Learn how to investigate, respond to, and look for threats using Microsoft Azure Sentinel, Azure Defender, and Microsoft 365 Defender. In this course, you will learn how to mitigate cyber threats using these technologies. Specifically, you will configure and use Azure Sentinel as well as use Kusto Query Language (KQL) to perform detection, analysis, and reporting.
The course is designed for people working in a Security Operations role and helps students prepare for the SC-200: Microsoft Security Operations Analyst exam.
After completing this course, students will be able to:
The Microsoft Security Operations Analyst works with organizational stakeholders to secure the organization’s information technology systems. Their goal is to reduce organizational risk by quickly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders. Responsibilities include threat management, monitoring and response using a variety of security solutions throughout their environment. The role investigates, responds to, and looks for threats using Microsoft Azure Sentinel, Azure Defender, Microsoft 365 Defender, and third-party security products. As the Security Operations Analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.
QA
Module 1: Mitigating threats using Microsoft Defender for Endpoint
Deploy the Microsoft Defender for Endpoint platform to detect, investigate, and respond to advanced threats. Learn how Microsoft Defender for Endpoint can help your organization stay secure. Learn how to deploy the Microsoft Defender for Endpoint environment, including onboarding devices and configuring security. Learn how to investigate incidents and alerts using Microsoft Defender for Endpoints. Perform advanced hunting and consult with threat experts. You will also learn how to configure automation in Microsoft Defender for Endpoint by managing environment settings. Finally, you will learn more about your environment’s vulnerabilities by using Threat and Vulnerability Management in Microsoft Defender for Endpoint.
Lessons
Lab: Mitigate threats using Microsoft Defender for Endpoint
After completing this module, participants will be able to:
Module 2: Mitigating threats using Microsoft 365 Defender
Analyze threat data across domains and quickly remediate threats with built-in orchestration and automation in Microsoft 365 Defender. Learn more about cybersecurity threats and how the new threat protection tools from Microsoft protect your organization’s users, devices, and data. Use advanced identity-based threat detection and remediation to protect your Azure Active Directory identities and applications from being compromised.
Lessons
Lab: Mitigate threats with Microsoft 365 Defender
After completing this module, participants will be able to:
Module 3: Mitigating threats using Azure Defender
Use Azure Defender integrated with Azure Security Center for protection and security of Azure, hybrid cloud, and on-premises workloads. Learn the purpose of Azure Defender, Azure Defender’s relationship to Azure Security Center, and how to enable Azure Defender. You will also learn about the protections and detections that Azure Defender provides for each cloud workload. Learn how you can add Azure Defender features to your hybrid environment.
Lessons
Lab: Defending against threats with Azure Defender
After completing this module, participants will be able to:
Module 4: Creating queries for Azure Sentinel using Kusto Query Language (KQL)
Write Kusto Query Language (KQL) statements to query log data to perform detections, analysis and reporting in Azure Sentinel. This module will focus on the most commonly used operators. The examples of KQL statements will show security-related table queries. KQL is the query language used to parse data to create analytics, workbooks, and perform hunting in Azure Sentinel. Learn how basic KQL statements provide the foundation for building more complex statements. Learn how to summarize and visualize data with a KQL statement that provides the foundation for building detections in Azure Sentinel. Learn how to use Kusto Query Language (KQL) to manipulate string data retrieved from log sources.
Lessons
Lab : Creating queries for Azure Sentinel using Kusto Query Language (KQL)
After completing this module, participants will be able to:
Module 5: Configuring your Azure Sentinel environment
Get started with Azure Sentinel by properly configuring the Azure Sentinel workspace. Traditional security information and event management (SIEM) systems typically take a long time to install and configure. They are also not necessarily designed with cloud workloads in mind. Azure Sentinel allows you to quickly start gaining valuable security insights from your cloud and on-premises data. This module will help you get started. Learn about the architecture of Azure Sentinel workspaces to ensure you configure your system to meet your organization’s security operations requirements. As a Security Operations Analyst, you need to understand the tables, fields, and data included in your workspace. Learn how to query the most commonly used data tables in Azure Sentinel.
Lessons
Lab : Setting up your Azure Sentinel environment
After completing this module, participants will be able to:
Module 6: Connecting logs to Azure Sentinel
Connect cloud-scale data across all users, devices, applications, and infrastructure, both on-premises and across multiple clouds to Azure Sentinel. The primary method of connecting log data is to use the data connectors provided by Azure Sentinel. This module provides an overview of the available data connectors. You will learn about the configuration options and data provided by Azure Sentinel connections for Microsoft 365 Defender.
Lessons
Lab : Connecting logs to Azure Sentinel
After completing this module, participants will be able to:
Module 7: Creating detections and performing investigations with Azure Sentinel
Discover previously undetected threats and remediate threats quickly with built-in orchestration and automation in Azure Sentinel. You will learn how to create Azure Sentinel playbooks to respond to security threats. You will explore Azure Sentinel incident management, learn about Azure Sentinel events and devices, and discover ways to resolve incidents. You’ll also learn how to query, visualize, and monitor data in Azure Sentinel.
Lessons
Lab : Create detections and perform investigations with Azure Sentinel
After completing this module, participants will be able to:
Module 8: Performing threat hunting in Azure Sentinel
In this module, you will learn how to proactively identify threat behaviors using Azure Sentinel queries. You will also learn how to use bookmarks and livestream to hunt for threats. You will also learn how to use notebooks in Azure Sentinel for advanced hunting.
Lessons
Laboration: Hot hunting in Azure Sentinel
After completing this module, participants will be able to:
Course Overview
34500 kr
4 days
Advanced
Can’t find a (suitable) date, but are interested in the course? Send in an expression of interest and we will do what we can to find a suitable opportunity.
Customized Courses
The course can be adapted from several perspectives:
In interaction with the course leader, we ensure that the course meets your needs.
Send an expression of interest for the training
Send an expression of interest for the training