Implementing and Administering Microsoft Sentinel
1h 44mIntermediate2023-12-11
Authors

Pete Zerger
Consultant, Author, Speaker, Leader, Microsoft MVP
Course details
Microsoft Sentinel is a next-generation, cloud-native security event and information management (SEIM) system that provides real-time analysis of security alerts generated for your cloud and on-premises resources. By leveraging built-in machine learning from the security analytics experts at Microsoft, Sentinel effectively detects threats while automating threat response using orchestration and built-in or custom security playbooks. In this course, join Pete Zerger as he guides you through the implementation and configuration of Microsoft Sentinel. Discover how to connect key services and threat intelligence resources to Sentinel; investigate cases; create security playbooks to set automated threat responses to issues; and leverage search and query tools to hunt for threats.
Skills covered
Azure SentinelMicrosoft Entra ID (Azure Active Directory)Cloud AdministrationNetwork AdministrationCloud PlatformsNetwork and System AdministrationCloud ComputingMicrosoftOne-Off
Concepts
0. Introduction
- 01 - Need a central point of analysis for security events
- 02 - What you should know
- 03 - Lab setup
1. Introduction and Concepts
- 04 - Sentinel feature flyover
- 05 - Onboarding Microsoft Sentinel
- 06 - Kusto query language quickstart
2. Configuring Microsoft Sentinel
- 07 - Connecting Microsoft services
- 08 - Connecting external services
- 09 - Integrating threat intelligence
3. Threat Detection, Investigation, and Response
- 10 - Detecting threats
- 11 - Investigating incidents
- 12 - Responding to threats using automation
- 13 - Security orchestration, automation, and response (SOAR)
- 14 - UEBA and machine learning
4. Advanced Threat Hunting Scenarios
- 15 - Threat hunting basics
- 16 - Hunting with bookmarks
- 17 - Hunting with notebooks
- 18 - Workbooks and dashboards
- 19 - Integrating with Microsoft Defender and Purview
Conclusion
- 20 - Next steps