Free
Microsoft Sentinel
This Microsoft Sentinel course is designed to prepare professionals to use Azure's bird-eye view cloud-native security tool to provide real-time security analysis, threat hunting, and response through the cloud for small and large enterprises. General IT knowledge, cloud concepts, and Microsoft Azure computing services knowledge are recommended.
5
H
56
M
Time
intermediate
difficulty
6
ceu/cpe
Course Content
Incident Response: Use Cases
Working with Sentinel
Instructor's Welcome to Microsoft Sentinel
Introduction: Getting Started with Sentinel
Deploying Sentinel
Sentinel Core Concepts: Design & Deployment
Workbooks
Creating with Sentinel: Analytics & Reporting
Threat Hunting
Operating with Sentinel: Threat Hunting & Incident Response
Incident Response Playbooks
Defending with Sentinel: Threat Response
Challenge Questions
Working with Sentinel
Functionality & Features
Introduction: Getting Started with Sentinel
Onboarding Azure Virtual Machines
Sentinel Core Concepts: Design & Deployment
Analytics Rules
Creating with Sentinel: Analytics & Reporting
Hunting with Livestream & Bookmarks
Operating with Sentinel: Threat Hunting & Incident Response
Automation Rules
Defending with Sentinel: Threat Response
Sentinel Best Practices
Introduction: Getting Started with Sentinel
Onboarding Non-Azure Virtual Machines
Sentinel Core Concepts: Design & Deployment
Custom Analytics Rule
Creating with Sentinel: Analytics & Reporting
Incident Response
Operating with Sentinel: Threat Hunting & Incident Response
Challenge Questions
Defending with Sentinel: Threat Response
Challenge Questions
Introduction: Getting Started with Sentinel
Onboarding Azure AD Logs
Sentinel Core Concepts: Design & Deployment
Onboarding Network Security Group Logs
Sentinel Core Concepts: Design & Deployment
Threat Intelligence
Creating with Sentinel: Analytics & Reporting
Challenge Questions
Operating with Sentinel: Threat Hunting & Incident Response
Challenge Questions
Sentinel Core Concepts: Design & Deployment
Challenge Questions
Creating with Sentinel: Analytics & Reporting
Course Description
What is Microsoft Sentinel?
> Microsoft Sentinel is a cloud-native solution tool that provides Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) within the Azure cloud platform. Mastering this tool proves that learners have a solid knowledge of using Microsoft Sentinel's cloud-native solutions to convey intelligent security analytics and threat intelligence across an enterprise through data collection, investigation, and response to threats.What is Involved in this Microsoft Sentinel course?
This course focuses on providing learners with an overview of Microsoft (Azure) Sentinel and how Sentinel can serve as a comprehensive security solution that provides real-time analysis of security alerts for the cloud and on-premises resources. Throughout this course, learners will receive a complete look into configuring Sentinel for deployment, how to connect it to resources, and what threat hunting, analysis management, and response look like once a system is active. The central theme throughout this course is how Sentinel provides a flexible and highly configurable security solution to small and large organizations focused on the needs of a SOC or related IT specialized team.Course Goals
By the end of this course, learners will be able to:Who Should Take this Microsoft Sentinel Course?
This Microsoft Sentinel course is ideal for professionals who have the foundational knowledge of utilizing Azure cloud platform services and wish to use its cloud-native solution tool to deliver security analytics that impacts threat detection, hunting, and response across an enterprise. This course is designed to validate learners' Azure cloud security solution knowledge and skill sets to current and potential employers, making them more attractive to hiring managers and recruiters. Learners taking this course are not required to have any Azure certification. However, it is recommended that they have general IT knowledge and take the AZ900 course on Cybrary's platform to familiarise themselves with foundational Azure cloud concepts and services.
Why should someone take this course with Cybrary?
Learners who want to master the Microsoft Sentinel tool must have the proper training and materials. Cybrary, one of the leading online cybersecurity training websites, is pleased to provide students with the best training and materials to help them understand cloud-native security tools.> At Cybrary, we make it afforable, convenient and flexible for students to learn at their own pace online. In addition, Cybrary provides an AZ-900 course that will help you to validate your knowledge on Azure Fundamentals, which will aid you in your pursuit to understanding its Sentinel cloud-native tool. Enrolling in this Microsoft Sentinel course is simple, just click on the Register button in the top right corner of the screen to get started.