{"course":{"productid":34038,"modality":2,"active":true,"language":"en","title":"Planning and implementing Microsoft Sentinel (SIEM & SOAR)","productcode":"M55610A","vendorcode":"OT","vendorname":"Other","fullproductcode":"OT-M55610A","courseware":{"has_ekit":false,"has_printkit":true,"language":""},"url":"https:\/\/portal.flane.co.uk\/course\/ot-m55610a","audience":"<p>This course is aimed at IT professionals and Azure administrators that have some experience administering and configuring Azure, but want to gain an insight into implementing Microsoft&rsquo;s SIEM\/SOAR solution, Microsoft Sentinel.<\/p>","outline":"<p><strong>Module 1: Overview of Microsoft Sentinel<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Overview of Microsoft Sentinel<\/li><li>Data ingestion methods<\/li><li>Microsoft Sentinel for MSSPs<\/li><li>User and Entity Behaviour Analytics<\/li><li>Fusion<\/li><li>Notebooks<\/li><li>Management &amp; Automation Tools<\/li><li>Logs &amp; Costs<\/li><\/ul><p><strong>Module 2: KQL<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Importance of KQL across Azure<\/li><li>The User Interface (demo)<\/li><li>The standard KQL Structure<\/li><li>Common KQL Commands<\/li><\/ul><p><strong>Module 3: Data Connectors<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Manage content in Microsoft Sentinel<\/li><li>Connect data to Microsoft Sentinel using data connectors<\/li><li>Connect Microsoft services to Microsoft Sentinel<\/li><li>Connect Microsoft 365 Defender to Microsoft Sentinel<\/li><li>Connect Windows hosts to Microsoft Sentinel<\/li><li>Connect Common Event Format logs to Microsoft Sentinel<\/li><li>Connect syslog data sources to Microsoft Sentinel<\/li><li>Connect threat indicators to Microsoft Sentinel<\/li><\/ul><p><strong>Module 4 &ndash; Analytics Rules<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Threat detection with Microsoft Sentinel analytics<\/li><li>Automation in Microsoft Sentinel<\/li><li>Threat response with Microsoft Sentinel playbooks<\/li><\/ul><p><strong>Module 5 &ndash; Incident Management<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Incident management Overview<\/li><li>User and Entity Behaviour Analytics<\/li><li>Data normalization in Microsoft Sentinel<\/li><li>Query, visualize, and monitor data<\/li><\/ul><p><strong>Module 6 &ndash; Hunting<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Threat hunting concepts<\/li><li>Threat hunting with Microsoft Sentinel<\/li><li>Use Search jobs in Microsoft Sentinel<\/li><li>Hunt for threats using notebooks<\/li><\/ul><p><strong>Module 7 &ndash; Watchlists<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Prioritize incidents<\/li><li>Import business data<\/li><li>Reduce Alert Fatigue<\/li><li>Enrich Event Data<\/li><\/ul><p><strong>Module 8 &ndash; Threat Intelligence<\/strong>\nLessons:\n<\/p>\n<ul>\n<li>Threat Intelligence Overview<\/li><li>Threat Intelligence in Microsoft Sentinel<\/li><\/ul>","summary":"<p>This 3 day hands on course helps you get ramped up with Microsoft Sentinel and provide hands-on practical experience for product features, capabilities, and scenarios.<\/p>\n<p>During the course you will deploy a Microsoft Sentinel workspace and ingest pre-recorded data to simulate scenarios that showcase various Microsoft Sentinel features.<\/p>","audience_plain":"This course is aimed at IT professionals and Azure administrators that have some experience administering and configuring Azure, but want to gain an insight into implementing Microsoft\u2019s SIEM\/SOAR solution, Microsoft Sentinel.","outline_plain":"Module 1: Overview of Microsoft Sentinel\nLessons:\n\n\n\n- Overview of Microsoft Sentinel\n- Data ingestion methods\n- Microsoft Sentinel for MSSPs\n- User and Entity Behaviour Analytics\n- Fusion\n- Notebooks\n- Management & Automation Tools\n- Logs & Costs\nModule 2: KQL\nLessons:\n\n\n\n- Importance of KQL across Azure\n- The User Interface (demo)\n- The standard KQL Structure\n- Common KQL Commands\nModule 3: Data Connectors\nLessons:\n\n\n\n- Manage content in Microsoft Sentinel\n- Connect data to Microsoft Sentinel using data connectors\n- Connect Microsoft services to Microsoft Sentinel\n- Connect Microsoft 365 Defender to Microsoft Sentinel\n- Connect Windows hosts to Microsoft Sentinel\n- Connect Common Event Format logs to Microsoft Sentinel\n- Connect syslog data sources to Microsoft Sentinel\n- Connect threat indicators to Microsoft Sentinel\nModule 4 \u2013 Analytics Rules\nLessons:\n\n\n\n- Threat detection with Microsoft Sentinel analytics\n- Automation in Microsoft Sentinel\n- Threat response with Microsoft Sentinel playbooks\nModule 5 \u2013 Incident Management\nLessons:\n\n\n\n- Incident management Overview\n- User and Entity Behaviour Analytics\n- Data normalization in Microsoft Sentinel\n- Query, visualize, and monitor data\nModule 6 \u2013 Hunting\nLessons:\n\n\n\n- Threat hunting concepts\n- Threat hunting with Microsoft Sentinel\n- Use Search jobs in Microsoft Sentinel\n- Hunt for threats using notebooks\nModule 7 \u2013 Watchlists\nLessons:\n\n\n\n- Prioritize incidents\n- Import business data\n- Reduce Alert Fatigue\n- Enrich Event Data\nModule 8 \u2013 Threat Intelligence\nLessons:\n\n\n\n- Threat Intelligence Overview\n- Threat Intelligence in Microsoft Sentinel","summary_plain":"This 3 day hands on course helps you get ramped up with Microsoft Sentinel and provide hands-on practical experience for product features, capabilities, and scenarios.\n\nDuring the course you will deploy a Microsoft Sentinel workspace and ingest pre-recorded data to simulate scenarios that showcase various Microsoft Sentinel features.","version":"1.0","duration":{"unit":"d","value":3,"formatted":"3 days"},"lastchanged":"2024-11-04T09:21:18+00:00","parenturl":"https:\/\/portal.flane.co.uk\/exertis\/json-courses","nexturl_course_schedule":"https:\/\/portal.flane.co.uk\/exertis\/json-course-schedule\/34038","source_lang":"en","source":"https:\/\/portal.flane.co.uk\/exertis\/json-course\/ot-m55610a"}}