity protection to monitor risky sign-ins and detections, and implement user risk and sign-in risk policies with MFA and conditional access for high-risk users.
Discover cloud app security as a cloud access security broker, gain visibility and control over data travel, and learn cloud discovery plus conditional access app control policies.
Explore cloud app security, using cloud access security broker concepts to control shadow IT, protect data with DLP, detect threats via UEBA, and assess compliance across Microsoft and third-party services.
Protect your organization's data with conditional access app controls that enforce access and session policies, integrate with Azure Active Directory and cloud app security, and prevent data exfiltration.
Explore how information protection uses data discovery, classifying sensitive information, data protection, and monitoring and reporting with cloud app security and Azure Information Protection.
Enable auditing for insider risk management by turning on audit logs in compliance.microsoft.com, then start recording user and admin activity; expect about 60 minutes for the change to take effect.
Explore four phases of Microsoft Cloud App Security—discover data, classify sensitive information with labels, apply real-time file policies, and monitor via the dashboard; includes hands-on lab activities.
Learn the four cloud app security phases—discovery, classifying sensitive information, protecting data, and monitoring—using Microsoft Defender for Cloud Apps to configure policies, sensitivity labels, and data loss prevention alerts.
Respond to data loss prevention alerts and understand DLP components in Microsoft 365. Use these alerts to identify the full scope of incidents in the Compliance Center and MCAS portal.
Identify sensitive information across Exchange Online, SharePoint Online, OneDrive for Business, and Teams with DLP alerts and policies; monitor, protect, and educate users via pop-ups, alerts, and training simulations.
Create and customize DLP policies in the Microsoft 365 compliance portal, selecting HIPAA configurations for PII and medical terms, configure protection actions, and monitor alerts.
Explore insider risk management in microsoft 365, using defender to detect, investigate, and contain risky activities, with built-in templates, prerequisites for policies, and actions on cases.
Explore insider risk management with Microsoft 365, using Graph connectors to surface real-time signals such as file activity, sentiment, and resignation dates to detect and mitigate insider threats.
Understand insider and external risks in a modern workplace, including brute-force and phishing attacks, and how employee misconduct such as data leaks or theft drives financial loss and brand damage.
Manage insider risk with Microsoft 365 Defender by creating workflows, policies, and alerts; triage, investigate, and take action on insider risk cases.
Assign precise insider risk management permissions in the compliance portal by selecting six roles: insider risk management, admins, investigators, analysts, auditors, and approvers, to control alerts, cases, and templates.
Master module one by reviewing threat protection in Microsoft 365, incident mitigation with 365 Defender, Defender for Office 365, and Azure Active Directory Identity Protection with data loss prevention alerts.
Your reviews matter in the sc-200 Microsoft security operations analyst course, presented with upbeat music for an engaging overview.
Mitigate threats with Microsoft Defender for Endpoint by deploying the environment and protecting Windows 10. Learn investigations, evidence and entities investigations, device actions, automation, alerts, and threat and vulnerability management.
Discover Defender for Endpoint features such as threat and vulnerability management, attack surface reduction, advanced protection with machine learning, and endpoint detection and response for automated threat remediation.
Explore Defender for Endpoint terminology, including devices (endpoints), evidence and forensics data, alerts and incident grouping, and automated investigations powered by Microsoft detection rules.
Onboard Windows devices to Microsoft Defender for Endpoint using role-based access control, onboarding scripts, and device groups; run simulations to generate incidents and learn incident management in Defender.
Learn to reduce the Windows 10 attack surface without sacrificing productivity, while writing and configuring attack surface reduction rules for Defender for Endpoint as a soc analyst.
Reduce the attack surface by limiting entry points and hardening targets. Use components like application control, exploit protection, network protection, and container isolation to stop malware and regulate traffic.
Create attack surface reduction rules in Microsoft Endpoint Manager for Windows 10 and later, configuring block, audit, or disabled modes, exclusions, and scoped assignments.
Explore the device inventory in Microsoft 365 Defender for Endpoint, viewing onboarded devices, risk and exposure levels, operating system details, and downloadable data in Excel or CSV for remediation.
Explore Windows 10 device investigations from the inventory to the device page, analyzing active alerts, security assessments, timelines, and vulnerability management for effective incident response.
