Implementing and Administering Microsoft Sentinel

Go to class
Write Review

Free Online Course: Implementing and Administering Microsoft Sentinel provided by LinkedIn Learning is a comprehensive online course, which lasts for 1-2 hours worth of material. The course is taught in English and is free of charge. Upon completion of the course, you can receive an e-certificate from LinkedIn Learning. Implementing and Administering Microsoft Sentinel is taught by Pete Zerger.

Overview
  • Learn how to implement and administer Azure Sentinel, a cloud-native security event and information management (SEIM) system that detects threats while automating threat responses.

Syllabus
  • Introduction

    • Need a central point of analysis for security events?
    • What you should know
    • Lab setup
    1. Introduction and Concepts
    • Sentinel feature flyover
    • Onboarding Microsoft Sentinel
    • Kusto query language quickstart
    2. Configuring Microsoft Sentinel
    • Connecting Microsoft services
    • Connecting external services
    • Integrating threat intelligence
    3. Threat Detection, Investigation, and Response
    • Detecting threats
    • Investigating incidents
    • Responding to threats with playbooks
    • Security orchestration, automation, and response (SOAR)
    • UEBA and machine learning
    4. Advanced Threat Hunting Scenarios
    • Threat hunting basics
    • Hunting with bookmarks
    • Hunting with notebooks
    • Workbooks and dashboards
    • Integrating with M365 Defender
    Conclusion
    • Next steps