<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.co.uk/css/xml-course.xsl"?><course productid="34038" language="en" source="https://portal.flane.co.uk/exertis/xml-course/ot-m55610a" lastchanged="2024-11-04T09:21:18+00:00" parent="https://portal.flane.co.uk/exertis/xml-courses"><title>Planning and implementing Microsoft Sentinel (SIEM &amp; SOAR)</title><productcode>M55610A</productcode><vendorcode>OT</vendorcode><vendorname>Other</vendorname><fullproductcode>OT-M55610A</fullproductcode><version>1.0</version><audience>&lt;p&gt;This course is aimed at IT professionals and Azure administrators that have some experience administering and configuring Azure, but want to gain an insight into implementing Microsoft&amp;rsquo;s SIEM/SOAR solution, Microsoft Sentinel.&lt;/p&gt;</audience><outline>&lt;p&gt;&lt;strong&gt;Module 1: Overview of Microsoft Sentinel&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Overview of Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Data ingestion methods&lt;/li&gt;&lt;li&gt;Microsoft Sentinel for MSSPs&lt;/li&gt;&lt;li&gt;User and Entity Behaviour Analytics&lt;/li&gt;&lt;li&gt;Fusion&lt;/li&gt;&lt;li&gt;Notebooks&lt;/li&gt;&lt;li&gt;Management &amp;amp; Automation Tools&lt;/li&gt;&lt;li&gt;Logs &amp;amp; Costs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 2: KQL&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Importance of KQL across Azure&lt;/li&gt;&lt;li&gt;The User Interface (demo)&lt;/li&gt;&lt;li&gt;The standard KQL Structure&lt;/li&gt;&lt;li&gt;Common KQL Commands&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 3: Data Connectors&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Manage content in Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Connect data to Microsoft Sentinel using data connectors&lt;/li&gt;&lt;li&gt;Connect Microsoft services to Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Connect Microsoft 365 Defender to Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Connect Windows hosts to Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Connect Common Event Format logs to Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Connect syslog data sources to Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Connect threat indicators to Microsoft Sentinel&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 4 &amp;ndash; Analytics Rules&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Threat detection with Microsoft Sentinel analytics&lt;/li&gt;&lt;li&gt;Automation in Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Threat response with Microsoft Sentinel playbooks&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 5 &amp;ndash; Incident Management&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Incident management Overview&lt;/li&gt;&lt;li&gt;User and Entity Behaviour Analytics&lt;/li&gt;&lt;li&gt;Data normalization in Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Query, visualize, and monitor data&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 6 &amp;ndash; Hunting&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Threat hunting concepts&lt;/li&gt;&lt;li&gt;Threat hunting with Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Use Search jobs in Microsoft Sentinel&lt;/li&gt;&lt;li&gt;Hunt for threats using notebooks&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 7 &amp;ndash; Watchlists&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prioritize incidents&lt;/li&gt;&lt;li&gt;Import business data&lt;/li&gt;&lt;li&gt;Reduce Alert Fatigue&lt;/li&gt;&lt;li&gt;Enrich Event Data&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Module 8 &amp;ndash; Threat Intelligence&lt;/strong&gt;
Lessons:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Threat Intelligence Overview&lt;/li&gt;&lt;li&gt;Threat Intelligence in Microsoft Sentinel&lt;/li&gt;&lt;/ul&gt;</outline><audience_plain>This course is aimed at IT professionals and Azure administrators that have some experience administering and configuring Azure, but want to gain an insight into implementing Microsoft’s SIEM/SOAR solution, Microsoft Sentinel.</audience_plain><outline_plain>Module 1: Overview of Microsoft Sentinel
Lessons:



- Overview of Microsoft Sentinel
- Data ingestion methods
- Microsoft Sentinel for MSSPs
- User and Entity Behaviour Analytics
- Fusion
- Notebooks
- Management &amp; Automation Tools
- Logs &amp; Costs
Module 2: KQL
Lessons:



- Importance of KQL across Azure
- The User Interface (demo)
- The standard KQL Structure
- Common KQL Commands
Module 3: Data Connectors
Lessons:



- Manage content in Microsoft Sentinel
- Connect data to Microsoft Sentinel using data connectors
- Connect Microsoft services to Microsoft Sentinel
- Connect Microsoft 365 Defender to Microsoft Sentinel
- Connect Windows hosts to Microsoft Sentinel
- Connect Common Event Format logs to Microsoft Sentinel
- Connect syslog data sources to Microsoft Sentinel
- Connect threat indicators to Microsoft Sentinel
Module 4 – Analytics Rules
Lessons:



- Threat detection with Microsoft Sentinel analytics
- Automation in Microsoft Sentinel
- Threat response with Microsoft Sentinel playbooks
Module 5 – Incident Management
Lessons:



- Incident management Overview
- User and Entity Behaviour Analytics
- Data normalization in Microsoft Sentinel
- Query, visualize, and monitor data
Module 6 – Hunting
Lessons:



- Threat hunting concepts
- Threat hunting with Microsoft Sentinel
- Use Search jobs in Microsoft Sentinel
- Hunt for threats using notebooks
Module 7 – Watchlists
Lessons:



- Prioritize incidents
- Import business data
- Reduce Alert Fatigue
- Enrich Event Data
Module 8 – Threat Intelligence
Lessons:



- Threat Intelligence Overview
- Threat Intelligence in Microsoft Sentinel</outline_plain><duration unit="d" days="3">3 days</duration><miles/></course>