Become an Azure Sentinel Ninja: The complete level 400 training

Published Apr 12 2020 04:05 PM 393K Views
Microsoft

(Last updated Sept 6th 2021)

 

In this blog post, we try to walk you through Azure Sentinel level 400 training and help you become an Azure Sentinel master.

 

Already did the Ninja Training? check what's new.​​​​​

 

Curriculum 

Curriculum.jpg

 

This training program includes 16 modules. The post includes a presentation for each module, preferably recorded (when still not, we are working on the recording) and supporting information: relevant product documentation, blog posts, and other resources.

The modules listed below are split into five groups following the life cycle of a SOC:

 

Part 1: Overview

- Module 0: Other learning and support options

- Module 1: Get started with Azure Sentinel

- Module 2: How is Azure Sentinel used?

 

Part 2: Architecting & Deploying

- Module 3: Workspace and tenant architecture

- Module 4: Data collection

- Module 5: Log Management

- Module 6: Enrichment: TI, Watchlists, and more

- Module X: Migration

- Module Z: ASIM and Normalization

 

Part 3: Creating Content

- Module 7: The Kusto Query Language (KQL)

- Module 8: Analytics

- Module 9: SOAR

- Module 10: Workbooks, reporting, and visualization

- Module Y: Notebooks

- Module 11: Use cases and solutions

 

Part 4: Operating

- Module 12: A day in a SOC analyst's life, incident management, and investigation

- Module 13: Hunting

- Module 14: User and Entity Behavior Analytics (UEBA) 

- Module 15: Monitoring Azure Sentinel's health

 

Part 5: Advanced Topics

- Module 16: Extending and Integrating using Azure Sentinel APIs

- Module 17: Bring your own ML

 

Part 1: Overview

 

Module 0: Other learning and support options

 

The Ninja training is a level 400 training. If you don't want to go as deep or have a specific issue, other resources might be more suitable:

  • Already did the Ninja Training? Check what's new​ in the Ninja training.
  • While extensive, the Ninja training has to follow a script and cannot expand on every topic. The FAQ companion to the Ninja Training tries to closed this gap.
  • Azure Sentinel's official learning path is best if you want step-by-step training to use Azure Sentinel's features.
  • You can now certify with the new SC-200 certification (Microsoft Security Operations Analyst) which covers Azure Sentinel. The  SC-200 is not a Ninja Training certification, but the exam is largely based on Ninja Training materials, making it a good learning path for the certification. You may also want to consider the SC-900 certification (Microsoft Security, Compliance, and Identity Fundamentals), for a broader, higher level view of the Microsoft Security suite.
  • Premier customer? You might want the on-site (or remote these days)  4 day Azure Sentinel Fundamentals Workshop. Contact your Customer Success Account Manager to arrange.
  • Already a Ninja? Just keep track of what's new, or join our Private Preview program for an even earlier glimpse. 
  • Have a specific issue? Ask (or answer other) on the Azure Sentinel Tech Community. As a last resort, send an e-mail to AzureSentinel@microsoft.com.

 

Think you're a true Sentinel Ninja? Take the knowledge check and find out. If you pass the 
knowledge check with a score of over 80% you can request a certificate to prove your ninja
skills!

1. Take the knowledge check here. 
2. If you score 80% or more in the knowledge check, request your participation certificate 
here. If you achieved less than 80%, please review the questions that you got it wrong, study
more and take the assessment again.

 

Module 1: Get started with Azure Sentinel

 

Short on time? Watch the Fall Ignite presentation
Already know? This webinar summarizes what's new in Sentinel in the past six months (Apr-Sept 21).
Get deeper? Watch the Webinar: MP4YouTube, Presentation

 

Microsoft Azure Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution. Azure Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response (read more).

 

If you want to get an initial overview of Azure Sentinel's technical capabilities, the latest Ignite presentation is a good starting point. You might also find the Quick Start Guide to Azure Sentinel useful (requires registration). A more detailed overview, however somewhat dated, can be found in this webinar: MP4YouTube, Presentation.

 

Lastly, want to try it yourself? The Azure Sentinel All-In-One Accelerator  (blog, Youtube, MP4, deck) presents an easy way to get you started. To learn how to start yourself, review the onboarding documentation, or watch Insight's Sentinel setup and configuration video.

 

Learn from users

Thousands of organizations and service providers are using Azure Sentinel. As usual with security products, most do not go public about that. Still, there are some.

 

Learn from Analysts

 

Module 2: How is Azure Sentinel used?

 

Short on time? Read this presentation.

 

Many users use Azure Sentinel as their primary SIEM. Most of the modules in this course cover this use case. In this module, we present a few additional ways to use Azure Sentinel.

 

As part of the Microsoft Security stack

Use Sentinel, Azure Defender, Microsoft 365 Defender  in tandem to protect your Microsoft workloads, including Windows, Azure, and Office:

 

To monitor your multi-cloud workloads

The cloud is (still) new and often not monitored as extensively as on-prem workloads. Read this presentation to learn how Azure Sentinel can help you close the cloud monitoring gap across your clouds.

 

Side by side with your existing SIEM

Either for a transition period or a longer term, if you are using Azure Sentinel for your cloud workloads, you may be using Azure Sentinel alongside your existing SIEM. You might also be using both with a ticketing system such as Service Now. 

 

For more information on migrating from another SIEM to Azure Sentinel, watch the migration webinar: MP4YouTubeDeck.

 

There are three common scenarios for side by side deployment:

You can also send the alerts from Azure Sentinel to your 3rd party SIEM or ticketing system using the Graph Security API , which is simpler but would not enable sending additional data. 

 

For MSSPs

Since it eliminates the setup cost and is location agnostics, Azure Sentinel is a popular choice for providing SIEM as a service. You can find a list of MISA (Microsoft Intelligent Security Association) member MSSPs using Azure Sentinel. Many other MSSPs, especially regional and smaller ones, use Azure Sentinel but are not MISA members.

 

To start your journey as an MSSP, you should read the Azure Sentinel Technical Playbooks for MSSPs. More information about MSSP support is included in the next module, cloud architecture and multi-tenant support.  

 

Part 2: Architecting & Deploying

 

While the previous section offers options to start using Azure Sentinel in a matter of minutes, before you start a production deployment, you need to plan. This section walks you through the areas that you need to consider when architecting your solution, as well as provides guidelines on how to implement your design:

  • Workspace and tenant architecture
  • Data collection 
  • Log management
  • Threat Intelligence acquisition

 

Module 3: Workspace and tenant architecture

 

Short on time? Watch the Nic DiCola's Ignite presentation (first 11 Minutes)
Get Deeper? Watch the Webinar: MP4YouTubePresentation

 

An Azure Sentinel instance is called a workspace. The workspace is the same as a Log Analytics workspace and supports any Log Analytics capability. You can think of Sentinel as a solution that adds SIEM features on top of a Log Analytics workspace.

 

Multiple workspaces are often necessary and can act together as a single Azure Sentinel system. A special use case is providing service using Azure Sentinel, for example, by an MSSP (Managed Security Service Provider) or by a Global SOC in a large organization. 

 

To learn more about why use multiple workspaces and use them as one Azure Sentinel system, read Extend Azure Sentinel across workspaces and tenants or, if you prefer, the Webinar version: MP4YouTubePresentation.

 

There are a few specific areas that require your consideration when using multiple workspaces:

 

 

The Azure Sentinel Technical Playbook for MSSPs provides detailed guidelines for many of those topics, and is useful also for large organizations, not just to MSSPs.

 

Module 4: Data collection

 

Sept 2021 update: our latest webinar on data collection scenarios by Edi Lahav and Yaniv 
Shasha. YouTube, MP4, Deck


Short on time? Watch the Nic DiCola's Ignite presentation (Mid 11 Minutes)
Get Deeper? Watch the Webinar: YouTube, MP4Deck.

 

The foundation of a SIEM is collecting telemetry: events, alerts, and contextual enrichment information such as Threat Intelligence, vulnerability data, and asset information. You can find a list of sources you can connect here:

  • Documentation of the connectors which are part of the connectors gallery.
  • The Grand List of sources you can connect to Azure Sentinel, whether part of the gallery or not (note: this list is no longer being updated).

 

How you connect each source falls into several categories or source types. Each source type has a distinct setup effort but once deployed,  it serves all sources of that type. The Grand List specifies for each source what its type is. To learn more about those categories, watch the Webinar (includes Module 3): YouTube, MP4Deck.

 

The types are:

 

  • Built-in service-to-service connectors allow Azure Sentinel to connect directly to cloud services such as Office 365 or AWS CloudTrail. Some of the service-to-service connectors, such as AAD, utilize Azure diagnostics behind the scenes. 

 

  • Direct refers to sources that natively know how to send data to Azure Sentinel or Log Analytics. These include Azure services or other Microsoft solutions that support sending telemetry (often referred to as "diagnostics") to Log Analytics and 3rd party sources that use the ingestion API to write to Log analytics or Azure Sentinel directly. The Microsoft direct sources are listed in addition to the Grand List and in the blog post "Collecting logs from Microsoft Services and Applications."

 

  • The Log Forwarder is a VM that enables collecting Syslog and CEF events from remote systems. If a source is listed in the Grand List as CEF or Syslog, you will use the Log Forwarder to collect from it. Learn more about the Log Forwarder in this webinar (plus a bonus: learn how to use it to filter events):  YouTubeMP4Deck.

 

  • The Log Analytics agent collects information from Windows or Linux hosts. In addition to OS events such as Windows Events, the agent can collect events stored in files. Learn more about the Log Analytics agent in this blog: collecting telemetry from on-prem and IaaS server using the Log Analytics agent. The Azure Monitor Agent is a new generation agent currently in preview that offers advantages such as Windows events filtering. The Log Analytics agent is being deprecated on 31 August 2024, so if you have not yet deployed the Log Analytics agent you should consider whether it is possible for you to start using the Azure Monitor Agent (see next bullet point).

 

  • The Azure Monitor Agent (AMA) is the replacement for the Log Analytics Agent. The Azure Monitor agent introduces several new capabilities not available in the Log Analytics agent such as filtering, scoping, and multi-homing. At the time of writing this update, AMA isn't yet at parity with the Log Analytics agent, although this will change over time. Consider whether the features you need for your Azure Sentinel deployment are supported in AMA, or whether to continue to use the Log Analytics agent for now and migrate at a later date. You can sign up for the Everything You Ever Wanted to Know About Using the New Azure Monitor Agent (AMA) with Azure Sentinel on Nov 22 here.

 

 

  • Integrate Threat Intelligence (TI) sources using the built-in connectors from TAXII servers or Microsoft Graph Security API. Read more on how to in the documentation. TI can also be important as a custom log using a custom connector or as a lookup table. You can read more about how TI is used managed in Azure Azure in the TI modules later. 

 

If your source is not available, you can create a custom connector. Custom connectors use the ingestion API and therefore are similar to direct sources. Custom connectors are most often implemented using Logic Apps, offering a codeless option, or Azure Functions.

 

Module 5: Log Management

 

While how many and which workspaces to use is the first architecture question to ask, there are additional log management architectural decisions:

  • Where and how long to retain data.
  • How to best manage access to data and secure it. 

 

Retention

 

Logs Security

 

Dedicated cluster

 

Module 6: Enrichment: TI, Watchlists, and more

 

One of the important functions of a SIEM is to apply contextual information to the event steam, enabling detection, alert prioritization, and incident investigation. Contextual information includes, for example, threat intelligence, IP intelligence, host and user information, and watchlists.

 

Azure Sentinel provides comprehensive tools to import, manage, and use threat intelligence. For other types of contextual information, Azure Sentinel provides Watchlists, as well as alternative solutions.

Threat Intelligence

 

Sept 2021 update: Sign up for the Explore the Power of Threat Intelligence in Azure Sentinel
webinar on Oct 25 here.

Short on time? watch the Ignite session (28 Minutes)
Get Deeper? Watch the Webinar: YouTubeMP4Presentation

 

Threat Intelligence is an important building block of a SIEM.

 

In Azure Sentinel, you can integrate threat intelligence (TI) using the built-in connectors from TAXII servers or through the Microsoft Graph Security API. Read more on how to in the documentation. Refer to the data collection modules for more information about importing Threat Intelligence. 

 

Once imported, Threat Intelligence is used extensively throughout Azure Sentinel and is weaved into the different modules. The following features focus on using Threat Intelligence:

 

Watchlists and other lookup mechanisms

 
To import and manage any type of contextual information, Azure Sentinel provides Watchlists, which enable you to upload data tables in CSV format and use them in your KQL queries. Read more about Watchlists in the documentation
 
In addition to Watchlists, you can also use the KQL externaldata operator, custom logs, and KQL functions to manage and query context information. Each one of the four methods has its pros and cons, and you can read more about the comparison between those options in the blog post "Implementing Lookups in Azure Sentinel." While each method is different, using the resulting information in your queries is similar enabling easy switching between them.
 
Read utilize Watchlists to Drive Efficiency During Azure Sentinel Investigations for ideas on using Watchlist outside of analytic rules.
 

Module X: Migration

 

Watch the Webinar: YouTubeMP4Presentation

 

In many (if not most) cases, you already have a SIEM and need to migrate to Azure Sentinel. While it may be a good time to start over and rethink your SIEM implementation, it makes sense to utilize some of the assets you already built in your current implementation. To start watch our webinar describing best practices for converting detection rules from Splunk, QRadar, and ArcSight to Azure Sentinel Rules: YouTubeMP4Presentation, blog.

 

You might also be interested in some of the resources presented in the blog:

 

Module Z: ASIM and Normalization

 

Watch the Understanding Normalization in Azure Sentinel webinar: YouTubePresentation
Watch the Deep Dive into Azure Sentinel Normalizing Parsers and Normalized
Content webinar:
YouTube, MP3, Presentation

Sign up for the Turbocharging ASIM: Making Sure Normalization Helps Performance Rather Than
Impacting It webinar on Oct 6 here.

 

Working with various data types and tables together presents a challenge. You must become familiar with many different data types and schemas, write and use a unique set of analytics rules, workbooks, and hunting queries for each, even for those that share commonalities (for example, DNS servers). Correlation between the different data types necessary for investigation and hunting is also tricky.

 

The Azure Sentinel Information Model (ASIM) provides a seamless experience for handling various sources in uniform, normalized views. ASIM aligns with the Open-Source Security Events Metadata (OSSEM) common information model, promoting vendor agnostic, industry-wide normalization.

 

The current implementation is based on query time normalization using KQL functions. And includes the following:

  • Normalized schemas cover standard sets of predictable event types that are easy to work with and build unified capabilities. The schema defines which fields should represent an event, a normalized column naming convention, and a standard format for the field values.
  • Parsers map existing data to the normalized schemas. Parsers are implemented using KQL functions.
  • Content for each normalized schema includes analytics rules, workbooks, hunting queries, and additional content. This content works on any normalized data without the need to create source-specific content.

 

Using ASIM provides the following benefits:

  • Cross source detection: Normalized analytic rules work across sources, on-prem and cloud, now detecting attacks such as brute force or impossible travel across systems including Okta, AWS, and Azure.
  • Allows source agnostic content: the coverage of built-in as well as custom content using ASIM automatically expands to any source that supports ASIM, even if the source was added after the content was created. For example, process event analytics support any source that a customer may use to bring in the data, including Defender for Endpoint, Windows Events, and Sysmon. We are ready to add Sysmon for Linux and WEF once released!
  • Support for your custom sources in built-in analytics
  • Ease of use: once an analyst learns ASIM, writing queries is much simpler as the field names are always the same.

 

To learn more about ASIM:

  • Watch the overview webinar: YouTube, slides.
  • Watch the Deep Dive into Azure Sentinel Normalizing Parsers and Normalized Content webinar: YouTube, MP3, Presentation.
  • Sign up for the Turbocharging ASIM: Making Sure Normalization Helps Performance Rather Than Impacting It webinar on Oct 6 here.
  • Read the documentation.

 

To Deploy ASIM:

  • Deploy the parsers from the folders starting with “ASim*” in the parsers folder on GitHub.
  • Activate analytic rules that use ASIM. Search for “normal” in the template gallery to find some of them. To get the full list use this GitHub search.

 

To Use ASIM:

 

Part 3: Creating Content

 

What is Azure Sentinel's content?

 

Azure Sentinel security value is a combination of its built-in capabilities such as UEBA, Machine Learning, or out-of-the-box analytics rules and your capability to create custom capabilities and customize built-in ones. Customized SIEM capabilities are often referred to as "content" and include analytic rules, hunting queries, workbooks, playbooks, and more.