Defender for Endpoint uses behavioral blocking to identify and stop threats by analyzing behaviors and process trees, containing them before data exfiltration, and correlating alerts into EDR incidents.
Client behavioral blocking detects suspicious actions and automatically blocks and remediates them. Defender Antivirus uses protection service and ML to classify artifacts and alert in Defender Security Center, preventing attacks.
Discover how EDR in block mode automatically blocks and remediates malicious artifacts detected post-breach. Learn its integration with threat management and how recommendations prompt enabling block mode.
Enable EDR in block mode to block malicious artifacts and protect devices, following recommendations from device inventory and security center settings, including remediation options and Defender Antivirus cloud delivered protection.
Navigate device inventory to apply containment actions (isolate device, restrict app execution, run antivirus) and investigation actions (initiate automated investigation, collect investigation package, initiate live response) using Defender for Endpoint.
Explore live response workflows in Microsoft security operations. Initiate remote access to a Windows device, run commands, analyze processes, remediate threats, and review command history for real-time containment.
Learn to perform evidence and entities investigations in Microsoft Defender for Endpoint by gathering forensics artifacts and analyzing changes to files, IP addresses, domains, and user accounts.
Explore how to investigate a user in Microsoft 365 Defender, analyzing alerts, timelines, and MCAS activity to detect compromises and assess user exposure, including suspending the user or requiring reauthentication.
Configure automated investigation and remediation in Microsoft Defender for Endpoint. Enable block mode, allow or block files, and automatic alert resolution, with considerations for behavioral blocking and risk impact.
Enable and configure automation uploads in Azure 365 Defender to automatically send file content for automated investigation, including allowed extensions and memory content analysis.
Automation folder exclusion lets you specify folders, extensions, and file names to skip during automated investigations, including folder and subfolder scope, to prevent attackers from hiding exploits.
Explore file level investigations in Microsoft 365 Defender by examining a file like cmd.exe, reviewing alerts, deep analysis, and artifacts to assess maliciousness and breach scope.
Understand device group remediation automation levels, from full remediation with automatic actions and action center visibility and undo, to semi automation requiring approvals for core, non-temp, or all folders.
Block risky devices by integrating Microsoft Defender for Endpoint with Intune and Azure Active Directory, then create Windows 10 compliance policies and a conditional access policy to enforce device compliance.
Configure alerts and detections in Microsoft Defender for Endpoint, manage indicators, and apply detection rules while exploring advanced features like live response, unsigned script execution, and custom network indicators.
Configure advanced features in Defender for Endpoint, including live response sessions, unsigned script execution, and custom network indicators, via the Microsoft 365 Defender portal.
Configure email notifications in Defender for Endpoint for specified recipients and alerts, using a rule name including organization and tenant, set device scope, test email, and create suppression rules.
Identify and manage indicators of compromise using Microsoft 365 Defender to block threats through file hashes, IPs, URLs, and certificates, with configurable actions, expiry, and scope.
Explore the Threat and Vulnerability Management dashboard to learn its functionalities, identify device vulnerabilities with Microsoft Defender for Endpoint, remediate dashboard-reported weaknesses, and track emerging threats.
The threat and vulnerability management dashboard reduces organizational exposure by identifying, assessing, and remediating endpoint weaknesses using real-time device and software data, with threat analytics.
Learn to mitigate threats with Microsoft Defender for Endpoint: deploy and onboard devices, automate investigations, isolate devices, configure alerts, and explore threat and vulnerability management with analytics.
Discover why your reviews matter in the Microsoft security operations analyst track through the reviews matter lecture.
Defend cloud workloads across Azure and non-Azure resources by enabling Azure Defender, securing workloads such as databases, storage, virtual machines, and networks, and using Azure Security Center features.
Explore how Azure Security Center provides unified infrastructure security management to harden networks and secure workloads across Azure, on-premises, and other clouds against rapid changes and sophisticated attacks.
Explore how Microsoft Defender for Cloud provides continuous assessment, vulnerability remediation, network map visualization, and threat protection across Azure resources, with native Defender for Endpoint integration and just-in-time access.
