Managed Detection and Response (MDR) Fundamentals
2h 58mBeginner2024-01-22
Authors

Liam Cleary
Microsoft MVP and MCT, CEO of SharePlicity
Course details
In managed detection and response (MDR), an organization outsources some of its security operations to a third-party provider. It’s good to build a thorough understanding of this useful service. In this course, Liam Cleary—Microsoft Certified Trainer, Microsoft MVP Alum, and the CEO of SharePlicity—guides you through the basics you need to know about MDR. Learn how to differentiate MDR from other security methods and approaches. Explore threat monitoring, log management, real-time event analysis, and incident detection techniques and tools. Develop an understanding of incident response workflow, phases, and best practices. Find out about the skills you’ll need to use in incident investigation, evidence collection, and reporting. Learn the basics of threat hunting and the use of advanced hunting techniques and tools within Microsoft 365. Plus, go over incident management frameworks, regulatory compliance considerations, and the development of incident response plans.
Skills covered
Governance, Risk, and ComplianceEssential TrainingCybersecurity
Concepts
0. Introduction
- 01 - A security mindset
1. Introduction to Managed Detection and Response (MDR)
- 02 - Managed detection and response (MDR) explained
- 03 - Key components
- 04 - What makes an MDR program
- 05 - MDR vs. other security methods
2. Threat Monitoring and Security Event Analysis
- 06 - Introduction to threat monitoring
- 07 - Objectives of threat monitoring
- 08 - Log management and analysis
- 09 - Correlation and context
- 10 - Azure Log Analytics - Setup and usage
- 11 - Real-time event analysis and alerting
- 12 - Microsoft Defender for Cloud Apps
- 13 - Real-time event analysis - Microsoft Defender for Cloud Apps
3. Incident Detection and Response
- 14 - Incident detection techniques and tools
- 15 - Key detection tools
- 16 - Incident detection with Microsoft Defender for Endpoint
- 17 - Incident response workflow and phases
- 18 - Viewing security incidents in Microsoft 365
- 19 - Incident investigation and evidence collection
- 20 - Preservation techniques
4. Threat Hunting
- 21 - Threat hunting basics
- 22 - Proactive threat hunting
- 23 - Understanding indicators of compromise (IOCs)
- 24 - Recognizing signs of breach and attack methods
- 25 - Overview of threat hunting techniques and tools
- 26 - Using advanced hunting within Microsoft 365
5. Incident Management and Reporting
- 27 - Incident management frameworks and best practices
- 28 - Developing an incident response plan
- 29 - Incident documentation and reporting
- 30 - Regulatory compliance and incident reporting
Conclusion
- 31 - Next steps