 

In this section, we grouped the modules that help you learn how to create such content or modify built-in-content to your needs.  We start with KQL, the Lingua Franca of Azure Sentinel. The following modules discuss one of the content building blocks such as rules, playbooks, and workbooks. We wrap up by discussing use cases, which encompass elements of different types to address specific security goals such as threat detection, hunting, or governance. 

 

Module 7: KQL

 

Short on time? Start at the beginning and go as far as time allows.

 

Most Azure Sentinel capabilities use KQL or Kusto Query Language. When you search in your logs, write rules, create hunting queries, or design workbooks, you use KQL.  Note that the next section on writing rules explains how to use KQL in the specific context of SIEM rules.

 

We suggest you follow this Sentinel KQL journey:

  1. Pluralsight KQL course - the basics
  2. The Azure Sentinel KQL Lab: An interactive lab teaching KQL focusing on what you need for Azure Sentinel:
    1. Learning module (SC-200 part 4)
    2. Deck, Lab URL 
    3. Jupyter Notebooks version contributed by jjsantanna, which let you test the queries within the notebook.
    4. Learning webinar: Youtube, MP4;
    5. Reviewing lab solutions webinar: YouTube , MP4
  3. Pluralsight Advanced KQL course
  4. Optimizing Azure Sentinel KQL queries performance: YouTubeMP4Deck.
  5. Using ASIM in your KQL queries: YouTube, Deck

 

You might also find the following reference information useful as you learn KQL:

 

Module 8: Analytics

 

Writing Scheduled Analytics Rules

 

Short on time? watch the Webinar: MP4YouTubePresentation

 

Azure Sentinel enables you to use built-in rule templates, customize the templates for your environment, or create custom rules. The core of the rules is a KQL query; however, there is much more than that to configure in a rule.

 

To learn the procedure for creating rules, read the documentation. To learn how to write rules, i.e., what should go into a rule, focusing on KQL for rules, watch the webinar: MP4, YouTube, Presentation.

 

SIEM rules have specific patterns. Learn how to implement rules and write KQL for those patterns:  

 

To blog post "Blob and File Storage Investigations" provides a step by step example of writing a useful analytic rule.

 

Using built-in analytics

 

Short on time? watch the Machine Learning Webinar: MP4YouTubePresentation

 

Before embarking on your own rule writing, you should take advantage of the built-in analytics capabilities. Those do not require much from you, but it is worthwhile learning about them:

 

Module 9: Implementing SOAR

 

Sept 2021 update: sign up for the What’s New in Azure Sentinel Automation webinar on Oct 28 
here.

Short on time? watch the Webinar:
YouTubeMP4, Deck

 

In modern SIEMs such as Azure Sentinel, SOAR (Security Orchestration, Automation, and Response) comprises the entire process from the moment an incident is triggered and until it is resolved. This process starts with an incident investigation and continues with an automated response. The blog post "How to use Azure Sentinel for Incident Response, Orchestration and Automation" provides an overview of common use cases for SOAR.

 

Automation rules are the starting point for Azure Sentinel automation. They provide a lightweight method for central automated handling of incidents, including suppression, false-positive handling, and automatic assignment.

 

To provide robust workflow based automation capabilities, automation rules use Logic App playbooks:

You can find dozens of useful Playbooks in the Playbooks folder on the Azure Sentinel GitHub, or read "A playbook using a watchlist to Inform a subscription owner about an alert" for a Playbook walkthrough.

 

While Azure Sentinel is a cloud-native SIEM, its automation capabilities do extend to on-prem environments, either using the Logic Apps on-prem gateway or using Azure Automation as described in "Automatically disable On-prem AD User using a Playbook triggered in Azure"

 

Module 10: Workbooks, reporting, and visualization

 

Short on time? Watch the Webinar: YouTubeMP4Deck

 

Workbooks

 

As the nerve center of your SOC, you need Azure Sentinel to visualize the information it collects and produces. Use workbooks to visualize data in Azure Sentinel.

 

Workbooks can be interactive and enable much more than just charting. With Workbooks, you can create apps or extension modules for Azure Sentinel to complement built-in functionality. We also use workbooks to extend the features of Azure Sentinel. Few examples of such apps you can both use and learn from are:

You can find dozens of workbooks in the Workbooks folder in the Azure Sentinel GitHub. Some of those are available in the Azure Sentinel workbooks gallery and some are not. 

 

Reporting and other visualization options

 

Workbooks can serve for reporting. For more advanced reporting capabilities such as reports scheduling and distribution or pivot tables, you might want to use:

 

Module Y: Notebooks

 

Short on time? Watch the short introduction video 
Get Deeper? Watch the Webinar: YouTubeMP4Presentation

 

Jupyter notebooks are fully integrated with Azure Sentinel. While usually considered an important tool in the hunter's tool chest and discussed the webinars in the hunting section below, their value is much broader. Notebooks can serve for advanced visualization, an investigation guide, and for sophisticated automation.

 

To understand them better, watch the Introduction to notebooks video. Get started using the Notebooks webinar (YouTubeMP4, Presentation) or by reading the documentation. The Azure Sentinel Notebooks Ninja series is an ongoing training series to upskill you in Notebooks.

 

An important part of the integration is implemented by MSTICPY, a Python library developed by our research team for use with Jupyter notebooks that adds Azure Sentinel interfaces and sophisticated security capabilities to your notebooks.

 

Module 11: Use cases and solutions

 

Sept 21 update: sign up for the Create Your Own Azure Sentinel Solutions webinar on Nov 16 
here.

Short on time? watch the "Tackling Identity" Webinar: YouTubeMP4Deck

 

Using connectors, rules, playbooks, and workbooks enables you to implement use cases: the SIEM term for a content pack intended to detect and respond to a threat. You can deploy Sentinel built-in use cases by activating the suggested rules when connecting each Connector. A solution is a group of use cases addressing a specific threat domain.

 

The Webinar "Tackling Identity" (YouTubeMP4Presentation) explains what a use case is, how to approach its design, and presents several use cases that collectively address identity threats.

 

Another very relevant solution area is protecting remote work. Watch our ignite session on protection remote work, and read more on the specific use cases:

 

And lastly, focusing on recent attacks, learn how to monitor the software supply chain with Azure Sentinel.

 

Azure Sentinel solutions provide in-product discoverability, single-step deployment, and enablement of end-to-end product, domain, and/or vertical scenarios in Azure Sentinel. Read more about them here, and sign up for the upcoming webinar on Nov 16 on how to create solutions here.

 

 

Part 4: Operating

 

Module 12: Handling incidents

 

Sept 21 update: sign up for the Decrease Your SOC’s MTTR (Mean Time to Respond) by Integrating 
Azure Sentinel with Microsoft Teams webinar on Nov 10 here.

Short on time? Watch the "day in a life" Webinar: YouTubeMP4Deck

 

After building your SOC, you need to start using it. The "day in a SOC analyst life" webinar (YouTubeMP4Presentation) walks you through using Azure Sentinel in the SOC to triage, investigate and respond to incidents.

 

Integrating with Microsoft Teams directly from Azure Sentinel enables your teams to collaborate seamlessly across the organization, and with external stakeholders. Sign up for the Decrease Your SOC’s MTTR (Mean Time to Respond) by Integrating Azure Sentinel with Microsoft Teams webinar on Nov 10 here.

 

You might also want to read the documentation article on incident investigation. As part of the investigation, you will also use the entity pages to get more information about entities related to your incident or identified as part of your investigation.

 

Incident investigation in Azure Sentinel extends beyond the core incident investigation functionality. We can build additional investigation tools using Workbooks and Notebooks (the latter are discussed later, under hunting). You can also build additional investigation tools or modify ours to your specific needs. Examples include: 

 

Module 13: Hunting

 

Short on time? watch the Webinar: YouTubeMP4Deck
(Note that the Webinar starts with an update on new features, to learn about hunting, start at slide 12. The YouTube 
link is already set to start there)

 

While most of the discussion so far focused on detection and incident management, hunting is another important use case for Azure Sentinel. Hunting is a proactive search for threats rather than a reactive response to alerts. 

 

The hunting dashboard was recently refreshed in July 2021 and shows all the queries written by Microsoft's team of security analysts and any extra queries that you have created or modified. Each query provides a description of what it hunts for, and what kind of data it runs on. These templates are grouped by their various tactics - the icons on the right categorize the type of threat, such as initial access, persistence, and exfiltration. Read more about it here.

 

To understand more about what hunting is and how Azure Sentinel supports it, Watch the hunting intro Webinar (YouTubeMP4Deck). Note that the Webinar starts with an update on new features. To learn about hunting, start at slide 12. The YouTube link is already set to start there.

 

While the intro webinar focuses on tools, hunting is all about security. Our security research team webinar on hunting (MP4YouTubePresentation) focuses on how to actually hunt. The follow-up AWS Threat Hunting using Sentinel Webinar (MP4, YouTube, Presentation) really drives the point by showing an end-to-end hunting scenario on a high-value target environment. Lastly, you can learn how to do SolarWinds Post-Compromise Hunting with Azure Sentinel and WebShell hunting motivated by the latest recent vulnerabilities in on-premises Microsoft Exchange servers.

 

Module 14: User and Entity Behavior Analytics (UEBA)

 

Short on time? Watch the Webinar: YouTubeDeck , MP4

 

Azure Sentinel newly introduced User and Entity Behavior Analytics (UEBA) module enables you to identify and investigate threats inside your organization and their potential impact - whether a compromised entity or a malicious insider.

 

Learn more about UEBA in the UEBA Webinar (YouTubeDeck, MP4) and read about using UEBA for investigations in your SOC. 

 

Module 15: Monitoring Azure Sentinel's health

 

Short on time? watch the videos on monitoring connectors, 
security operations health or workspace audit.

 

Part of operating a SIEM is making sure it works smoothly and an evolving area in Azure Sentinel. Use the following to monitor Azure Sentinel's health:

 

 

Part 5: Advanced Topics

 

Module 16: Extending and Integrating using Azure Sentinel APIs

 

Short on time? watch the video (5 minutes)
Get deeper? Watch the Webinar: MP4YouTubePresentation

 

As a cloud-native SIEM, Azure Sentinel is an API first system. Every feature can be configured and used through an API, enabling easy integration with other systems and extending Sentinel with your own code. If API sounds intimidating to you, don't worry; whatever is available using the API is also available using PowerShell.

 

To learn more about Azure Sentinel APIs, watch the short introductory video and blog post. To get the details, watch the deep dive Webinar (MP4YouTubePresentation) and read the blog post  Extending Azure Sentinel: APIs, Integration, and management automation.

 

Module 17: Bring your own ML

 

Short on time? watch the video

 

Azure Sentinel provides a great platform for implementing your own Machine Learning algorithms. We call it Bring Your Own ML or BYOML for short. Obviously, this is intended for advanced users. If you are looking for built-in behavioral analytics, use our ML Analytic rules, UEBA module, or write your own behavioral analytics KQL based analytics rules.

 

To start with bringing your own ML to Azure Sentinel, watch the video, and read the blog post. You might also want to refer to the BYOML documentation

69 Comments
Frequent Contributor

Hi @Ofer_Shezaf, Awesome collection Ofer - thanks very much for the time taken on this.

 

Just a few typos that might have crept in:
The first link in Module 2 is not a presentation but loops back to this page?

In Module 6 & 11 the Deck link is to the Presentation & the Presentation link is the MP4 recording

In Module 9 the Presentation link loops back to this page? But is this also part of the 3 files that are tucked away at the bottom of the page? ;)

 

Stay safe

 

Microsoft

Thanks @David Caddick! I hope I have fixed them all.

Thank you for Sharing this Awesome Azure Sentinel Training with the Community :cool:

Occasional Contributor

Nice work @Ofer_Shezaf ! Do you have any certification or exam as part of this training?

Contributor

@Ofer_Shezaf - Brilliant work & good to see all in one pack .

Occasional Visitor

Hi Guys i am not able to get the presentations.

Occasional Visitor

Only managed to download presentation for module 4 and 6.

Super Contributor

Hi 

 

Awesome - is there some "Baseline/Best Practice/minimum" for Sentinel - in deploying->configuring/settings/datacollectors/rules template setup? 

hope question makes sense :D 

Microsoft

Hey @Ofer_Shezaf 

 

this is wonderfull, perfect time when in covid wait, thank you ;) 

 

~Moe 

Occasional Contributor

Thank you @Ofer_Shezaf !

 

We are glad for these sessions as we also have some extra time!

 

Microsoft

@Taen keren : Sentinel implementation is very use case specific - differnt users deploy it for different goals. A way to start would be to pick the sources you are most interested in monitoring and protecting. The connector page for those sources has anlaytics rules, workbooks and queries which would be the starting point listed on the "what's next" tab.  

Microsoft

@Joseph-Abraham 

 

The training blog is extensive but informal. Currently certification is only as part of Az500 but it is at a much higher level.  I agree that it is a good idea and will check how to do something like that.

 

~ Ofer

Microsoft

@Tmothibi : I was able to and did not here of the issue from other people. Does it work now? If not, can you share with me privately the error/issue details?

Occasional Visitor

Hello,

Are the video links from 3 & 4 supposed to be the same?  They both (on youtube and onedrive) point to the same videos.

 

Really enjoying this link so far so thanks for creating it.  

Microsoft

Hi @fad3r : Yes, they are the same. I presented both topics in a single Webinar. I will replace (3) this week as I am doing an updated Webinar dedicated to this topic.

Respected Contributor

@Ofer_Shezaf Az-500 is going to be updated next month and there is only one small item about Sentinel in the new listing of topics, see https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE3VC70. Could you please work with the exam team to get more Sentinel questions added?

Microsoft

Hi @Ofer_Shezaf , First of all thank you for the training contents and it is really wonderful.

 

Do we have plans to launch certification as well for Azure Sentinel Level 400 Ninja ? 

Microsoft

@Nitish_Anand : After posting the program I learned that many would have liked to have such a certificate. I am looking into this, but we have no short term plans around it as of yet.

Regular Visitor

@Ofer_ShezafCan you provide me the end to end architecture diagram for SOAR? for instance how the communication will happen between on-prem data center paloalto/checkpoint firewall and sentinel to block malicious IP address, port in paloalto/checkpoint firewall? what are all the components involved in SOAR? what are all prerequisite?

Microsoft

@Vijaymkm : refere to https://docs.microsoft.com/en-us/azure/logic-apps/logic-apps-gateway-connection for details on how to connect Logic Apps, our SOAR engine, to on-prem resources.

Senior Member

Thank you for this @Ofer_Shezaf . This is great I was looking for a consolidated documentation that is a deep dive..!

 

~egal

Occasional Contributor

Thanks for the great info; sharing with my Linkedin Network

New Contributor

A great collection of resources, Thank you @Ofer_Shezaf 

Visitor
Hi Ofer,

Under Module 13: Hunting, "Threat Hunting - AWS using Sentinel, webinar on April 22nd, register here."
 
Should've already happened? but i can't find the youtube video. If it never took place maybe handy to remove it from the list?

- Jurgen
Microsoft

@Jurgen790 : Thanks for the reminder. Updated.

Regular Visitor

@Ofer_Shezaf  can you share the complete list of connector for security products i.e. Firewall (Checkpoint, paloalto, Cisco, etc), IPS, Anti-malware, URL filtering, etc..I am unable to find https://docs.microsoft.com/en-us/connectors/connector-reference/ . i am wondering how we can perform SOAR functions using logic apps without connectors

Microsoft

super useful content really liked the design sessions

Occasional Contributor

Thanks for sharing ! 

Occasional Visitor

@Ofer_Shezaf Great Work, thank you very much. 

Respected Contributor

@Ofer_Shezaf while you are working on a certificate program, it could also be helpful if you contacted the MVP program to discuss how people working with Sentinel can be nominated for that award. I assume that its in the Threat Protection area

Microsoft

@Dean Gross : the certificate is not an award and does not need nominations, it would be based on passing an exam. As an update, the certificate will be based, at least initially, on the newly released Sentinel learning path and not the Ninja training. 

Valued Contributor

One modification that may be useful is if you could make the listing of the sections at the top of the page hyperlinks to the sections on the page to make navigation easier.

Microsoft

@Gary Bushey : I tried. Anchor times seem to not work well with the CSS the community site uses :-(. Direct links are even more important for the FAQ. Well maybe time to move to the Microsoft docs site.

Frequent Visitor

How can I get a format certificate of completion for this course? Also I dont see any certification path for Sentinel!