Explore how Azure Defender for Cloud provides a secure score across Azure and non-Azure resources, tracks regulatory compliance, and guides onboarding of non-Azure servers via Log Analytics and remediation workflows.
Explore cloud security pillars with CSPM and CWP in Azure Defender for Cloud, highlighting secure score, misconfigurations, asset inventory, remediation, and built-in policy compliance.
Protects Azure resources with Defender for Cloud, including servers, app services, SQL databases, storage, Kubernetes, container registries, Key Vault, DNS, and connects hybrid workloads to log analytics workspace for protection.
Azure Defender for servers unifies Defender for Cloud with Defender for Endpoint to deliver integrated EDR, vulnerability scanning, just-in-time VM access, file integrity monitoring, and adaptive network and application controls.
Protect app services with Azure Defender for App Services, a managed platform that uses signals and internal logs to detect distributed attacks on web apps and APIs with seamless integration.
Create an Azure app service and enable Defender for cloud integration by default, selecting PHP in central US. View all Defender recommendations to guide security and plan storage integration next.
Azure Defender for Storage provides cloud-native, one-click security protecting data in blobs, files, and data lakes, with Microsoft Threat Intelligence-powered detections and automated malware responses.
Create an SQL database in the Azure portal and integrate with Defender for Cloud, enabling vulnerability assessment, advanced threat protection, and alerts for SQL injection and anomalous database activity.
Explore how Azure Defender for Key Vault provides advanced threat protection for encryption keys and secrets, with alerts and remediation recommendations visible in Defender for Cloud and M365 Defender.
Azure Defender for DNS continuously monitors DNS queries and uses advanced analytics to detect tunneling, malware, phishing, and malicious activity, with DNS protection on by default in Defender for Cloud.
Explore Azure Defender for Kubernetes, a cloud-native security offering that delivers environment hardening, workload protection, and runtime protection for containerized apps on AKS.
Azure Defender for Cloud provides cloud-native vulnerability assessment for container registries by integrating with Qualys to scan images on push, pull, and import, delivering actionable remediation guidance.
Connect Azure assets to Azure Defender and learn automatic and manual provisioning methods to ensure Defender for Cloud automatically protects all Azure resources.
Explore the asset inventory in Microsoft Defender for Cloud, view resource posture, receive vulnerability recommendations, and take action to remediate across subscriptions using Azure Resource Graph and KQL queries.
Enable auto provisioning in azure defender for cloud to install required extensions and agents, including log analytics and security extensions, across existing and new resources via a deploy-if-not-exist policy.
Send VM logs to a log analytics workspace used by Defender for Cloud, choose existing and new VMs, and set detail levels from minimal to all events.
Learn manual provisioning for log analytics by installing Windows and Linux agents and configuring the workspace ID and the primary key to connect to an Azure Defender log analytics workspace.
Onboard non Azure devices to Defender for Cloud using Azure ARC or the Defender portal with the Log Analytics Agent, including AWS, Google, and on premises Windows and Linux.
Onboard a Google Cloud Platform Windows server to Azure Arc, install the Azure Arc agent via script, enable TLS 1.2, register Microsoft.HybridCompute, and onboard to Microsoft Defender for Cloud.
Connect AWS to Defender for Cloud via the Azure portal using the AWS connector. Deploy the CloudFormation template to provision resources and enable log analytics.
Explore remediation of security alerts in Microsoft Defender for Cloud and prevent future attacks. Learn to automatically respond to container alerts with defined remediation steps as a soc analyst.
Learn how SOC analysts defend the enterprise perimeter against data theft by organized attackers and how automation with Defender tools enables rapid alerts triage, detection, and response.
Learn how Defender for Cloud generates and prioritizes security alerts, provides remediation recommendations, and uses Cloud Smart Alert Correlation to fuse related alerts into a single incident.
Discover how Defender for Cloud uses integrated threat intelligence, behavioral analytics, and anomaly detection—powered by machine learning—to detect threats across Azure resources and networks while reducing false alerts.
Defender for Cloud assigns alert severities: high, medium, low, and informational, to prioritize responses, with high signaling probable compromise and urgent investigation, driven by ML and anomaly-based detections.
