SC-200: Perform threat hunting in Microsoft Sentinel

Go to class
Write Review

Free Online Course: SC-200: Perform threat hunting in Microsoft Sentinel provided by Microsoft Learn is a comprehensive online course, which lasts for 1-2 hours worth of material. The course is taught in English and is free of charge.

Overview
    • Module 1: Explain threat hunting concepts in Microsoft Sentinel
    • Upon completion of this module, the learner will be able to:

      • Describe threat hunting concepts for use with Microsoft Sentinel
      • Define a threat hunting hypothesis for use in Microsoft Sentinel
    • Module 2: Threat hunting with Microsoft Sentinel
    • In this module, you will:

      • Use queries to hunt for threats.
      • Save key findings with bookmarks.
      • Observe threats over time with livestream.
    • Module 3: Hunt for threats using notebooks in Microsoft Sentinel
    • Upon completion of this module, the learner will be able to:

      • Explore API libraries for advanced threat hunting in Microsoft Sentinel
      • Describe notebooks in Microsoft Sentinel
      • Create and use notebooks in Microsoft Sentinel

Syllabus
    • Module 1: Explain threat hunting concepts in Microsoft Sentinel
      • Introduction
      • Understand cybersecurity threat hunts
      • Develop a hypothesis
      • Knowledge check
      • Summary and resources
    • Module 2: Threat hunting with Microsoft Sentinel
      • Introduction
      • Exercise setup
      • Explore creation and management of Microsoft Sentinel threat-hunting queries
      • Save key findings with bookmarks
      • Observe threats over time with livestream
      • Exercise - Hunt for threats by using Microsoft Sentinel
      • Summary
    • Module 3: Hunt for threats using notebooks in Microsoft Sentinel
      • Introduction
      • Access Azure Sentinel data with external tools
      • Hunt with notebooks
      • Create a notebook
      • Explore notebook code
      • Knowledge check
      • Summary and resources