Microsoft

@dmarshetty : this is an unofficial course and it has no certification. We are planning to have a SOC operations certification that will include Sentinel in a couple of months.

Frequent Visitor

@Ofer_Shezaf thank you. Is there any other course where we can get a certificate? I have done the Azure Sentinel's official learning path you mentioned but even that doesn't seem to have any certificate.

Occasional Visitor

There is no link for Module 2. I think I got to the right place. The first video follows with "Azure Sentinel webinar: Cloud & On-Premises architecture - YouTube(https://www.youtube.com/watch?v=_mm3GNwPBHU)

Microsoft

@RandyDover : I don't have a Webinar for Module 2. The link you shared was the Webinar for Module 3, but was since updated, and the current presentations for Module 3 are more up to date.

New Contributor

Any chance of you lifting this over to a GitHub repo @Ofer_Shezaf would be great to keep it continually updated etc.

 

Thanks

Microsoft

Hi @davidclarke : First, I am updating this blog on an ongoing basis. We consider moving it to the official Azure Sentinel documentation so it is not a workd of mouth kind of resource. Microsoft docs are GitHub so they allow anyone to suggest updates just like a regular GitHub repo. 

Frequent Contributor

Just sayin'... pretty awesome post right here!  I will be using this as I prepare to eventually write both AZ-500 and SC-200.

Senior Member

Thanks a lot for the magnificent topic  .. I believe this will help me pass the SC-200 Exam.

Valued Contributor

I would like thank you for this article.

I suggest to add courses and contents into the Microsoft Learn's lessons website as it is a fun way to learning and earn badge too.

Microsoft

@Reza_Ameri : in module zero, you can find the official Sentienl learning path as well as the SC-200 certification which includes a learning path. They share similarties with (and sometimes actually are based on) the Ninja training. The latter offers a certification based on the conent  (well, you will have to know MDE and AzD as well to certify).

Valued Contributor

Thank you @Ofer_Shezaf for the clarification.

Hi!

Just a heads up that the link Playbooks folder under Module 9: SOAR currently links to the Workbooks folder in Github, not Playbooks: https://github.com/Azure/Azure-Sentinel/tree/master/Workbooks.

Microsoft

Thanks @Louise_Wiljander.  Corrected.

Respected Contributor

@Ofer_Shezaf the Security compass has been replaced the Best Practices, see Microsoft Security Best Practices | Microsoft Docs. You may want to update the description above to help decrease confusion.

Occasional Visitor

Hi,

Do we have an estimation of the time requested to complete this training ?

Thanks in advance

Senior Member

@Ofer_Shezaf - I have the same question as @FrancoisV500 - How much time should we plan for going through this training?