Continuously monitor your infrastructure and threat landscape using threat intelligence monitoring, signal sharing, and detection tuning to refine machine learning algorithms through true positives and false positives.
Explore how Mitre attack tactics map to the kill chain, from pre-attack to impact, including initial access, persistence, privilege escalation, defense evasion, credential access, and discovery.
Learn to navigate the Azure portal and Defender for Cloud alerts, view full alert details for a Kubernetes cluster, and apply manual or automated remediation to mitigate threats.
Automate security responses in Defender for Cloud with workflow automation that triggers on alerts or recommendations. Use logic apps to implement remediation actions, such as AWS WAF Web ACL associations.
Learn to reduce alert noise by creating suppression rules for false positives, enabling selective dismissal across subscriptions, with custom and all filtering options and viewing dismissed alerts.
Mitigate threats with Microsoft Defender for Cloud, plan and connect Azure and non-Azure assets, remediate security alerts, and preview module four on Kusto Query Language.
Learn to create queries in Microsoft Sentinel using KQL to analyze log data, build analytics and workbooks, and perform threat hunting through hands-on labs.
Learn KQL, a read-only, SQL-like query language, to process data and generate results with pipes, filters, and a summarize count across databases, tables, and columns.
Practice Kusto queries in a no-charge log analytics lab accessible via aka.ms/lademo with an Azure account. Learn to run queries, adjust time range, and view results and charts.
Declare variables with let to filter security events by timeoffset of 7 days using ago and where. Set discardeventid and compare time ranges, noting case sensitive behavior for accurate results.
Learn to use the search operator for multi-table, multi-column searches and the where operator for precise filtering, with examples using time filters and event IDs such as 4624 and 4625.
Extend the operator adds a new severity order column. Use a case expression to map alert severity (high, medium, low, informational) to numbers (3, 2, 1, 0) in KQL.
Learn to use the order by operator to sort SecurityEvent query results over the last seven days, extend to map account types to object types, and apply descending order.
Explore the project operator in KQL, learning to include or exclude columns, rename and reorder outputs, using SecurityEvent as a practical example.
Learn to use KQL to summarize security events, count occurrences, and apply dcount for distinct assets, counting processes, computers, and IP addresses across event IDs 4688 and 4624.
Learn how arg_max and arg_min identify the latest and oldest security events for a given computer, using time generated and last seven days.
Render operator creates visualizations from query results using area, bar, column, pie, scatter, and time charts to present data such as account counts and IP activity.
Master the bin function to bucket security logs into time intervals (1D, 2D, 3D), perform distinct counts on SigninLogs identities over 90 days, and visualize results with render time charts.
Use the union operator to merge multiple tables, such as SecurityEvent and SecurityAlert, returning all rows. Pipe data, then summarize by type to count events, illustrating wildcard unions like Security*.
Learn to create Kusto queries using let, where, search, extend, order by, and project. Merge data with union to analyze data, build workbooks, and hunt in Microsoft Sentinel.
Explore how a siem solution collects, analyzes, and queries logs across enterprise systems for correlation, anomaly detection, alerts, and incident management using log management, visualizations, and Kusto query language.
Explore Microsoft Sentinel, a cloud-native SIEM in Azure that ingests data from AWS, Azure, Google Cloud, and on-prem sources for end-to-end security operations with built-in machine learning and Playbooks.
Explore the core components of Microsoft Sentinel, including data connectors, log retention, workbooks, analytics alerts, threat hunting, incidents and investigations, and automation playbooks.
Use data connectors to ingest data into Microsoft Sentinel from diverse sources, including syslog, cef, common event format, TAXII for threat intelligence, cloud services, and on-premises data.
Connect data sources to trigger automatic ingestion in Microsoft Sentinel, store data in Log Analytics, and use KQL to query and manage log retention for Azure Sentinel, and explore workbooks.
Visualize Microsoft Sentinel data with Workbooks, using built-in dashboards powered by KQL queries, and build or edit custom Workbooks across Sentinel and Azure Monitor.
Explore proactive analytics alerts in Microsoft Sentinel to notify you of suspicious activity. Learn to use built-in, Microsoft proprietary machine learning alerts, and customize or schedule alerts from scratch.
Explore threat hunting in Azure Sentinel by using built-in and custom queries, and create your own queries; leverage Azure Notebooks for advanced hunting to search through your data.
