-
Learn how to implement and administer Azure Sentinel, a cloud-native security event and information management (SEIM) system that detects threats while automating threat responses.
Azure Sentinel is a next-generation, cloud-native security event and information management (SEIM) system that provides real-time analysis of security alerts generated for your cloud and on-premises resources. By leveraging built-in machine learning from the security analytics experts at Microsoft, Sentinel effectively detects threats while automating threat response using orchestration and built-in or custom security playbooks. In this course, join Pete Zerger as he guides you through the implementation and configuration of Azure Sentinel. Discover how to connect key services and threat intelligence resources to Sentinel; investigate cases; create security playbooks to set automated threat responses to issues; and leverage search and query tools to hunt for threats.
Overview
Syllabus
-
Introduction
- An introduction to Azure Sentinel
- What you should know
- Lab requirements
- Sentinel feature flyover
- Onboarding Azure Sentinel
- Kusto query language quickstart
- Connecting Microsoft services
- Connecting external services
- Connecting threat intelligence
- Detecting suspicious activities
- Investigating cases
- Responding to threats
- Setting up automated threat response
- Threat hunting basics
- Hunting with bookmarks
- Hunting with notebooks
- Building custom dashboards
- Next steps