%3CLINGO-SUB%20id%3D%22lingo-sub-1302131%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1302131%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%2C%26nbsp%3BAwesome%20collection%20Ofer%20-%20thanks%20very%20much%20for%20the%20time%20taken%20on%20this.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20a%20few%20typos%20that%20might%20have%20crept%20in%3A%3CBR%20%2F%3EThe%20first%20link%20in%20Module%202%20is%20not%20a%20presentation%20but%20loops%20back%20to%20this%20page%3F%3C%2FP%3E%3CP%3EIn%20Module%206%20%26amp%3B%2011%20the%20Deck%20link%20is%20to%20the%20Presentation%20%26amp%3B%20the%20Presentation%20link%20is%20the%20MP4%20recording%3C%2FP%3E%3CP%3EIn%20Module%209%20the%20Presentation%20link%20loops%20back%20to%20this%20page%3F%20But%20is%20this%20also%20part%20of%20the%203%20files%20that%20are%20tucked%20away%20at%20the%20bottom%20of%20the%20page%3F%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStay%20safe%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1302216%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1302216%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F129396%22%20target%3D%22_blank%22%3E%40David%20Caddick%3C%2FA%3E!%26nbsp%3BI%20hope%20I%20have%20fixed%20them%20all.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1304511%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1304511%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20for%20Sharing%20this%20Awesome%20Azure%20Sentinel%20Training%20with%20the%20Community%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Fhtml%2Fimages%2Femoticons%2Fcool_40x40.gif%22%20alt%3D%22%3Acool%3A%22%20title%3D%22%3Acool%3A%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1304691%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1304691%22%20slang%3D%22en-US%22%3E%3CP%3ENice%20work%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B!%20Do%20you%20have%20any%20certification%20or%20exam%20as%20part%20of%20this%20training%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1305043%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1305043%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B-%20Brilliant%20work%20%26amp%3B%20good%20to%20see%20all%20in%20one%20pack%26nbsp%3B.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1306639%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1306639%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Guys%20i%20am%20not%20able%20to%20get%20the%20presentations.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1306694%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1306694%22%20slang%3D%22en-US%22%3E%3CP%3EOnly%20managed%20to%20download%20presentation%20for%20module%204%20and%206.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1306827%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1306827%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAwesome%20-%20is%20there%20some%20%22Baseline%2FBest%20Practice%2Fminimum%22%20for%20Sentinel%20-%20in%20deploying-%26gt%3Bconfiguring%2Fsettings%2Fdatacollectors%2Frules%20template%20setup%3F%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3Ehope%20question%20makes%20sense%20%3AD%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1308637%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1308637%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ethis%20is%20wonderfull%2C%20perfect%20time%20when%20in%20covid%20wait%2C%20thank%20you%20%3B)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E~Moe%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1309120%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1309120%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%20!%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20glad%20for%20these%20sessions%20as%20we%20also%20have%20some%20extra%20time!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1312013%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1312013%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F108979%22%20target%3D%22_blank%22%3E%40Taen%20keren%3C%2FA%3E%26nbsp%3B%3A%20Sentinel%20implementation%20is%20very%20use%20case%20specific%20-%20differnt%20users%20deploy%20it%20for%20different%20goals.%20A%20way%20to%20start%20would%20be%20to%20pick%20the%20sources%20you%20are%20most%20interested%20in%20monitoring%20and%20protecting.%20The%20connector%20page%20for%20those%20sources%20has%20anlaytics%20rules%2C%20workbooks%20and%20queries%20which%20would%20be%20the%20starting%20point%20listed%20on%20the%20%22what's%20next%22%20tab.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1312542%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1312542%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F387181%22%20target%3D%22_blank%22%3E%40joseph2165%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20training%20blog%20is%20extensive%20but%20informal.%20Currently%20certification%20is%20only%20as%20part%20of%20Az500%20but%20it%20is%20at%20a%20much%20higher%20level.%26nbsp%3B%26nbsp%3BI%20agree%20that%20it%20is%20a%20good%20idea%20and%20will%20check%20how%20to%20do%20something%20like%20that.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E~%20Ofer%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1312546%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1312546%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F621358%22%20target%3D%22_blank%22%3E%40Tmothibi%3C%2FA%3E%26nbsp%3B%3A%20I%20was%20able%20to%20and%20did%20not%20here%20of%20the%20issue%20from%20other%20people.%20Does%20it%20work%20now%3F%20If%20not%2C%20can%20you%20share%20with%20me%20privately%20the%20error%2Fissue%20details%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1313783%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1313783%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EAre%20the%20video%20links%20from%203%20%26amp%3B%204%20supposed%20to%20be%20the%20same%3F%26nbsp%3B%20They%20both%20(on%20youtube%20and%20onedrive)%20point%20to%20the%20same%20videos.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EReally%20enjoying%20this%20link%20so%20far%20so%20thanks%20for%20creating%20it.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1319137%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1319137%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F625098%22%20target%3D%22_blank%22%3E%40fad3r%3C%2FA%3E%26nbsp%3B%3A%20Yes%2C%20they%20are%20the%20same.%20I%20presented%20both%20topics%20in%20a%20single%20Webinar.%20I%20will%20replace%20(3)%20this%20week%20as%20I%20am%20doing%20an%20updated%20Webinar%20dedicated%20to%20this%20topic.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1328489%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1328489%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3BAz-500%20is%20going%20to%20be%20updated%20next%20month%20and%20there%20is%20only%20one%20small%20item%20about%20Sentinel%20in%20the%20new%20listing%20of%20topics%2C%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fquery.prod.cms.rt.microsoft.com%2Fcms%2Fapi%2Fam%2Fbinary%2FRE3VC70%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fquery.prod.cms.rt.microsoft.com%2Fcms%2Fapi%2Fam%2Fbinary%2FRE3VC70%3C%2FA%3E.%20Could%20you%20please%20work%20with%20the%20exam%20team%20to%20get%20more%20Sentinel%20questions%20added%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1338349%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1338349%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B%2C%20First%20of%20all%20thank%20you%20for%20the%20training%20contents%20and%20it%20is%20really%20wonderful.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDo%20we%20have%20plans%20to%20launch%20certification%20as%20well%20for%20Azure%20Sentinel%20Level%20400%20Ninja%20%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1338363%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1338363%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F276809%22%20target%3D%22_blank%22%3E%40Nitish_Anand%3C%2FA%3E%26nbsp%3B%3A%20After%20posting%20the%20program%20I%20learned%20that%20many%20would%20have%20liked%20to%20have%20such%20a%20certificate.%20I%20am%20looking%20into%20this%2C%20but%20we%20have%20no%20short%20term%20plans%20around%20it%20as%20of%20yet.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1381777%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1381777%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3ECan%20you%20provide%20me%20the%20end%20to%20end%20architecture%20diagram%20for%20SOAR%3F%20for%20instance%20how%20the%20communication%20will%20happen%20between%20on-prem%20data%20center%20paloalto%2Fcheckpoint%20firewall%20and%20sentinel%20to%20block%20malicious%20IP%20address%2C%20port%20in%20paloalto%2Fcheckpoint%20firewall%3F%20what%20are%20all%20the%20components%20involved%20in%20SOAR%3F%20what%20are%20all%20prerequisite%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1388946%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1388946%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F573980%22%20target%3D%22_blank%22%3E%40Vijaymkm%3C%2FA%3E%26nbsp%3B%3A%20refere%20to%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Flogic-apps%2Flogic-apps-gateway-connection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Flogic-apps%2Flogic-apps-gateway-connection%3C%2FA%3E%26nbsp%3Bfor%20details%20on%20how%20to%20connect%20Logic%20Apps%2C%20our%20SOAR%20engine%2C%20to%20on-prem%20resources.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1408127%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1408127%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20for%20this%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B.%20This%20is%20great%20I%20was%20looking%20for%20a%20consolidated%20documentation%20that%20is%20a%20deep%20dive..!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E~egal%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1448027%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1448027%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20the%20great%20info%3B%20sharing%20with%20my%20Linkedin%20Network%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1455841%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1455841%22%20slang%3D%22en-US%22%3E%3CP%3EA%20great%20collection%20of%20resources%2C%20Thank%20you%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1460959%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1460959%22%20slang%3D%22en-US%22%3E%3CDIV%3E%3CFONT%3EHi%20Ofer%2C%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%3CFONT%3EUnder%20%3CSTRONG%3EModule%2013%3A%20Hunting%3C%2FSTRONG%3E%2C%20%3CEM%3E%22Threat%20Hunting%20-%20AWS%20using%20Sentinel%2C%20webinar%20on%20April%2022nd%2C%20register%20here.%22%3C%2FEM%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CFONT%3EShould've%20already%20happened%3F%20but%20i%20can't%20find%20the%20youtube%20video.%20If%20it%20never%20took%20place%20maybe%20handy%20to%20remove%20it%20from%20the%20list%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%3CFONT%3E-%20Jurgen%3C%2FFONT%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1461293%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1461293%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F696143%22%20target%3D%22_blank%22%3E%40Jurgen790%3C%2FA%3E%26nbsp%3B%3A%20Thanks%20for%20the%20reminder.%20Updated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1538918%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1538918%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B%20can%20you%20share%20the%20complete%20list%20of%20connector%20for%20security%20products%20i.e.%20Firewall%20(Checkpoint%2C%20paloalto%2C%20Cisco%2C%20etc)%2C%20IPS%2C%20Anti-malware%2C%20URL%20filtering%2C%20etc..I%20am%20unable%20to%20find%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fconnectors%2Fconnector-reference%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fconnectors%2Fconnector-reference%2F%3C%2FA%3E%26nbsp%3B.%20i%20am%20wondering%20how%20we%20can%20perform%20SOAR%20functions%20using%20logic%20apps%20without%20connectors%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1682890%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1682890%22%20slang%3D%22en-US%22%3E%3CP%3Esuper%20useful%20content%20really%20liked%20the%20design%20sessions%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1747833%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1747833%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20sharing%20!%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1970611%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1970611%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3BGreat%20Work%2C%20thank%20you%20very%20much.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2024982%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2024982%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3Bwhile%20you%20are%20working%20on%20a%20certificate%20program%2C%20it%20could%20also%20be%20helpful%20if%20you%20contacted%20the%20MVP%20program%20to%20discuss%20how%20people%20working%20with%20Sentinel%20can%20be%20nominated%20for%20that%20award.%20I%20assume%20that%20its%20in%20the%20Threat%20Protection%20area%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2025101%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2025101%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1096%22%20target%3D%22_blank%22%3E%40Dean%20Gross%3C%2FA%3E%26nbsp%3B%3A%20the%20certificate%20is%20not%20an%20award%20and%20does%20not%20need%20nominations%2C%20it%20would%20be%20based%20on%20passing%20an%20exam.%20As%20an%20update%2C%20the%20certificate%20will%20be%20based%2C%20at%20least%20initially%2C%20on%20the%20newly%20released%20Sentinel%20learning%20path%20and%20not%20the%20Ninja%20training.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2276920%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2276920%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3Bthe%20Security%20compass%20has%20been%20replaced%20the%20Best%20Practices%2C%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsecurity%2Fcompass%2Fcompass%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Security%20Best%20Practices%20%7C%20Microsoft%20Docs%3C%2FA%3E.%20You%20may%20want%20to%20update%20the%20description%20above%20to%20help%20decrease%20confusion.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2027752%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2027752%22%20slang%3D%22en-US%22%3E%3CP%3EOne%20modification%20that%20may%20be%20useful%20is%20if%20you%20could%20make%20the%20listing%20of%20the%20sections%20at%20the%20top%20of%20the%20page%20hyperlinks%20to%20the%20sections%20on%20the%20page%20to%20make%20navigation%20easier.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2027878%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2027878%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F46875%22%20target%3D%22_blank%22%3E%40Gary%20Bushey%3C%2FA%3E%26nbsp%3B%3A%20I%20tried.%20Anchor%20times%20seem%20to%20not%20work%20well%20with%20the%20CSS%20the%20community%20site%20uses%20%3A-(.%20Direct%20links%20are%20even%20more%20important%20for%20the%20FAQ.%20Well%20maybe%20time%20to%20move%20to%20the%20Microsoft%20docs%20site.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078605%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078605%22%20slang%3D%22en-US%22%3E%3CP%3EHow%20can%20I%20get%20a%20format%20certificate%20of%20completion%20for%20this%20course%3F%20Also%20I%20dont%20see%20any%20certification%20path%20for%20Sentinel!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078608%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078608%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F936029%22%20target%3D%22_blank%22%3E%40dmarshetty%3C%2FA%3E%26nbsp%3B%3A%20this%20is%20an%20unofficial%20course%20and%20it%20has%20no%20certification.%20We%20are%20planning%20to%20have%20a%20SOC%20operations%20certification%20that%20will%20include%20Sentinel%20in%20a%20couple%20of%20months.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2078626%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2078626%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3Bthank%20you.%20Is%20there%20any%20other%20course%20where%20we%20can%20get%20a%20certificate%3F%20I%20have%20done%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Flearn%2Fpaths%2Fsecurity-ops-sentinel%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Sentinel's%20official%20learning%20path%3C%2FA%3E%26nbsp%3Byou%20mentioned%20but%20even%20that%20doesn't%20seem%20to%20have%20any%20certificate.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2108203%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2108203%22%20slang%3D%22en-US%22%3E%3CP%3EThere%20is%20no%20link%20for%20Module%202.%20I%20think%20I%20got%20to%20the%20right%20place.%20The%20first%20video%20follows%20with%20%22%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D_mm3GNwPBHU%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EAzure%20Sentinel%20webinar%3A%20Cloud%20%26amp%3B%20On-Premises%20architecture%20-%20YouTube%3C%2FA%3E%22%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D_mm3GNwPBHU%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3E(https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D_mm3GNwPBHU%3C%2FA%3E)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2109509%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2109509%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F947651%22%20target%3D%22_blank%22%3E%40RandyDover%3C%2FA%3E%26nbsp%3B%3A%20I%20don't%20have%20a%20Webinar%20for%20Module%202.%20The%20link%20you%20shared%20was%20the%20Webinar%20for%20Module%203%2C%20but%20was%20since%20updated%2C%20and%20the%20current%20presentations%20for%20Module%203%20are%20more%20up%20to%20date.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2114688%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2114688%22%20slang%3D%22en-US%22%3E%3CP%3EAny%20chance%20of%20you%20lifting%20this%20over%20to%20a%20GitHub%20repo%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3Bwould%20be%20great%20to%20keep%20it%20continually%20updated%20etc.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2116874%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2116874%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F915717%22%20target%3D%22_blank%22%3E%40davidclarke%3C%2FA%3E%26nbsp%3B%3A%20First%2C%20I%20am%20updating%20this%20blog%20on%20an%20ongoing%20basis.%20We%20consider%20moving%20it%20to%20the%20official%20Azure%20Sentinel%20documentation%20so%20it%20is%20not%20a%20workd%20of%20mouth%20kind%20of%20resource.%20Microsoft%20docs%20are%20GitHub%20so%20they%20allow%20anyone%20to%20suggest%20updates%20just%20like%20a%20regular%20GitHub%20repo.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2194130%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2194130%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20sayin'...%20pretty%20awesome%20post%20right%20here!%26nbsp%3B%20I%20will%20be%20using%20this%20as%20I%20prepare%20to%20eventually%20write%20both%20AZ-500%20and%20SC-200.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2201865%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2201865%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20a%20lot%20for%20the%20magnificent%20topic%26nbsp%3B%20..%20I%20believe%20this%20will%20help%20me%20pass%20the%20SC-200%20Exam.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2202721%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2202721%22%20slang%3D%22en-US%22%3E%3CP%3EI%20would%20like%20thank%20you%20for%20this%20article.%3C%2FP%3E%3CP%3EI%20suggest%20to%20add%20courses%20and%20contents%20into%20the%26nbsp%3B%3CSTRONG%3EMicrosoft%20Learn%3C%2FSTRONG%3E%3CSTRONG%3E's%3C%2FSTRONG%3E%20lessons%20website%20as%20it%20is%20a%20fun%20way%20to%20learning%20and%20earn%20badge%20too.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2203479%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2203479%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F972439%22%20target%3D%22_blank%22%3E%40Reza_Ameri%3C%2FA%3E%26nbsp%3B%3A%20in%20module%20zero%2C%20you%20can%20find%20the%20official%20Sentienl%20learning%20path%20as%20well%20as%20the%20SC-200%20certification%20which%20includes%20a%20learning%20path.