Learn to manage security alerts in Microsoft Sentinel by creating incidents, changing status, assigning them to analysts, and adjusting priority, while visually investigating incidents through entity mapping and timeline.
Automate incident response with Microsoft Sentinel by building playbooks and SOAR workflows using Azure Logic Apps and runbooks to enhance analytics, investigations, and remediations for security operations.
Create a Log Analytics workspace, then add Microsoft Sentinel on top, selecting a dev resource group and a workspace named laws sentinel, with a 30-day free trial.
Explore role-based access controls in Azure Sentinel by assigning sentinel-specific reader, responder, and contributor roles from Log Analytics with permissions for incidents, workbooks, and data.
Onboard devices to Microsoft Sentinel using data connectors for Microsoft 365, Azure, and non-Azure sources. Learn about permissions, connector pages, CEF and syslog formats, vendor connectors, and dashboards and queries.
Onboard a Windows host to Microsoft Sentinel via the Security Events connector with Azure or non-Azure deployment, auto-deploy the MMA log analytics agent, and configure workspace details to stream events.
Onboard a Windows host to Sentinel, ingesting events with the legacy security event connector, then tailor streaming options and query the Log Analytics workspace with Crystal queries.
Create and manage Microsoft Sentinel watchlists to collect data for event correlation, searches, detection rules, and threat hunting; store them in the workspace for alert reduction via allow lists.
Create a Tor exit nodes watchlist in Microsoft Sentinel by uploading a csv with a header, using the watchlist wizard, and mapping the header, noting ingestion delays.
Learn to create a threat hunting query in Azure Sentinel using a watchlist, KQL scripting, and live stream alerts to detect Tor-based activity and monitor Azure resources in real time.
Watch hunting queries run in real time with Microsoft Sentinel livestream; add queries to livestream and simulate alerts using Tor Browser in an Azure portal lab on a virtual machine.
Capture Tor exit node traffic with Azure Sentinel, watch lists, and live streams to detect suspicious activity. Correlate activity logs with Log Analytics to identify culprits and investigate VM actions.
Create analytical rules to generate real-time alerts from indicators of attack, enabling detection of compromised accounts, suspicious user behavior, data exfiltration, insider threats, and threat hunting within Sentinel.
Explore fusion analytical rule type in Microsoft Sentinel, where fusion correlates alerts across products and uses machine learning to detect multi-stage attacks across identity, data exfiltration, and ransomware.
Configure security solutions connected to Microsoft Sentinel to automatically create incidents. Ingest alerts from MCAS, Defender for Identity, and Defender for Endpoint to support SIEM and XDR concepts.
Learn how Microsoft Sentinel's built-in machine learning behavior analytics rules detect suspicious activities, correlate signals, and reduce alert noise, with examples like anomalous ssh and rdp logins.
Explore analytical rule types in microsoft security operations: anomaly based, scheduled alerts, and near real time rules. Create rules from templates or with a wizard using kusto queries.
Create analytics rules from predefined templates in the Azure portal, auto-fill tactics and severity, configure the Kusto-based rule logic, incident alerts, and optional automated actions, then validate and provision.
Create custom analytics rules using scheduled query rules and KQL to detect Azure activity and virtual machines creation, with entity mapping, query scheduling, alert thresholds, and incident automation.
Manage analytical rules by editing, disabling, duplicating, or deleting them; the editing wizard preserves inputs and lets you attach automated responses or playbooks, while deletion is permanent.
Define cyber threat intelligence (cti) and indicators of compromise, including urls, file hashes, and ip addresses, and apply cti to alerts, hunting, and siem workflows in microsoft sentinel.
Create threat indicators in the azure portal by adding domain names, tagging them as malicious, and setting revoked status, then query the threat intelligence indicator table in log analytics.
Connect various logs to Microsoft Sentinel by configuring the Office 365 Connector, CEF format logs, and Syslog data, and learn how to integrate threat indicators and third party services.
Learn how the Microsoft 365 Defender connectors for endpoint, identity, Office 365, cloud apps, insider risk, and IoT feed raw data into Microsoft Sentinel, enabling selected Defender alerts in Sentinel.