%20They%20share%20similarties%20with%20(and%20sometimes%20actually%20are%20based%20on)%20the%20Ninja%20training.%26nbsp%3BThe%20latter%20offers%20a%20certification%20based%20on%20the%20conent%26nbsp%3B%20(well%2C%20you%20will%20have%20to%20know%20MDE%20and%20AzD%20as%20well%20to%20certify).%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2205440%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2205440%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3Bfor%20the%20clarification.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2229321%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2229321%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%0A%3CP%3EJust%20a%20heads%20up%20that%20the%20link%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Ftree%2Fmaster%2FWorkbooks%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EPlaybooks%3C%2FSTRONG%3E%20folder%3C%2FA%3E%26nbsp%3Bunder%20Module%209%3A%20SOAR%20currently%20links%20to%20the%20Workbooks%20folder%20in%20Github%2C%20not%20Playbooks%3A%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Ftree%2Fmaster%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Ftree%2Fmaster%2F%3C%2FA%3E%3CSTRONG%3EWorkbooks.%3C%2FSTRONG%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2233873%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2233873%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1005710%22%20target%3D%22_blank%22%3E%40Louise_Wiljander%3C%2FA%3E.%26nbsp%3B%20Corrected.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2291069%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2291069%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EDo%20we%20have%20an%20estimation%20of%20the%20time%20requested%20to%20complete%20this%20training%20%3F%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1246310%22%20slang%3D%22en-US%22%3EBecome%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1246310%22%20slang%3D%22en-US%22%3E%3CP%3E%3CEM%3E%3CSTRONG%3E(Last%20updated%20April%2020th%202021)%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20this%20blog%20post%2C%20I%20try%20to%20walk%20you%20through%20Azure%20Sentinel%20level%20400%20training%20and%20help%20you%20become%20an%20Azure%20Sentinel%20master.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CSTRONG%3EAlready%20did%20the%20Ninja%20Training%3F%20check%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fthe-ninja-training-2021-edition-is-out%2Fba-p%2F2027400%22%20target%3D%22_self%22%3Ewhat's%20new%3C%2FA%3E.%E2%80%8B%E2%80%8B%E2%80%8B%E2%80%8B%E2%80%8B%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--1359172486%22%20id%3D%22toc-hId--1359172486%22%20id%3D%22toc-hId--1359172486%22%20id%3D%22toc-hId--1359172486%22%20id%3D%22toc-hId--1359172486%22%20id%3D%22toc-hId--1359172486%22%20id%3D%22toc-hId--1359172486%22%20id%3D%22toc-hId--1359172486%22%3ECurriculum%26nbsp%3B%3C%2FH2%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Curriculum.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F183841i98A9D4F89F6EE81E%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Curriculum.jpg%22%20alt%3D%22Curriculum.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20training%20program%20includes%2016%20modules.%20The%20post%20includes%20a%20presentation%20for%20each%20module%2C%20preferably%20recorded%20(when%20still%20not%2C%20we%20are%20working%20on%20the%20recording)%20and%20supporting%20information%3A%20relevant%20product%20documentation%2C%20blog%20posts%2C%20and%20other%20resources.%20%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20modules%20listed%20below%20are%20split%20into%20five%20groups%20following%20the%20life%20cycle%20of%20a%20SOC%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--668611012%22%20id%3D%22toc-hId--668611012%22%20id%3D%22toc-hId--668611012%22%20id%3D%22toc-hId--668611012%22%20id%3D%22toc-hId--668611012%22%20id%3D%22toc-hId--668611012%22%20id%3D%22toc-hId--668611012%22%20id%3D%22toc-hId--668611012%22%3EPart%201%3A%20Overview%3C%2FH3%3E%0A%3CP%3E-%20Module%200%3A%20Other%20learning%20and%20support%20options%3C%2FP%3E%0A%3CP%3E-%20Module%201%3A%20Get%20started%20with%20Azure%20Sentinel%3C%2FP%3E%0A%3CP%3E-%20Module%202%3A%20How%20is%20Azure%20Sentinel%20used%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-1818901821%22%20id%3D%22toc-hId-1818901821%22%20id%3D%22toc-hId-1818901821%22%20id%3D%22toc-hId-1818901821%22%20id%3D%22toc-hId-1818901821%22%20id%3D%22toc-hId-1818901821%22%20id%3D%22toc-hId-1818901821%22%20id%3D%22toc-hId-1818901821%22%3EPart%202%3A%20Architecting%20%26amp%3B%20Deploying%3C%2FH3%3E%0A%3CP%3E-%20Module%203%3A%20Workspace%20and%20tenant%20architecture%3C%2FP%3E%0A%3CP%3E-%20Module%204%3A%20Data%20collection%3C%2FP%3E%0A%3CP%3E-%20Module%205%3A%20Log%20Management%3C%2FP%3E%0A%3CP%3E-%20Module%206%3A%20Enrichment%3A%20TI%2C%20Watchlists%2C%20and%20more%3C%2FP%3E%0A%3CP%3E-%20Modele%20X%3A%20Migration%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-11447358%22%20id%3D%22toc-hId-11447358%22%20id%3D%22toc-hId-11447358%22%20id%3D%22toc-hId-11447358%22%20id%3D%22toc-hId-11447358%22%20id%3D%22toc-hId-11447358%22%20id%3D%22toc-hId-11447358%22%20id%3D%22toc-hId-11447358%22%3EPart%203%3A%20Creating%20Content%3C%2FH3%3E%0A%3CP%3E-%20Module%207%3A%20The%20Kusto%20Query%20Language%20(KQL)%3C%2FP%3E%0A%3CP%3E-%20Module%208%3A%20Analytics%3C%2FP%3E%0A%3CP%3E-%20Module%209%3A%20SOAR%3C%2FP%3E%0A%3CP%3E-%20Module%2010%3A%20Workbooks%2C%20reporting%2C%20and%20visualization%3C%2FP%3E%0A%3CP%3E-%20Module%20Y%3A%20Notebooks%3C%2FP%3E%0A%3CP%3E-%20Module%2011%3A%20Use%20cases%20and%20solutions%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--1796007105%22%20id%3D%22toc-hId--1796007105%22%20id%3D%22toc-hId--1796007105%22%20id%3D%22toc-hId--1796007105%22%20id%3D%22toc-hId--1796007105%22%20id%3D%22toc-hId--1796007105%22%20id%3D%22toc-hId--1796007105%22%20id%3D%22toc-hId--1796007105%22%3EPart%204%3A%20Operating%3C%2FH3%3E%0A%3CP%3E-%20Module%2012%3A%26nbsp%3BA%20day%20in%20a%20SOC%20analyst's%20life%2C%20incident%20management%2C%20and%20investigation%3C%2FP%3E%0A%3CP%3E-%20Module%2013%3A%20Hunting%3C%2FP%3E%0A%3CP%3E-%20Module%2014%3A%20User%20and%20Entity%20Behavior%20Analytics%20(UEBA)%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-%20Module%2015%3A%20Monitoring%20Azure%20Sentinel's%20health%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-691505728%22%20id%3D%22toc-hId-691505728%22%20id%3D%22toc-hId-691505728%22%20id%3D%22toc-hId-691505728%22%20id%3D%22toc-hId-691505728%22%20id%3D%22toc-hId-691505728%22%20id%3D%22toc-hId-691505728%22%20id%3D%22toc-hId-691505728%22%3EPart%205%3A%20Advanced%20Topics%3C%2FH3%3E%0A%3CP%3E-%20Module%2016%3A%26nbsp%3BExtending%20and%20Integrating%20using%26nbsp%3BAzure%20Sentinel%20APIs%3C%2FP%3E%0A%3CP%3E-%20Module%2017%3A%20Bring%20your%20own%20ML%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-681002624%22%20id%3D%22toc-hId-681002624%22%20id%3D%22toc-hId-681002624%22%20id%3D%22toc-hId-681002624%22%20id%3D%22toc-hId-681002624%22%20id%3D%22toc-hId-681002624%22%20id%3D%22toc-hId-681002624%22%20id%3D%22toc-hId-681002624%22%3E%3CFONT%20size%3D%226%22%20color%3D%22%230000FF%22%3EPart%201%3A%20Overview%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--1126451839%22%20id%3D%22toc-hId--1126451839%22%20id%3D%22toc-hId--1126451839%22%20id%3D%22toc-hId--1126451839%22%20id%3D%22toc-hId--1126451839%22%20id%3D%22toc-hId--1126451839%22%20id%3D%22toc-hId--1126451839%22%20id%3D%22toc-hId--1126451839%22%3EModule%200%3A%20Other%20learning%20and%20support%20options%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20Ninja%20training%20is%20a%20level%20400%20training.%20If%20you%20don't%20want%20to%20go%20as%20deep%20or%20have%20a%20specific%20issue%2C%20other%20resources%20might%20be%20more%20suitable%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAlready%20did%20the%20Ninja%20Training%3F%20Check%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fthe-ninja-training-2021-edition-is-out%2Fba-p%2F2027400%22%20target%3D%22_self%22%3Ewhat's%20new%3C%2FA%3E%E2%80%8B%20in%20the%20Ninja%20training.%3C%2FLI%3E%0A%3CLI%3EWhile%20extensive%2C%20the%20Ninja%20training%20has%20to%20follow%20a%20script%20and%20cannot%20expand%20on%20every%20topic.%20The%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fasfaq%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EFAQ%20companion%20to%20the%20Ninja%20Training%3C%2FA%3E%20tries%20to%20closed%20this%20gap.%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Flearn%2Fpaths%2Fsecurity-ops-sentinel%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Sentinel's%20official%20learning%20path%3C%2FA%3E%20is%20best%20if%20you%20want%20step-by-step%20training%20to%20use%20Azure%20Sentinel's%20features.%3C%2FLI%3E%0A%3CLI%3EYou%20can%20now%20certify%20with%20the%20new%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Flearn%2Fcertifications%2Fexams%2Fsc-200%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ESC-200%20certification%20(Microsoft%20Security%20Operations%20Analyst)%3C%2FA%3E%26nbsp%3Bwhich%20covers%20Azure%20Sentinel.%20The%26nbsp%3B%20SC-200%20is%20not%20a%20Ninja%20Training%20certification%2C%20but%20the%20exam%20is%20largely%20based%20on%20Ninja%20Training%20materials%2C%20making%20it%20a%20good%20learning%20path%20for%20the%20certification.%20You%20may%20also%20want%20to%20consider%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Flearn%2Fcertifications%2Fexams%2Fsc-900%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ESC-900%20certification%3C%2FA%3E%20(Microsoft%20Security%2C%20Compliance%2C%20and%20Identity%20Fundamentals)%2C%20for%20a%20broader%2C%20higher%20level%20view%20of%20the%20Microsoft%20Secuirty%20suite.%3C%2FLI%3E%0A%3CLI%3EPremier%20customer%3F%20You%20might%20want%20the%20on-site%20(or%20remote%20these%20days)%20%3CA%20href%3D%22https%3A%2F%2Fdatasheets.azureedge.net%2Fdatasheetsv2%2Fnnjfdhzt2q5v-2-11325%2Fen-US.pdf%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EAzure%20Sentinel%20Fundamentals%204%20days%20workshop%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3EAlready%20a%20Ninja%3F%20Just%20keep%20track%20of%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FSentinelAnnouncements%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ewhat's%20new%2C%3C%2FA%3E%26nbsp%3Bor%20join%20our%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FSecurityPrP%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%20data-interception%3D%22on%22%20data-cke-saved-href%3D%22%2Fteams%2FAzureSentinelProductInfo%2FSitePages%2FAzure-Sentinel-General-FAQ.aspx%23my-customer-or-i-want-to-join-a-private-preview%22%3EPrivate%20Previews%3C%2FA%3E%26nbsp%3Bprogram%20for%20an%20even%20earlier%20glimpse.%20Didn't%20find%20what%20you%20are%20looking%20for%3F%26nbsp%3BSubmit%20feature%20requests%20using%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ffeedback.azure.com%2Fforums%2F920458-azure-sentinel%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%20data-cke-saved-href%3D%22https%3A%2F%2Ffeedback.azure.com%2Fforums%2F920458-azure-sentinel%22%3EUservoice%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3EHave%20a%20specific%20issue%3F%20Ask%20(or%20answer%20other)%20on%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2Fbd-p%2FAzureSentinel%22%20target%3D%22_blank%22%20data-cke-saved-href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2Fbd-p%2FAzureSentinel%22%3EAzure%20Sentinel%20Tech%20Community%3C%2FA%3E.%26nbsp%3BAs%20a%20last%20resort%2C%20send%20an%20e-mail%20to%26nbsp%3B%3CA%20href%3D%22mailto%3AAzureSentinel%40microsoft.com%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EAzureSentinel%40microsoft.com%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1361060994%22%20id%3D%22toc-hId-1361060994%22%20id%3D%22toc-hId-1361060994%22%20id%3D%22toc-hId-1361060994%22%20id%3D%22toc-hId-1361060994%22%20id%3D%22toc-hId-1361060994%22%20id%3D%22toc-hId-1361060994%22%20id%3D%22toc-hId-1361060994%22%3EModule%201%3A%20Get%20started%20with%20Azure%20Sentinel%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CSTRONG%3E%3CFONT%20size%3D%224%22%3E%3CEM%3EShort%20on%20time%3F%20Watch%26nbsp%3Bthe%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DJeu0lRjoVs4%26amp%3Bab_channel%3DMicrosoftIgnite%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EFall%20Ignite%20presentation%3C%2FA%3E%3CFONT%20size%3D%222%22%3E%3CBR%20%2F%3E%3C%2FFONT%3E%3C%2FEM%3E%3CEM%3EAlready%20know%3F%20The%20%3CA%20href%3D%22https%3A%2F%2Fmyignite.microsoft.com%2Fsessions%2F3de9574e-1ef8-496a-96d3-309a57831064%3F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ESpring%20Ignite%20session%3C%2FA%3E%3C%2FEM%3E%3CEM%3E%20focuses%20on%3C%2FEM%3E%20what's%20new%20and%20an%20how%20to%20use%20demo%3CEM%3E%3CFONT%20size%3D%222%22%3E%3CBR%20%2F%3E%3CFONT%20size%3D%224%22%3EGet%20deeper%3F%20Watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmggMkcVweWOqoxuN9%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F7An7BB-CcQI%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%2C%3C%2FA%3E%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgjrN_zHpzbnfX_mX%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FFONT%3E%3C%2FFONT%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EMicrosoft%20Azure%20Sentinel%20is%20a%20scalable%2C%20cloud-native%2C%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Esecurity%20information%20event%20management%20(SIEM)%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Band%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Esecurity%20orchestration%20automated%20response%20(SOAR)%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3Bsolution.%20Azure%20Sentinel%20delivers%20intelligent%20security%20analytics%20and%20threat%20intelligence%20across%20the%20enterprise%2C%20providing%20a%20single%20solution%20for%20alert%20detection%2C%20threat%20visibility%2C%20proactive%20hunting%2C%20and%20threat%20response%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Foverview%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3E%3CEM%3Eread%20more%3C%2FEM%3E%3C%2FA%3E).%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20want%20to%20get%20an%20initial%20overview%20of%20Azure%20Sentinel's%20technical%20capabilities%2C%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DJeu0lRjoVs4%26amp%3Bab_channel%3DMicrosoftIgnite%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Elatest%20Ignite%20presentation%3C%2FA%3E%20is%20a%20good%20starting%20point.%20You%20might%20also%20find%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fazure.microsoft.com%2Fen-us%2Fresources%2Fquick-start-guide-to-azure-sentinel%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EQuick%20Start%20Guide%20to%20Azure%20Sentinel%3C%2FA%3E%20useful%20(requires%20registration).%26nbsp%3BA%20more%20detailed%20overview%2C%20however%20somewhat%20dated%2C%20can%20be%20found%20in%20this%20webinar%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmggMkcVweWOqoxuN9%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F7An7BB-CcQI%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%2C%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgjrN_zHpzbnfX_mX%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20data-unlink%3D%22true%22%3ELastly%2C%20want%20to%20try%20it%20yourself%3F%26nbsp%3BThe%26nbsp%3B%3CSPAN%20style%3D%22font-size%3A%2012.0pt%3B%22%3EAzure%20Sentinel%20All-In-One%20Accelerator%3C%2FSPAN%3E%26nbsp%3B%3CSPAN%20style%3D%22font-size%3A%2012.0pt%3B%22%3E%26nbsp%3B(%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-all-in-one-accelerator%2Fba-p%2F1807933%22%20target%3D%22_self%22%3Eblog%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FJB73TuX9DVs%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYoutube%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_04FEB2021_MP4%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhjw41XZvVSCSNIuX%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Edeck%3C%2FA%3E)%20presents%20an%20easy%20way%20to%20get%20you%20started.%20To%20learn%20how%20to%20start%20yourself%2C%20review%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-onboard%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Eonboarding%20documentation%3C%2FA%3E%2C%3C%2FSPAN%3E%3CSPAN%20style%3D%22font-size%3A%2012.0pt%3B%22%3E%26nbsp%3Bor%20watch%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DCyd16wVwxZc%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EInsight's%20Sentinel%20setup%20and%20configuration%20video%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%20style%3D%22font-size%3A%2012.0pt%3B%22%3E.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-2051622468%22%20id%3D%22toc-hId-2051622468%22%20id%3D%22toc-hId-2051622468%22%20id%3D%22toc-hId-2051622468%22%20id%3D%22toc-hId-2051622468%22%20id%3D%22toc-hId-2051622468%22%20id%3D%22toc-hId-2051622468%22%20id%3D%22toc-hId-2051622468%22%3ELearn%20from%20users%3C%2FH3%3E%0A%3CP%3EThousands%20of%20organizations%20and%20service%20providers%20are%20using%20Azure%20Sentinel.%20As%20usual%20with%20security%20products%2C%20most%20do%20not%20go%20public%20about%20that.%20Still%2C%20there%20are%20some.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EYou%20can%20find%20public%20%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fcustomers.microsoft.com%2Fen-us%2Fsearch%3Fsq%3D%2522Azure%2520Sentinel%2520%2522%26amp%3Bff%3D%26amp%3Bp%3D0%26amp%3Bso%3Dstory_publish_date%2520desc%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ecustomer%20use%20cases%20here%2C%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fwww.insightcdct.com%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EInsight%3C%2FA%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%20released%20a%20use%20case%20about%20%3C%2FSPAN%3E%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fwww.insightcdct.com%2FResources%2FCase-Studies%2FCase-Studies%2FNBA-Team-Adopts-Azure-Sentinel-for-a-Modern-Securi%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ean%20NBA%20team%20adapting%20Sentinel%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3EStuart%20Gregg%2C%26nbsp%3BSecurity%20Operations%20Manager%20%40%20ASOS%2C%20posted%20a%20much%20more%20detailed%20%3CA%20href%3D%22https%3A%2F%2Fmedium.com%2F%40stuart.gregg%2Fproactive-phishing-with-azure-sentinel-part-1-b570fff3113%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Eblog%20post%20from%20Azure%20Sentinel's%20experience%2C%20focusing%20on%20hunting%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--450995474%22%20id%3D%22toc-hId--450995474%22%20id%3D%22toc-hId--450995474%22%20id%3D%22toc-hId--450995474%22%20id%3D%22toc-hId--450995474%22%20id%3D%22toc-hId--450995474%22%20id%3D%22toc-hId--450995474%22%20id%3D%22toc-hId--450995474%22%3ELearn%20from%20Analysts%3C%2FH3%3E%0A%3CUL%3E%0A%3CLI%3E%3CSPAN%3E%3CA%20title%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2020%2F12%2F01%2Fazure-sentinel-achieves-a-leader-placement-in-forrester-wave-with-top-ranking-in-strategy%2F%22%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2020%2F12%2F01%2Fazure-sentinel-achieves-a-leader-placement-in-forrester-wave-with-top-ranking-in-strategy%2F%22%20target%3D%22_self%22%20data-cke-saved-href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2020%2F12%2F01%2Fazure-sentinel-achieves-a-leader-placement-in-forrester-wave-with-top-ranking-in-strategy%2F%22%20data-interception%3D%22on%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Sentinel%20is%20a%20Leader%20placement%20in%20Forrester%20Wave%3C%2FA%3E.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1907434640%22%20id%3D%22toc-hId-1907434640%22%20id%3D%22toc-hId-1907434640%22%20id%3D%22toc-hId-1907434640%22%20id%3D%22toc-hId-1907434640%22%20id%3D%22toc-hId-1907434640%22%20id%3D%22toc-hId-1907434640%22%20id%3D%22toc-hId-1907434640%22%3EModule%202%3A%20How%20is%20Azure%20Sentinel%20used%3F%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20read%26nbsp%3Bthis%26nbsp%3B%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Fgxcuf89792%2Fattachments%2Fgxcuf89792%2FAzureSentinelBlog%2F243%2F1%2FL400-P2%2520Use%2520cases.pdf%22%20target%3D%22_blank%22%3Epresentation%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMany%20users%20use%20Azure%20Sentinel%20as%20their%20primary%20SIEM.%20Most%20of%20the%20modules%20in%20this%20course%20cover%20this%20use%20case.%20In%20this%20module%2C%20we%20present%20a%20few%20additional%20ways%20to%20use%20Azure%20Sentinel.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-229062896%22%20id%3D%22toc-hId-229062896%22%20id%3D%22toc-hId-229062896%22%20id%3D%22toc-hId-229062896%22%20id%3D%22toc-hId-229062896%22%20id%3D%22toc-hId-229062896%22%20id%3D%22toc-hId-229062896%22%20id%3D%22toc-hId-229062896%22%3EAs%20part%20of%20the%20Microsoft%20Security%20stack%3C%2FH3%3E%0A%3CP%3EUse%20Sentinel%2C%20Azure%20Defender%2C%20Microsoft%20365%20Defender%26nbsp%3B%20in%20tandem%20to%20protect%20your%20Microsoft%20workloads%2C%20including%20Windows%2C%20Azure%2C%20and%20Office%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ERead%20more%20about%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fwhats-new-azure-sentinel-and-microsoft-365-defender-incident%2Fba-p%2F2191090%22%20target%3D%22_self%22%3Eour%20comprehensive%20SIEM%2BXDR%20solution%20combining%20Azure%20Sentinel%20and%20Microsoft%20365%20Defender%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3ERead%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fazuresecuritycompass%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EThe%20Azure%20Security%20compass%3C%2FA%3E%26nbsp%3Bto%20understand%20Microsoft's%20blueprint%20for%20your%20security%20operations.%3C%2FLI%3E%0A%3CLI%3ERead%20and%20watch%20how%20such%20a%20setup%20helps%20detect%20and%20respond%20to%20a%20WebShell%20attack%3A%26nbsp%3B%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fanalysing-web-shell-attacks-with-azure-defender-data-in-azure%2Fba-p%2F1724130%22%20target%3D%22_self%22%3EBlog%20Post%3C%2FA%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3E%2C%20%3C%2FSPAN%3E%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fvideo-hub%2Fwebshell-attack-deep-dive%2Fm-p%2F1698964%22%20target%3D%22_self%22%3EVideo%20demo.%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--1578391567%22%20id%3D%22toc-hId--1578391567%22%20id%3D%22toc-hId--1578391567%22%20id%3D%22toc-hId--1578391567%22%20id%3D%22toc-hId--1578391567%22%20id%3D%22toc-hId--1578391567%22%20id%3D%22toc-hId--1578391567%22%20id%3D%22toc-hId--1578391567%22%3ETo%20monitor%20your%20multi-cloud%20workloads%3C%2FH3%3E%0A%3CP%3EThe%20cloud%20is%20(still)%20new%20and%20often%20not%20monitored%20as%20extensively%20as%20on-prem%20workloads.%20Read%20this%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Fgxcuf89792%2Fattachments%2Fgxcuf89792%2FAzureSentinelBlog%2F243%2F1%2FL400-P2%2520Use%2520cases.pdf%22%20target%3D%22_blank%22%3Epresentation%3C%2FA%3E%26nbsp%3Bto%20learn%20how%20Azure%20Sentinel%20can%20help%20you%20close%20the%20cloud%20monitoring%20gap%20across%20your%20clouds.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-909121266%22%20id%3D%22toc-hId-909121266%22%20id%3D%22toc-hId-909121266%22%20id%3D%22toc-hId-909121266%22%20id%3D%22toc-hId-909121266%22%20id%3D%22toc-hId-909121266%22%20id%3D%22toc-hId-909121266%22%20id%3D%22toc-hId-909121266%22%3ESide%20by%20side%20with%20your%20existing%20SIEM%3C%2FH3%3E%0A%3CP%3EEither%20for%20a%20transition%20period%20or%20a%20longer%20term%2C%20if%20you%20are%20using%20Azure%20Sentinel%20for%20your%20cloud%20workloads%2C%20you%20may%20be%20using%20Azure%20Sentinel%20alongside%20your%20existing%20SIEM.%20You%20might%20also%20be%20using%20both%20with%20a%20ticketing%20system%20such%20as%20Service%20Now.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20more%20information%20on%20migrating%20from%20another%20SIEM%20to%20Azure%20Sentinel%2C%20watch%20the%20migration%20webinar%3A%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20color%3A%20%23063e6c%3B%20outline%3A%200px%3B%20text-align%3A%20center%3B%22%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_DetectionRules_19FEB21_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20color%3A%20%23063e6c%3B%20outline%3A%200px%3B%20text-align%3A%20center%3B%22%20href%3D%22https%3A%2F%2Fyoutu.be%2FnjXK1h9lfR4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20color%3A%20%23063e6c%3B%20outline%3A%200px%3B%20text-align%3A%20center%3B%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhlsYDm99KLbNWlq5%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck.%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20are%20three%20common%20scenarios%20for%20side%20by%20side%20deployment%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EA%20best%20practice%2C%20if%20you%20have%20a%20ticketing%20system%20in%20your%20SOC%2C%20is%20to%20send%20alerts%2C%20or%20incidents%2C%20from%20both%20SIEM%20systems%20to%20a%20ticketing%20system%20such%20as%20Service%20Now%2C%20for%20example%2C%20using%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-incident-bi-directional-sync-with-servicenow%2Fba-p%2F1667771%22%20target%3D%22_self%22%3EAzure%20Sentinel%20Incident%20Bi-directional%20sync%20with%20ServiceNow%3C%2FA%3E%26nbsp%3Bor%20by%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsending-alerts-enriched-with-supporting-events-from-azure%2Fba-p%2F1456976%22%20target%3D%22_self%22%3Esending%20alerts%20enriched%20with%20supporting%20events%20from%20Azure%20Sentinel%20to%203rd%20party%20SIEMs%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3EAt%20least%20initially%2C%20many%20users%20send%20alerts%20from%20Azure%20sentinel%20to%20your%20on-prem%20SIEM.%20Read%20on%20how%20to%20do%20it%20in%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsending-alerts-enriched-with-supporting-events-from-azure%2Fba-p%2F1456976%22%20target%3D%22_self%22%3ESending%20alerts%20enriched%20with%20supporting%20events%20from%20Azure%20Sentinel%20to%203rd%20party%20SIEMs%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3EOver%20time%2C%20as%20Azure%20Sentinel%20covers%20more%20workloads%2C%20it%20is%20typical%20to%20reverse%20that%20and%20send%20alerts%20from%20your%20on-prem%20SIEM%20to%20Azure%20Sentinel.%20To%20do%20that%3A%0A%3CUL%3E%0A%3CLI%3EWith%20Splunk%2C%20read%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fhow-to-export-data-from-splunk-to-azure-sentinel%2Fba-p%2F1891237%22%20target%3D%22_self%22%3E%22Send%20data%20and%20notable%20events%20from%20Splunk%20to%20Azure%20Sentinel%20using%20the%20Azure%20Sentinel%20Splunk%20App%3C%2FA%3E.%22%3C%2FLI%3E%0A%3CLI%3EWith%20QRadar%20read%26nbsp%3B%3CA%20id%3D%22link_16%22%20class%3D%22page-link%20lia-link-navigation%20lia-custom-event%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fmigrating-qradar-offenses-to-azure-sentinel%2Fba-p%2F2102043%22%20target%3D%22_blank%22%3ESending%20QRadar%20offenses%20to%20Azure%20Sentinel%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3EFor%20ArcSight%2C%20use%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fcommunity.microfocus.com%2Ft5%2FLogger-Forwarding-Connectors%2FArcSight-Forwarding-Connector-Configuration-Guide%2Fta-p%2F1583918%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ECEF%20Forwarding%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EYou%20can%20also%20send%20the%20alerts%20from%20Azure%20Sentinel%20to%20your%203rd%20party%20SIEM%20or%20ticketing%20system%20using%26nbsp%3Bthe%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fgraph%2Fsecurity-siemintegration%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EGraph%20Security%20API%3C%2FA%3E%2C%20which%20is%20simpler%20but%20would%20not%20enable%20sending%20additional%20data.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--898333197%22%20id%3D%22toc-hId--898333197%22%20id%3D%22toc-hId--898333197%22%20id%3D%22toc-hId--898333197%22%20id%3D%22toc-hId--898333197%22%20id%3D%22toc-hId--898333197%22%20id%3D%22toc-hId--898333197%22%20id%3D%22toc-hId--898333197%22%3EFor%20MSSPs%3C%2FH3%3E%0A%3CP%3ESince%20it%20eliminates%20the%20setup%20cost%20and%20is%20location%20agnostics%2C%20Azure%20Sentinel%20is%20a%20popular%20choice%20for%20providing%20SIEM%20as%20a%20service.%20You%20can%20find%20a%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2020%2F07%2F14%2Fmicrosoft-intelligent-security-association-managed-security-service-providers%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Elist%20of%20MISA%20(Microsoft%20Intelligent%20Security%20Association)%20member%20MSSPs%20using%20Azure%20Sentinel%3C%2FA%3E.%20Many%20other%20MSSPs%2C%20especially%20regional%20and%20smaller%20ones%2C%20use%20Azure%20Sentinel%20but%20are%20not%20MISA%20members.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20start%20your%20journey%20as%20an%20MSSP%2C%20you%20should%20read%20the%20%3CA%20href%3D%22http%3A%2F%2Faka.ms%2Fazsentinelmssp%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Sentinel%20Technical%20Playbooks%20for%20MSSPs%3C%2FA%3E.%20More%20information%20about%20MSSP%20support%20is%20included%20in%20the%20next%20Module%2C%20cloud%20architecture%2C%20and%20multi-tenant%20support.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1460096917%22%20id%3D%22toc-hId-1460096917%22%20id%3D%22toc-hId-1460096917%22%20id%3D%22toc-hId-1460096917%22%20id%3D%22toc-hId-1460096917%22%20id%3D%22toc-hId-1460096917%22%20id%3D%22toc-hId-1460096917%22%20id%3D%22toc-hId-1460096917%22%3E%3CFONT%20size%3D%226%22%20color%3D%22%230000FF%22%3EPart%202%3A%20Architecting%20%26amp%3B%20Deploying%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhile%20the%20previous%20section%20offers%20options%20to%20start%20using%20Azure%20Sentinel%20in%20a%20matter%20of%20minutes%2C%20before%20you%20start%20a%20production%20deployment%2C%20you%20need%20to%20plan.%20This%20section%20walks%20you%20through%20the%20areas%20that%20you%20need%20to%20consider%20when%20architecting%20your%20solution%2C%20as%20well%20as%20provides%20guidelines%20on%20how%20to%20implement%20your%20design%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EWorkspace%20and%20tenant%20architecture%3C%2FLI%3E%0A%3CLI%3EData%20collection%26nbsp%3B%3C%2FLI%3E%0A%3CLI%3ELog%20management%3C%2FLI%3E%0A%3CLI%3EThreat%20Intelligence%20acquisition%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--347357546%22%20id%3D%22toc-hId--347357546%22%20id%3D%22toc-hId--347357546%22%20id%3D%22toc-hId--347357546%22%20id%3D%22toc-hId--347357546%22%20id%3D%22toc-hId--347357546%22%20id%3D%22toc-hId--347357546%22%20id%3D%22toc-hId--347357546%22%3EModule%203%3A%20Workspace%20and%20tenant%20architecture%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20Watch%26nbsp%3Bthe%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DJeu0lRjoVs4%26amp%3Bab_channel%3DMicrosoftIgnite%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ENick%20Dicoala's%20Ignite%20presentation%3C%2FA%3E%3CFONT%20size%3D%222%22%3E%20(first%2011%20Minutes)%3CBR%20%2F%3E%3CFONT%20size%3D%224%22%3EGet%20Deeper%3F%20Watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmgkqH7MASAKIg8ql8%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FhwahlwgJPnE%3Ft%3D341%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgkkYuxOITkGSI7x8%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FFONT%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAn%20Azure%20Sentinel%20instance%20is%20called%20a%20workspace.%20The%20workspace%20is%20the%20same%20as%20a%20Log%20Analytics%20workspace%20and%20supports%20any%20Log%20Analytics%20capability.%20You%20can%20think%20of%20Sentinel%20as%20a%20solution%20that%20adds%20SIEM%20features%20on%20top%20of%20a%20Log%20Analytics%20workspace.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMultiple%20workspaces%20are%20often%20necessary%20and%20can%20act%20together%20as%20a%20single%20Azure%20Sentinel%20system.%26nbsp%3BA%20special%20use%20case%20is%20providing%20service%20using%20Azure%20Sentinel%2C%20for%20example%2C%20by%20an%20%3CSTRONG%3EMSSP%3C%2FSTRONG%3E%20(Managed%20Security%20Service%20Provider)%20or%20by%20a%3CSTRONG%3E%20Global%20SOC%3C%2FSTRONG%3E%20in%20a%20large%20organization.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20learn%20more%20about%20why%20use%20multiple%20workspaces%20and%20use%20them%20as%20one%20Azure%20Sentinel%20system%2C%26nbsp%3B%3CSTRONG%3Eread%3C%2FSTRONG%3E%3CSPAN%3E%3CSTRONG%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fextend-sentinel-across-workspaces-tenants%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EExtend%20Azure%20Sentinel%20across%20workspaces%20and%20tenants%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSTRONG%3E%26nbsp%3Bor%2C%20if%20you%20prefer%2C%20the%20Webinar%20version%3A%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmgkqH7MASAKIg8ql8%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FhwahlwgJPnE%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgkkYuxOITkGSI7x8%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FSTRONG%3E.%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EThere%20are%20a%20few%20specific%20areas%20that%20require%20your%20consideration%20when%20using%20multiple%20workspaces%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAn%20important%20driver%20for%20using%20multiple%20workspaces%20is%20%3CSTRONG%3Edata%20residency%3C%2FSTRONG%3E.%20Read%20more%20about%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fquickstart-onboard%23geographical-availability-and-data-residency%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Sentinel%20data%20residency.%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3ETo%20deploy%20Azure%20Sentinel%20and%20manage%20content%20efficiently%20across%20multiple%20workspaces%3B%20you%20would%20like%20to%20manage%20Sentinel%20as%20code%20using%20%3CSTRONG%3ECI%2FCD%20technology%3C%2FSTRONG%3E.%20This%20is%2C%20in%20general%2C%20a%20recommended%20best%20practice%20for%20Azure%20sentinel%3A%0A%3CUL%3E%0A%3CLI%3E%26nbsp%3BRead%26nbsp%3B%3CA%20id%3D%22link_8%22%20class%3D%22page-link%20lia-link-navigation%20lia-custom-event%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdeploying-and-managing-azure-sentinel-ninja-style%2Fba-p%2F1858073%22%20target%3D%22_blank%22%3Edeploying%20and%20Managing%20Azure%20Sentinel%20-%20Ninja%20style%3C%2FA%3E%26nbsp%3Bfor%20a%20comprehensive%20CI%2FCD%20methodology.%3C%2FLI%3E%0A%3CLI%3EOr%20use%20a%20simpler%20solution%20to%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdeploying-and-managing-azure-sentinel-as-code%2Fba-p%2F1131928%22%20target%3D%22_blank%22%3Edeploy%20and%20Managing%20Azure%20Sentinel%20as%20Code%3C%2FA%3E%26nbsp%3Band%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fcombining-azure-lighthouse-with-sentinel-s-devops-capabilities%2Fba-p%2F1210966%22%20target%3D%22_self%22%3E%20extend%20this%20capability%20across%20workspaces%20and%20tenants%20using%20Azure%20Lighthouse.%3C%2FA%3E%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3CLI%3EWhen%20managing%20multiple%20workspaces%20as%20an%20MSSP%2C%20you%20may%20want%20to%20protect%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fmssp-protect-intellectual-property%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ethe%20MSSP%E2%80%99s%20Intellectual%20Property%20in%20Azure%20Sentinel%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20%3CA%20href%3D%22http%3A%2F%2Faka.ms%2Fazsentinelmssp%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Setninel%20Technical%20Playbook%20for%20MSSPs%3C%2FA%3E%26nbsp%3Bprovides%20detailed%20guidelines%20for%20many%20of%20those%20topics%2C%20and%20is%20useful%20also%20for%20large%20organizations%2C%20not%20just%20to%20MSSPs.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-2140155287%22%20id%3D%22toc-hId-2140155287%22%20id%3D%22toc-hId-2140155287%22%20id%3D%22toc-hId-2140155287%22%20id%3D%22toc-hId-2140155287%22%20id%3D%22toc-hId-2140155287%22%20id%3D%22toc-hId-2140155287%22%20id%3D%22toc-hId-2140155287%22%3EModule%204%3A%20Data%20collection%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20Watch%26nbsp%3Bthe%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FDyL9MEMhqmI%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3ENick%20Dicoala's%20Ignite%20presentation%3C%2FA%3E%3CFONT%20size%3D%222%22%3E%20(Mid%2011%20Minutes)%3CBR%20%2F%3E%3CFONT%20size%3D%224%22%3EGet%20Deeper%3F%20Watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F_mm3GNwPBHU%3Ft%3D411%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmggvs6o4EcxYTgvV6%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgjuszn8-jty5Gbx7%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EDeck.%3C%2FA%3E%3C%2FFONT%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20foundation%20of%20a%20SIEM%20is%20collecting%20telemetry%3A%20events%2C%20alerts%2C%20and%20contextual%20enrichment%20information%20such%20as%20Threat%20Intelligence%2C%20vulnerability%20data%2C%20and%20asset%20information.%20You%20can%20find%20a%20list%20of%20sources%20you%20can%20connect%20here%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-data-sources%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EDocumentation%3C%2FA%3E%20of%20the%20connectors%20which%20are%20part%20of%20the%20%3CSTRONG%3Econnectors%20gallery%3C%2FSTRONG%3E%20(63%20as%20of%20this%20writing).%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EThe%20%3CA%20href%3D%22http%3A%2F%2Faka.ms%2Fsentinelgrandlist%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EGrand%20List%3C%2FA%3E%20of%20sources%3C%2FSTRONG%3E%20you%20can%20connect%20to%20Azure%20Sentinel%2C%20whether%20part%20of%20the%20gallery%20or%20not%20(171%20as%20of%20this%20writing).%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHow%20you%20connect%20each%20source%20falls%20into%20several%20categories%20or%20source%20types.%20Each%20source%20type%20has%20a%20distinct%20setup%20effort%20but%20once%20deployed%2C%26nbsp%3B%20it%20serves%20all%20sources%20of%20that%20type.%20The%20Grand%20List%20specifies%20for%20each%20source%20what%20its%20type%20is.%20To%20learn%20more%20about%20those%20categories%2C%26nbsp%3B%3CSTRONG%3Ewatch%20the%20Webinar%20(includes%20Module%203)%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F_mm3GNwPBHU%3Ft%3D411%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmggvs6o4EcxYTgvV6%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgjuszn8-jty5Gbx7%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EDeck.%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20types%20are%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EBuilt-in%20service-to-service%20connectors%3C%2FSTRONG%3E%20allow%20Azure%20Sentinel%20to%20connect%20directly%20to%20cloud%20services%20such%20as%20Office%20365%20or%20AWS%20CloudTrail.%20Some%20of%20the%20service-to-service%20connectors%2C%20such%20as%20AAD%2C%20utilize%20Azure%20diagnostics%20behind%20the%20scenes.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EDirect%3C%2FSTRONG%3E%20refers%20to%20sources%20that%20natively%20know%20how%20to%20send%20data%20to%20Azure%20Sentinel%20or%20Log%20Analytics.%20These%20include%20Azure%20services%20or%20other%20Microsoft%20solutions%20that%20support%20sending%20telemetry%20(often%20referred%20to%20as%20%22%3CSTRONG%3Ediagnostics%3C%2FSTRONG%3E%22)%20to%20Log%20Analytics%20and%203rd%20party%20sources%20that%20use%20the%20ingestion%20API%20to%20write%20to%20Log%20analytics%20or%20Azure%20Sentinel%20directly.%20The%20Microsoft%20direct%20sources%20are%20listed%20in%20addition%20to%20the%20Grand%20List%20and%20in%20the%20blog%20post%20%22%3CA%20tabindex%3D%22-1%22%20title%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-collecting-logs-from-microsoft-services-and%2Fba-p%2F792669%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FAzure-Sentinel-Collecting-logs-from-Microsoft-Services-and%2Fba-p%2F792669%22%20target%3D%22_blank%22%3ECollecting%20logs%20from%20Microsoft%20Services%20and%20Applications.%22%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EThe%20Log%20Forwarder%3C%2FSTRONG%3E%20is%20a%20VM%20that%20enables%20collecting%20Syslog%20and%20CEF%20events%20from%20remote%20systems.%20If%20a%20source%20is%20listed%20in%20the%20Grand%20List%20as%20CEF%20or%20Syslog%2C%20you%20will%20use%20the%20Log%20Forwarder%20to%20collect%20from%20it.