Configure the Office 365 data connector in Microsoft Sentinel to ingest Office 365 activity logs, covering Exchange, SharePoint, and Teams, into the Office Activity table for security monitoring.
Onboard the Azure Active Directory connector to ingest audit logs and sign-in logs into Microsoft Sentinel, capturing sign-in activities, conditional access, application usage, legacy authentications, and authentication details.
Connect the Azure Active Directory Identity Protection data connector to Sentinel, enabling automatic incident creation from Identity Protection alerts and consolidating risk events, users, and vulnerabilities.
Connect Microsoft Defender for Office 365 to Sentinel to ingest email and URL threats using the data connector, tracking alerts like malicious URLs and phish URLs in emails.
Integrate Microsoft Defender for Endpoint with Microsoft 365 Defender to stream advanced hunting events into Azure Sentinel, populating log analytics tables like device info and device network info.
Connect threat indicators to Microsoft Sentinel by onboarding TAXII and Threat Intelligence Platform connectors, store indicators in the threat intelligence indicator table, and use Graph APIs for monitoring and hunting.
Explore security incidents in Microsoft Sentinel, learn the threat response system with playbooks, analyze user entity behaviors, and query, visualize, and monitor data.
Explore incident management in Microsoft Sentinel by defining data connectors, events, analytical rules, alerts, and incidents to organize, investigate, and track technology threats.
Investigate incidents in Azure Sentinel using the investigation window to visualize entities and relationships, review alert timelines, and inspect entities with insights for threat response playbooks.
Ingest events with data connectors into the log analytics workspace of Microsoft Sentinel, and use analytical rules to generate alerts and incidents for security investigations.
Explore incident management in Microsoft Sentinel by integrating Defender for Cloud Apps, creating an API token policy, and investigating generated incidents.
Learn to manage security incidents in Microsoft Sentinel, from viewing the overview and incident details to assigning ownership, updating status and severity, and interpreting evidences, entities, and analytical rules.
Shows how to simulate a brute force attack on the azure portal by creating an analytics rule from rule templates and testing with incognito logins, triggering a sentinel incident.
Monitor Azure Active Directory role changes, including global administrator, exporting audit logs to Log Analytics to trigger Sentinel incidents. Use KQL-based analytical rule and a logic app to alert Teams.
Create an analytical rule in Sentinel to query the Azure Log Analytics audit logs for role membership changes, triggering an alert and a Teams message via a Logic App.
Create and modify a user in Azure Active Directory, assign the billing administrator role, then verify the change in audit logs and export logs to Log Analytics for Sentinel integration.
Verify that Azure Active Directory audit logs export to Log Analytics and reflect the addition of Joe to the global administrator role, then check Sentinel for related incidents.
Learn how Microsoft Sentinel generates incidents from analytical rules driven by Kusto queries, using audit logs and log analytics, with automated responses via Logic Apps and playbooks.
Create a new logic app in the Azure portal named automation for role changes, design a Sentinel workflow that triggers alerts and posts to a Microsoft Teams channel via connectors.
Edit the analytical rule in Sentinel to attach a logic app playbook, validate and save, then trigger membership-change alerts that create incidents and notify the SOC teams channel.
Explore UEBA, or user entity behavior analytics, which uses AI and ML to establish baselines and detect anomalies across users and entities like routers, servers, and IoT devices.
Explore UEBA in Microsoft Sentinel, reviewing alerts and entities like user accounts, hostnames, and IP addresses, and how user principal name, GUID, and domain\username are merged into a single identity.
Explore entity pages in Microsoft Sentinel UEBA, reviewing user and IP entities via a three-panel view: entity details, activity timeline, and behavioral insights, with investigation touchpoints and KQL queries.
Explore Microsoft Sentinel workbooks to query, visualize, and monitor data with interactive reports using text, tables, charts, tiles, and KQL functions, then use templates or build from scratch.
Explore how to create and customize workbooks in the Microsoft Sentinel portal using templates or from scratch, leveraging data connectors and Azure Active Directory sign-in logs, and customize KQL queries.
Learn to create and customize a security workbook in Microsoft Sentinel by editing names, adding tiles, building kql queries, and configuring time ranges and visualizations.