%20%3CSTRONG%3ELearn%20more%20about%20the%20Log%20Forwarder%20in%20this%20webinar%26nbsp%3B(plus%20a%20bonus%3A%20learn%20how%20to%20use%20it%20to%20filter%20events)%3A%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2Fjtv-k2CyH-g%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmg13iygEzKzKzKKPf%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmg17QwR3scS4N4DiJ%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3C%2FSTRONG%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EThe%20%3CSTRONG%3ELog%20Analytics%20agent%3C%2FSTRONG%3E%20collects%20information%20from%20Windows%20or%20Linux%20hosts.%20In%20addition%20to%20OS%20events%20such%20as%20Windows%20Events%2C%20the%20agent%20can%20collect%20events%20stored%20in%20files.%20Learn%20more%20about%20the%20Log%20Analytics%20agent%20in%20this%20blog%3A%26nbsp%3B%3CA%20tabindex%3D%22-1%22%20title%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-agent-collecting-telemetry-from-on-prem-and-iaas%2Fba-p%2F811760%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FAzure-Sentinel%2FAzure-Sentinel-Agent-Collecting-telemetry-from-on-prem-and-IaaS%2Fba-p%2F811760%22%20target%3D%22_blank%22%3Ecollecting%20telemetry%20from%20on-prem%20and%20IaaS%20server%20using%20the%20Log%20Analytics%20agent%3C%2FA%3E.%20The%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fazure-monitor-agent-overview%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Monitor%20Agent%3C%2FA%3E%20is%20a%20new%20generation%20agent%20currently%20in%20preview%20that%20offers%20advantages%20such%20as%20Windows%20events%20filtering.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EELK's%20%3CSTRONG%3ELogstash%20and%20Beats%3C%2FSTRONG%3E%20can%20be%20used%20as%20an%20alternative%20to%20both%20the%20agent%20and%20Log%20Forwarder%20using%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fconnect-logstash%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Sentinel%20Logstash%20output%20plug-in%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EIntegrate%20%3CSTRONG%3EThreat%20Intelligence%20(TI)%20sources%3C%2FSTRONG%3E%20using%20the%20built-in%20connectors%20from%20TAXII%20servers%20or%20Microsoft%20Graph%20Security%20API.%26nbsp%3B%3CSPAN%3ERead%20more%20on%20how%20to%20in%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fimport-threat-intelligence%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation.%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3BTI%20can%20also%20be%20important%20as%20a%20custom%20log%20using%20a%20custom%20connector%20or%20as%20a%20lookup%20table.%26nbsp%3B%3C%2FSPAN%3EYou%20can%20read%20more%20about%20how%20TI%20is%20used%20managed%20in%20Azure%20Azure%20in%20the%20TI%20modules%20later.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20your%20source%20is%20not%20available%2C%20you%20can%20%3CSTRONG%3Ecreate%20a%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fcreate-custom-connector%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ecustom%20connector%3C%2FA%3E%3C%2FSTRONG%3E.%20Custom%20connectors%20use%20the%20ingestion%20API%20and%20therefore%20are%20similar%20to%20direct%20sources.%20Custom%20connectors%20are%20most%20often%20implemented%20using%20Logic%20Apps%2C%20offering%20a%20codeless%20option%2C%20or%20Azure%20Functions.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-332700824%22%20id%3D%22toc-hId-332700824%22%20id%3D%22toc-hId-332700824%22%20id%3D%22toc-hId-332700824%22%20id%3D%22toc-hId-332700824%22%20id%3D%22toc-hId-332700824%22%20id%3D%22toc-hId-332700824%22%20id%3D%22toc-hId-332700824%22%3EModule%205%3A%20Log%20Management%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhile%20how%20many%20and%20which%20workspaces%20to%20use%20is%20the%20first%20architecture%20question%20to%20ask%2C%20there%20are%20additional%20log%20management%20architectural%20decisions%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EWhere%20and%20how%20long%20to%20retain%20data.%3C%2FLI%3E%0A%3CLI%3EHow%20to%20best%20manage%20access%20to%20data%20and%20secure%20it.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--647508979%22%20id%3D%22toc-hId--647508979%22%20id%3D%22toc-hId--647508979%22%20id%3D%22toc-hId--647508979%22%20id%3D%22toc-hId--647508979%22%20id%3D%22toc-hId--647508979%22%20id%3D%22toc-hId--647508979%22%20id%3D%22toc-hId--647508979%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3ERetention%3C%2FSPAN%3E%3C%2FH3%3E%0A%3CUL%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EIf%20you%20want%20to%20retain%20data%20for%20more%20than%20two%20years%20or%20reduce%20the%20retention%20cost%2C%20you%20can%20consider%26nbsp%3Busing%20Azure%20Data%20Explorer%20for%20long-term%20retention%20of%20Azure%20Sentinel%20logs%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3A%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmh0Nnt2bnuFtMWKOL%3Fe%3DW0aiZ9%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EWebinar%20Slides%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FUO8zeTxgeVw%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EWebinar%20Recording%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fusing-azure-data-explorer-for-long-term-retention-of-azure%2Fba-p%2F1883947%22%20target%3D%22_self%22%3EBlog%3C%2FA%3E)%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EIf%26nbsp%3Byou%20prefer%20another%20long-term%20retention%20solution%2C%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fcli%2Fazure%2Fmonitor%2Flog-analytics%2Fworkspace%2Fdata-export%3Fview%3Dazure-cli-latest%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Eexport%20from%20Azure%20Sentinel%20%2F%20Log%20Analytics%20to%20Azure%20Storage%20and%20Event%20Hub%3C%2FA%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3Eor%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Flogs-export-logic-app%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Emove%20Logs%20to%20Long-Term%20Storage%20using%20Logic%20Apps%3C%2FA%3E.%20The%20latter%20advantage%20is%20that%20it%20can%20export%20historical%20data.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3ELastly%2C%20you%20can%20set%20fine-grained%20retention%20periods%20using%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fpremier-field-engineering%2Fazure-log-analytics-data-retention-by-type-in-real-life%2Fba-p%2F1416287%22%20target%3D%22_self%22%3Etable-level%20retention%20Settings%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3B(and%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fnew-per-data-type-retention-is-now-available-for-azure-sentinel%2Fba-p%2F917316%22%20target%3D%22_blank%22%3Edocumentation%3C%2FA%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E)%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-1840003854%22%20id%3D%22toc-hId-1840003854%22%20id%3D%22toc-hId-1840003854%22%20id%3D%22toc-hId-1840003854%22%20id%3D%22toc-hId-1840003854%22%20id%3D%22toc-hId-1840003854%22%20id%3D%22toc-hId-1840003854%22%20id%3D%22toc-hId-1840003854%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3ELogs%20Security%3C%2FSPAN%3E%3C%2FH3%3E%0A%3CUL%3E%0A%3CLI%3EUse%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fcontrolling-access-to-azure-sentinel-data-resource-rbac%2Fba-p%2F1301463%22%20target%3D%22_self%22%3E%20resource%20RBAC%3C%2FA%3E%26nbsp%3Bor%20%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Ftable-level-rbac-in-azure-sentinel%2Fba-p%2F965043%22%20target%3D%22_blank%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3Etable%20Level%20RBAC%3C%2FSPAN%3E%3C%2FA%3E%26nbsp%3Bto%20enable%20multiple%20teams%20to%20use%20a%20single%20workspace.%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EIf%20needed%2C%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-gb%2Fazure%2Fazure-monitor%2Fplatform%2Fpersonal-data-mgmt%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3Edelete%20PII%20data%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3Bfrom%20your%20workspaces.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fauditing-azure-sentinel-activities%2Fba-p%2F1718328%22%20target%3D%22_self%22%3ELearn%20how%20to%20audit%20workspace%20queries%20and%20Azure%20Sentinel%20use%3C%2FA%3E%2C%20using%20alerts%20workbooks%20and%20queries.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3EUse%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fprivate-link-security%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Eprivate%20links%3C%2FA%3E%26nbsp%3Bto%20ensure%20logs%20never%20leave%20your%20private%20network.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-32549391%22%20id%3D%22toc-hId-32549391%22%20id%3D%22toc-hId-32549391%22%20id%3D%22toc-hId-32549391%22%20id%3D%22toc-hId-32549391%22%20id%3D%22toc-hId-32549391%22%20id%3D%22toc-hId-32549391%22%20id%3D%22toc-hId-32549391%22%3EDedicated%20cluster%3C%2FH3%3E%0A%3CUL%3E%0A%3CLI%3EMore%20than%201TB%2Fd%3F%20You%20can%20have%20your%20own%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Flogs-dedicated-clusters%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ELog%20Analytics%20dedicated%20cluster%3C%2FA%3E.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--1903987791%22%20id%3D%22toc-hId--1903987791%22%20id%3D%22toc-hId--1903987791%22%20id%3D%22toc-hId--1903987791%22%20id%3D%22toc-hId--1903987791%22%20id%3D%22toc-hId--1903987791%22%20id%3D%22toc-hId--1903987791%22%20id%3D%22toc-hId--1903987791%22%3EModule%206%3A%20Enrichment%3A%20TI%2C%20Watchlists%2C%20and%20more%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOne%20of%20the%20important%20functions%20of%20a%20SIEM%20is%20to%20apply%20contextual%20information%20to%20the%20event%20steam%2C%20enabling%20detection%2C%20alert%20prioritization%2C%20and%20incident%20investigation.%20Contextual%20information%20includes%2C%20for%20example%2C%20threat%20intelligence%2C%20IP%20intelligence%2C%20host%20and%20user%20information%2C%20and%20watchlists.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Sentinel%20provides%20comprehensive%20tools%20to%20import%2C%20manage%2C%20and%20use%20threat%20intelligence.%20For%20other%20types%20of%20contextual%20information%2C%20Azure%20Sentinel%20provides%20Watchlists%2C%20as%20well%20as%20alternative%20solutions.%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-712607761%22%20id%3D%22toc-hId-712607761%22%20id%3D%22toc-hId-712607761%22%20id%3D%22toc-hId-712607761%22%20id%3D%22toc-hId-712607761%22%20id%3D%22toc-hId-712607761%22%20id%3D%22toc-hId-712607761%22%20id%3D%22toc-hId-712607761%22%3EThreat%20Intelligence%3C%2FH3%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DRLt05JaOnHc%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EIgnite%20session%3C%2FA%3E%3CFONT%20size%3D%222%22%3E%20(28%20Minutes)%3CBR%20%2F%3E%3C%2FFONT%3E%3CFONT%20size%3D%222%22%3E%3CFONT%20size%3D%224%22%3EGet%20Deeper%3F%20Watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FzfoVe4iarto%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmgi8zazMLahRyycPf%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgi0pABN930p56id_%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FFONT%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThreat%20Intelligence%20is%20an%20important%20building%20block%20of%20a%20SIEM.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20Azure%20Sentinel%2C%20you%20can%26nbsp%3Bintegrate%20threat%20intelligence%20(TI)%20using%20the%20built-in%20connectors%20from%20TAXII%20servers%20or%20through%20the%20Microsoft%20Graph%20Security%20API.%26nbsp%3B%3CSPAN%3ERead%20more%20on%20how%20to%20in%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fimport-threat-intelligence%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation.%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3BRefer%20to%20the%20data%20collection%20modules%20for%20more%20information%20about%20importing%20Threat%20Intelligence.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOnce%20imported%2C%20Threat%20Intelligence%20is%20used%20extensively%20throughout%20Azure%20Sentinel%20and%20is%20weaved%20into%20the%20different%20modules.%20The%20following%20features%20focus%20on%20using%20Threat%20Intelligence%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EView%20and%20manage%20the%20imported%20threat%20intelligence%20in%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ELogs%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Ein%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fimport-threat-intelligence%23manage-your-threat-indicators-in-the-new-threat-intelligence-area-of-azure-sentinel%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Enew%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EThreat%20Intelligence%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Earea%3C%2FA%3E%20of%20Azure%20Sentinel.%3C%2FLI%3E%0A%3CLI%3EUse%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fimport-threat-intelligence%23analytics-puts-your-threat-indicators-to-work-detecting-potential-threats%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ebuilt-in%3CSTRONG%3E%26nbsp%3BTI%26nbsp%3BAnalytics%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Erule%20templates%3C%2FA%3E%20to%20generate%20security%20alerts%20and%20incidents%20using%20your%20imported%20threat%20intelligence.%3C%2FLI%3E%0A%3CLI%3EVisualize%20key%20information%20about%20your%20threat%20intelligence%20in%20Azure%20Sentinel%20with%20the%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fimport-threat-intelligence%23workbooks-provide-insights-about-your-threat-intelligence%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EThreat%20Intelligence%20workbook%3C%2FSTRONG%3E%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CDIV%20class%3D%22wiki-section-and-add%22%3E%0A%3CDIV%20id%3D%22section-6%22%20class%3D%22ts-wiki-section%22%20tabindex%3D%22-1%22%3E%0A%3CDIV%20class%3D%22wiki-canvas-inside-section%22%3E%0A%3CH3%20class%3D%22ts-wiki-section-view%22%20id%3D%22toc-hId--1094846702%22%20id%3D%22toc-hId--1094846702%22%20id%3D%22toc-hId--1094846702%22%20id%3D%22toc-hId--1094846702%22%20id%3D%22toc-hId--1094846702%22%20id%3D%22toc-hId--1094846702%22%20id%3D%22toc-hId--1094846702%22%20id%3D%22toc-hId--1094846702%22%3EWatchlists%20and%20other%20lookup%20mechanisms%3C%2FH3%3E%0A%3CDIV%20class%3D%22ts-wiki-section-view%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22ts-wiki-section-view%22%3ETo%20import%20and%20manage%20any%20type%20of%20contextual%20information%2C%20Azure%20Sentinel%20provides%20Watchlists%2C%20which%20enable%20you%20to%20upload%20data%20tables%20in%20CSV%20format%20and%20use%20them%20in%20your%20KQL%20queries.%20Read%20more%20about%20Watchlists%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fwatchlists%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E.%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22ts-wiki-section-view%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22ts-wiki-section-view%22%3EIn%20addition%20to%20Watchlists%2C%20you%20can%20also%20use%20the%20KQL%20externaldata%20operator%2C%20custom%20logs%2C%20and%20KQL%20functions%20to%20manage%20and%20query%20context%20information.%20Each%20one%20of%20the%20four%20methods%20has%20its%20pros%20and%20cons%2C%20and%20you%20can%20read%20more%20about%20the%20comparison%20between%20those%20options%20in%20the%20blog%20post%20%22%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fimplementing-lookups-in-azure-sentinel%2Fba-p%2F1091306%22%20target%3D%22_self%22%3EImplementing%20Lookups%20in%20Azure%20Sentinel%3C%2FA%3E.%22%20While%20each%20method%20is%20different%2C%20using%20the%20resulting%20information%20in%20your%20queries%20is%20similar%20enabling%20easy%20switching%20between%20them.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22ts-wiki-section-view%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%3ERead%20utilize%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Futilize-watchlists-to-drive-efficiency-during-azure-sentinel%2Fba-p%2F2090711%22%20target%3D%22_self%22%3EWatchlists%20to%20Drive%20Efficiency%20During%20Azure%20Sentinel%20Investigations%3C%2FA%3E%20for%20ideas%20on%20using%20Watchlist%20outside%20of%20analytic%20rules.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22ts-wiki-section-view%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22ts-wiki-section-view%22%3E%0A%3CH2%20id%3D%22toc-hId-1263583412%22%20id%3D%22toc-hId-1263583412%22%20id%3D%22toc-hId-1263583412%22%20id%3D%22toc-hId-1263583412%22%20id%3D%22toc-hId-1263583412%22%20id%3D%22toc-hId-1263583412%22%20id%3D%22toc-hId-1263583412%22%20id%3D%22toc-hId-1263583412%22%3EModule%20X%3A%20Migration%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CSTRONG%3E%3CFONT%20size%3D%224%22%3E%3CEM%3EWatch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FnjXK1h9lfR4%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_DetectionRules_19FEB21_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhlsYDm99KLbNWlq5%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20many%20(if%20not%20most)%20cases%2C%20you%20already%20have%20a%20SIEM%20and%20need%20to%20migrate%20to%20Azure%20Sentinel.%20While%20it%20may%20be%20a%20good%20time%20to%20start%20over%20and%20rethink%20your%20SIEM%20implementation%2C%20it%20makes%20sense%20to%20utilize%20some%20of%20the%20assets%20you%20already%20built%20in%20your%20current%20implementation.%20To%20start%20watch%20our%20webinar%20describing%26nbsp%3Bbest%20practices%20for%20converting%20detection%20rules%20from%20Splunk%2C%20QRadar%2C%20and%20ArcSight%20to%20Azure%20Sentinel%20Rules%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FnjXK1h9lfR4%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_DetectionRules_19FEB21_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhlsYDm99KLbNWlq5%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fbest-practices-for-migrating-detection-rules-from-arcsight%2Fba-p%2F2216417%22%20target%3D%22_self%22%3Eblog%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20might%20also%20be%20interested%20in%20some%20of%20the%20resources%20presented%20in%20the%20blog%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Fblob%2Fmaster%2FTools%2FRuleMigration%2FSPL%2520to%2520KQL.md%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ESplunk%20SPL%20to%20KQL%20mappings%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Fblob%2Fmaster%2FTools%2FRuleMigration%2FRule%2520Logic%2520Mappings.md%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EArcSight%20and%20QRadar%20rule%20mapping%20samples%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CH2%20id%3D%22toc-hId--543871051%22%20id%3D%22toc-hId--543871051%22%20id%3D%22toc-hId--543871051%22%20id%3D%22toc-hId--543871051%22%20id%3D%22toc-hId--543871051%22%20id%3D%22toc-hId--543871051%22%20id%3D%22toc-hId--543871051%22%20id%3D%22toc-hId--543871051%22%3E%3CFONT%20size%3D%226%22%20color%3D%22%230000FF%22%3EPart%203%3A%20Creating%20Content%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhat%20is%20Azure%20Sentinel's%20content%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Sentinel%20security%20value%20is%20a%20combination%20of%20its%20built-in%20capabilities%20such%20as%20UEBA%2C%20Machine%20Learning%2C%20or%20out-of-the-box%20analytics%20rules%20and%20your%20capability%20to%20create%20custom%20capabilities%20and%20customize%20built-in%20ones.%20Customized%20SIEM%20capabilities%20are%20often%20referred%20to%20as%20%22content%22%20and%20include%20analytic%20rules%2C%20hunting%20queries%2C%20workbooks%2C%20playbooks%2C%20and%20more.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20this%20section%2C%20we%20grouped%20the%20modules%20that%20help%20you%20learn%20how%20to%20create%20such%20content%20or%20modify%20built-in-content%20to%20your%20needs.%26nbsp%3B%20We%20start%20with%20KQL%2C%20the%20Lingua%20Franca%20of%20Azure%20Sentinel.%20The%20following%20modules%20discuss%20one%20of%20the%20content%20building%20blocks%20such%20as%20rules%2C%20playbooks%2C%20and%20workbooks.%20We%20wrap%20up%20by%20discussing%20use%20cases%2C%20which%20encompass%20elements%20of%20different%20types%20to%20address%20specific%20security%20goals%20such%20as%20threat%20detection%2C%20hunting%2C%20or%20governance.