Explore threat hunting concepts and procedures in Microsoft Sentinel, learn to develop a threat hunting hypothesis, and leverage notebooks and KQL queries to run effective hunts.
Proactively hunt for cyber threats using evidence from logs and threat intelligence, leveraging KQL queries in Microsoft Sentinel to detect hidden attackers before they move laterally.
Learn to conduct proactive threat hunting using a hypothesis-driven process grounded in operational threat intelligence and MITRE techniques, with continuous cycle, documentation, and actionable next steps.
Develop a testable, flexible threat hunting hypothesis that is achievable, time-bound, narrowly scoped, and documented for continuous improvement, starting simple and aligned to your threat model.
Explore threat hunting in Microsoft Sentinel using the MITRE ATT&CK framework to filter, run, and customize KQL queries, manage favorites, and build new queries.
Use Jupyter notebooks to integrate machine learning libraries, visualizations, and external data for detecting malicious activity patterns in security investigations. Practice data cleaning, transformations, numerical simulations, statistical modeling with notebooks.
Learn to clone Microsoft Sentinel notebook templates, create an Azure Machine Learning workspace, and attach compute power to run and train notebooks within the Sentinel environment.
Become a security operations analyst by using Microsoft Defender suites, Defender for Cloud, and Sentinel; master Kusto query language, threat hunting, and incident management across cloud environments.
There is no short cut to learning Azure security. This course teaches you how to learn it the right way with tons of labs excercises and the right volume of labs .
The Microsoft Security Operations Analyst works with organizational stakeholders to secure the organization's information technology systems. Their mission is to reduce corporate risk by quickly resolving active attacks in the environment, advising on threat protection practices, and reporting policy violations to the proper stakeholders.
Threat management, monitoring, and response using a variety of security technologies across their environment are among their responsibilities. Using Microsoft Azure Sentinel, Azure Defender, Microsoft 365 Defender, and third-party security tools, the position primarily investigates, responds to, and hunts for threats. The security operations analyst is a key stakeholder in the configuration and implementation of these technologies since they consume the operational output of these solutions.
The following topics needs to be completed in order to achieve SC - 200 Certification.
Module 1 Mitigate threats using Microsoft 365 Defender
Module 2 Mitigate threats using Microsoft Defender for Endpoint
Module 3 Mitigate threats using Azure Defender
Module 4 Create queries for Azure Sentinel using Kusto Query Language
Module 5 Microsoft Sentinel Environment - Configuration
Module 6 Microsoft Sentinel Environment - Connecting Logs
Module 7 Microsoft Sentinel Environment - Incidents,Threat Response , UEBA and Monitoring
Module 8 Module 8 Perform Threat Hunting with Microsoft Sentinel
You will learn and prepare to Implement the Microsoft Defender for Endpoint platform to detect, investigate, & respond to advanced threats.
This learning path aligns with exam SC-200: Microsoft Security Operations Analyst Exam.
Reviews from Participants -
In the beginning I was a little intimidated by the immensity of Microsoft security environment, but getting along with the course it all clicked in my head. The concepts are presented at a very good pace and I like that the information is on point. Segmenting the videos in small chunks is also beneficial for time management. I really appreciate and recommend this course! - Adrian Carbune
Great course. I learned a lot about Defender and Sentinel. I especially liked the module on KQL. IMO, it's the best tutorial on Kusto that I've found on the web. If Anand were to create a course that went in-depth on KQL I would certainly purchase it.
-Bill Jones
Anand has structured the course well, so that anyone, irrespective of their experience in Security, would be able to follow with ease. The course aligns very well with the Certification track. I strongly recommend this course to anyone who is interested in understanding Security.
-Moses M
am truley satisfied with this course. Anand nails the security features of M 365 defender suite. The graphics , narration and worlkflows are commendable. Just labs, labs and labs . Its all about getting straight to the point. Great Job!!!
-Gaurav
Great course, congratulations to teacher! Help me a lot to gain very knowledge about Defender and Sentinel. I appreciate it!!!
-Alexandre Gammaro
It was one of the The best course .Your are an amazing Instructor.
-Navid
This course is Awsome! One of the best I've ever made over here in Udemy platform.
-Mauricio Kobayashi