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1943641782%22%20id%3D%22toc-hId-1943641782%22%20id%3D%22toc-hId-1943641782%22%20id%3D%22toc-hId-1943641782%22%20id%3D%22toc-hId-1943641782%22%20id%3D%22toc-hId-1943641782%22%20id%3D%22toc-hId-1943641782%22%20id%3D%22toc-hId-1943641782%22%3EModule%207%3A%20KQL%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20Start%20at%20the%20beginning%20and%20go%20as%20far%20as%20time%20allows.%3CFONT%20size%3D%222%22%3E%3CBR%20%2F%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EMost%20Azure%20Sentinel%20capabilities%20use%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fkusto%2Fquery%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EKQL%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3Bor%20Kusto%20Query%20Language.%20When%20you%20search%20in%20your%20logs%2C%20write%20rules%2C%20create%20hunting%20queries%2C%20or%20design%20workbooks%2C%20you%20use%20KQL.%26nbsp%3B%20Note%20that%20the%20next%20section%20on%20writing%20rules%20explains%20how%20to%20use%20KQL%20in%20the%20specific%20context%20of%20SIEM%20rules.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20suggest%20you%20follow%20this%20Sentinel%20KQL%20journey%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20style%3D%22color%3A%20%23063e6c%3B%20outline%3A%200px%3B%22%20href%3D%22https%3A%2F%2Fwww.pluralsight.com%2Fcourses%2Fkusto-query-language-kql-from-scratch%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPluralsight%20KQL%20course%3C%2FA%3E%26nbsp%3B-%20the%20basics%3C%2FLI%3E%0A%3CLI%3EThe%20Azure%20Sentinel%20%3CSTRONG%3EKQL%20Lab%3C%2FSTRONG%3E%3A%20An%20interactive%20lab%20teaching%20KQL%20focusing%20on%20what%20you%20need%20for%20Azure%20Sentinel%3A%0A%3COL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Flearn%2Fpaths%2Fsc-200-utilize-kql-for-azure-sentinel%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ELearning%20module%20(SC-200%20part%204)%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhWSUcV-O-QIVxkAR%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EDeck%3C%2FA%3E%2C%20%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Faka.ms%2Flademo%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ELab%20URL%3C%2FA%3E%26nbsp%3B%3C%2FLI%3E%0A%3CLI%3Ea%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2Fjjsantanna%2Fazure_sentinel_learn_kql_lab%2Fblob%2Fmaster%2Fazure_sentinel_learn_kql_lab.ipynb%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EJupyter%20Notebooks%20version%3C%2FA%3E%20contributed%20by%20jjsantanna%2C%20which%20let%20you%20test%20the%20queries%20within%20the%20notebook.%3C%2FLI%3E%0A%3CLI%3ELearning%20webinar%3A%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fyoutu.be%2FEDCBLULjtCM%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYoutube%3C%2FA%3E%2C%20%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmglwAjUjmYy2Qn5J-%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EMP4%3B%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3EReviewing%20lab%20solutions%20webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FYKD_OFLMpf8%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_KQL2_28JUL20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3C%2FLI%3E%0A%3CLI%3E%3CA%20style%3D%22color%3A%20%23063e6c%3B%20outline%3A%200px%3B%22%20href%3D%22https%3A%2F%2Fwww.pluralsight.com%2Fcourses%2Fmicrosoft-azure-data-explorer-advanced-query-capabilities%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPluralsight%20Advanced%20KQL%20course%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EOptimizing%20Azure%20Sentinel%20KQL%3C%2FSTRONG%3E%20queries%20performance%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FjN1Cz0JcLYU%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_09SEP20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmg2imjIS8NABc26b-%3Fe%3DrXZrR5%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20might%20also%20find%20the%20following%20reference%20information%20useful%20as%20you%20learn%20KQL%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Fwww.mbsecure.nl%2Fblog%2F2019%2F12%2Fkql-cheat-sheet%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EThe%20KQL%20Cheat%20Sheet%3C%2FA%3E%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Fquery-optimization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EQuery%20optimization%20best%20practices%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-136187319%22%20id%3D%22toc-hId-136187319%22%20id%3D%22toc-hId-136187319%22%20id%3D%22toc-hId-136187319%22%20id%3D%22toc-hId-136187319%22%20id%3D%22toc-hId-136187319%22%20id%3D%22toc-hId-136187319%22%20id%3D%22toc-hId-136187319%22%3EModule%208%3A%20Analytics%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--844022484%22%20id%3D%22toc-hId--844022484%22%20id%3D%22toc-hId--844022484%22%20id%3D%22toc-hId--844022484%22%20id%3D%22toc-hId--844022484%22%20id%3D%22toc-hId--844022484%22%20id%3D%22toc-hId--844022484%22%20id%3D%22toc-hId--844022484%22%3EWriting%20Scheduled%20Analytics%20Rules%3C%2FH3%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmghlWrlBCPKwT5WTT%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FpJjljBT4ipQ%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgmffNHf0wqmNEqdx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Sentinel%20enables%20you%20to%20use%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-detect-threats-built-in%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ebuilt-in%20rule%20templates%3C%2FA%3E%2C%20customize%20the%20templates%20for%20your%20environment%2C%20or%20create%20custom%20rules.%20The%20core%20of%20the%20rules%20is%20a%20KQL%20query%3B%20however%2C%20there%20is%20much%20more%20than%20that%20to%20configure%20in%20a%20rule.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20learn%20the%20procedure%26nbsp%3Bfor%20creating%20rules%2C%20read%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-detect-threats-custom%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E.%20To%20learn%20how%20to%20write%20rules%2C%20i.e.%2C%20what%20should%20go%20into%20a%20rule%2C%20focusing%20on%20KQL%20for%20rules%2C%26nbsp%3B%3CSTRONG%3Ewatch%20the%20webinar%3A%20%3C%2FSTRONG%3E%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmghlWrlBCPKwT5WTT%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%3C%2FSTRONG%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FpJjljBT4ipQ%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%3C%2FSTRONG%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgmffNHf0wqmNEqdx%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPresentation%3C%2FA%3E.%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESIEM%20rules%20have%20specific%20patterns.%20Learn%20how%20to%20implement%20rules%20and%20write%20KQL%20for%20those%20patterns%3A%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3ECorrelation%20rules%3C%2FSTRONG%3E%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-correlation-rules-active-lists-out-make-list-in%2Fba-p%2F1029225%22%20target%3D%22_blank%22%3Eusing%20lists%20and%20the%20%22in%22%20operator%3C%2FA%3E%26nbsp%3Bor%20using%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-correlation-rules-the-join-kql-operator%2Fba-p%2F1041500%22%20target%3D%22_blank%22%3Ethe%20%22join%22%20operator%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EAggregation%3C%2FSTRONG%3E%3A%20see%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-correlation-rules-active-lists-out-make-list-in%2Fba-p%2F1029225%22%20target%3D%22_blank%22%3Eusing%20lists%20and%20the%20%22in%22%20operator%3C%2FA%3E%26nbsp%3Babove%2C%20or%20a%20more%20advanced%20pattern%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fhandling-sliding-windows-in-azure-sentinel-rules%2Fba-p%2F1505394%22%20target%3D%22_self%22%3Ehandling%20sliding%20windows%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3ELookups%3C%2FSTRONG%3E%3A%26nbsp%3B%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fimplementing-lookups-in-azure-sentinel-part-1-reference-files%2Fba-p%2F1091306%22%20target%3D%22_blank%22%3ERegular%3C%2FA%3E%2C%20or%26nbsp%3B%3CA%20id%3D%22link_7%22%20class%3D%22page-link%20lia-link-navigation%20lia-custom-event%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fapproximate-partial-and-combined-lookups-in-azure-sentinel%2Fba-p%2F1393795%22%20target%3D%22_blank%22%3EApproximate%2C%20partial%20%26amp%3B%20combined%20lookups%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fhandling-false-positives-in-azure-sentinel%2Fba-p%2F2158352%22%20target%3D%22_self%22%3EHandling%20false%20positives%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EDelayed%20events%3C%2FSTRONG%3E%3A%20are%20a%20fact%20of%20life%20in%20any%20SIEM%20and%20are%20hard%20to%20tackle.%20Azure%20Sentinel%20can%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fhandling-ingestion-delay-in-azure-sentinel-scheduled-alert-rules%2Fba-p%2F2052851%22%20target%3D%22_self%22%3Ehelp%20you%20mitigate%20delays%20in%20your%20rules%3C%2FA%3E.%3C%2FLI%3E%0A%3CLI%3EUsing%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Ffunctions%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EKQL%20functions%3C%2FA%3E%20as%20%3CSTRONG%3Ebuilding%20blocks%3C%2FSTRONG%3E%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fenriching-windows-security-events-with-parameterized-function%2Fba-p%2F1712564%22%20target%3D%22_self%22%3EEnriching%20Windows%20Security%20Events%20with%20Parameterized%20Function%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20blog%20post%20%22%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fmicrosoft-ignite-2021-blob-and-file-storage-investigations%2Fba-p%2F2175138%22%20target%3D%22_self%22%3EBlob%20and%20File%20Storage%20Investigations%3C%2FA%3E%22%20provides%20a%20step%20by%20step%20example%20of%20writing%20a%20useful%20analytic%20rule.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-1643490349%22%20id%3D%22toc-hId-1643490349%22%20id%3D%22toc-hId-1643490349%22%20id%3D%22toc-hId-1643490349%22%20id%3D%22toc-hId-1643490349%22%20id%3D%22toc-hId-1643490349%22%20id%3D%22toc-hId-1643490349%22%20id%3D%22toc-hId-1643490349%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EUsing%20built-in%20analytics%3C%2FSPAN%3E%3C%2FH3%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20Machine%20Learning%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_12JAN2021_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FDxZXHvq1jOs%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhgUqL5UfmNuKNa81%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EBefore%20embarking%20on%20your%20own%20rule%20writing%2C%20you%20should%20take%20advantage%20of%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-detect-threats-built-in%23about-out-of-the-box-detections%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ebuilt-in%20analytics%3C%2FA%3E%20capabilities.%20Those%20do%20not%20require%20much%20from%20you%2C%20but%20it%20is%20worthwhile%20learning%20about%20them%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EUse%20the%20built-in%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-detect-threats-built-in%23use-out-of-the-box-detections%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Escheduled%20rule%20templates%3C%2FA%3E.%20You%20can%20tune%20those%20templates%20by%20modifying%20the%20templates%20the%20same%20way%20to%20edit%20any%20scheduled%20rule.%20Make%20sure%20to%20deploy%20the%20templates%20for%20the%20data%20connectors%20you%20connect%20listed%20in%20the%20data%20connector%20%22next%20steps%22%20tab.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3ELearn%20more%20about%20Azure%20Sentinel's%20Machine%20learning%20c%3C%2FSPAN%3Eapabilities%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_12JAN2021_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FDxZXHvq1jOs%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhgUqL5UfmNuKNa81%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EFind%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ffusion%23attack-detection-scenarios%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Elist%20of%20Azure%20Sentinel's%20Advanced%20multi-stage%20attack%20detections%3C%2FA%3E%20(%22fusion%22)%20are%20enabled%20by%20default.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--293046833%22%20id%3D%22toc-hId--293046833%22%20id%3D%22toc-hId--293046833%22%20id%3D%22toc-hId--293046833%22%20id%3D%22toc-hId--293046833%22%20id%3D%22toc-hId--293046833%22%20id%3D%22toc-hId--293046833%22%20id%3D%22toc-hId--293046833%22%3EModule%209%3A%20Implementing%20SOAR%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20Webinar%3A%20%3C%2FSTRONG%3E%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FG6TIzJK8XBA%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_LA_30SEP20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhAKStlujGha80s6c%3Fe%3Dn7Zvrw%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20modern%20SIEMs%20such%20as%20Azure%20Sentinel%2C%20SOAR%20(Security%20Orchestration%2C%20Automation%2C%20and%20Response)%20comprises%20the%20entire%20process%20from%20the%20moment%20an%20incident%20is%20triggered%20and%20until%20it%20is%20resolved.%20This%20process%20starts%20with%20an%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-investigate-cases%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Eincident%20investigation%3C%2FA%3E%20and%20continues%20with%20an%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-respond-threats-playbook%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Eautomated%20response%3C%2FA%3E.%20The%20blog%20post%20%22%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fhow-to-use-azure-sentinel-for-incident-response-orchestration%2Fba-p%2F2242397%22%20target%3D%22_self%22%3EHow%20to%20use%20Azure%20Sentinel%20for%20Incident%20Response%2C%20Orchestration%20and%20Automation%3C%2FA%3E%22%20provides%20an%20overview%20of%20common%20use%20cases%20for%20SOAR.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fwhat-s-new-automation-rules%2Fba-p%2F2216926%22%20target%3D%22_self%22%3EAutomation%20rules%3C%2FA%3E%20are%20the%20starting%20point%20for%20Azure%20Sentinel%20automation.%20They%20provide%20a%20lightweight%20method%20for%20central%20automated%20handling%20of%20incidents%2C%20including%20suppression%2C%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fhandling-false-positives-in-azure-sentinel%2Fba-p%2F2158352%22%20target%3D%22_self%22%3Efalse-positive%20handling%3C%2FA%3E%2C%20and%20automatic%20assignment.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20provide%20robust%20workflow%20based%20automation%20capabilities%2C%20automation%20rules%20use%20Logic%20App%20playbooks%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EWatch%20the%20Logic%20Apps%20Sentinel%20playbooks%20Webinar%3A%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20color%3A%20%23063e6c%3B%20outline%3A%200px%3B%22%20href%3D%22https%3A%2F%2Fyoutu.be%2FG6TIzJK8XBA%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_LA_30SEP20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%2C%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhAKStlujGha80s6c%3Fe%3Dn7Zvrw%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3ERead%20about%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Flogic-apps%2Flogic-apps-overview%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ELogic%20Apps%3C%2FA%3E%2C%20which%20is%20the%20core%20technology%20driving%20Azure%20Sentinel%20playbooks.%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fconnectors%2Fazuresentinel%2F%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EThe%20Azure%20Sentinel%20Logic%20App%20connector%3C%2FA%3E%20is%20a%20link%20between%20Logic%20Apps%20and%20Azure%20Sentinel.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EYou%20can%20find%20dozens%20of%20useful%20Playbooks%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Ftree%2Fmaster%2FPlaybooks%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EPlaybooks%20folder%3C%2FA%3E%20on%20the%20Azure%20Sentinel%20GitHub%2C%20or%20read%26nbsp%3B%3CA%20id%3D%22link_10%22%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fplaybooks-amp-watchlists-part-1-inform-the-subscription-owner%2Fba-p%2F1768917%22%20target%3D%22_blank%22%3E%22A%20playbook%20using%20a%20watchlist%20to%20Inform%20a%20subscription%20owner%20about%20an%20alert%3C%2FA%3E%22%20for%20a%20Playbook%20walkthrough.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhile%20Azure%20Sentinel%20is%20a%20cloud-native%20SIEM%2C%20its%20automation%20capabilities%20do%20extend%20to%20on-prem%20environments%2C%20either%20using%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Flogic-apps%2Flogic-apps-gateway-connection%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ELogic%20Apps%20on-prem%20gateway%3C%2FA%3E%20or%20using%20Azure%20Automation%20as%20described%20in%20%22%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fautomatically-disable-on-prem-ad-user-using-a-playbook-triggered%2Fba-p%2F2098272%22%20target%3D%22_self%22%3EAutomatically%20disable%20On-prem%20AD%20User%20using%20a%20Playbook%20triggered%20in%20Azure%3C%2FA%3E%22%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--2100501296%22%20id%3D%22toc-hId--2100501296%22%20id%3D%22toc-hId--2100501296%22%20id%3D%22toc-hId--2100501296%22%20id%3D%22toc-hId--2100501296%22%20id%3D%22toc-hId--2100501296%22%20id%3D%22toc-hId--2100501296%22%20id%3D%22toc-hId--2100501296%22%3EModule%2010%3A%20Workbooks%2C%20reporting%2C%20and%20visualization%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20Watch%20the%20Webinar%3A%20%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%3E%3CA%20title%3D%22YouTube%22%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D7eYNaYSsk1A%26amp%3Blist%3DPLmAptfqzxVEUD7-w180kVApknWHJCXf0j%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20title%3D%22MP4%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmgnW6GuShRIQatg8k%3Fe%3DiPA7hh%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20title%3D%22Deck%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fp%2Fs!AnEPjr8tHcNmgnY-Yb8LQk3h70C0%3Fe%3DAkC4oT%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-516094256%22%20id%3D%22toc-hId-516094256%22%20id%3D%22toc-hId-516094256%22%20id%3D%22toc-hId-516094256%22%20id%3D%22toc-hId-516094256%22%20id%3D%22toc-hId-516094256%22%20id%3D%22toc-hId-516094256%22%20id%3D%22toc-hId-516094256%22%3EWorkbooks%3C%2FH3%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20the%20nerve%20center%20of%20your%20SOC%2C%20you%20need%20Azure%20Sentinel%20to%20visualize%20the%20information%20it%20collects%20and%20produces.%20Use%20workbooks%20to%20visualize%20data%20in%20Azure%20Sentinel.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%3ETo%20learn%20how%20to%20create%20workbooks%2C%20read%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fvisualize%2Fworkbooks-overview%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E%20or%20watch%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FiGiPpD_-10M%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EBilly%20York's%20Workbooks%20training%3C%2FA%3E%20(and%20%3CA%20href%3D%22https%3A%2F%2Fwww.cloudsma.com%2F2019%2F12%2Fazure-advent-calendar-azure-monitor-workbooks%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Eaccompanying%20text%3C%2FA%3E).%20%3C%2FFONT%3E%3C%2FLI%3E%0A%3CLI%3E%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%3EThose%20resources%20are%20not%20Azure%20Sentinel%20specific%2C%20and%20apply%20to%20Azure%20Wrokbooks%20in%20general.%26nbsp%3B%3C%2FFONT%3ETo%20learn%20more%20about%20Workbooks%20in%20Azure%20Sentinel%2C%20watch%20the%20Webinar%3A%26nbsp%3B%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%3E%3CA%20title%3D%22YouTube%22%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D7eYNaYSsk1A%26amp%3Blist%3DPLmAptfqzxVEUD7-w180kVApknWHJCXf0j%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20title%3D%22MP4%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmgnW6GuShRIQatg8k%3Fe%3DiPA7hh%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20title%3D%22Deck%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fp%2Fs!AnEPjr8tHcNmgnY-Yb8LQk3h70C0%3Fe%3DAkC4oT%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%2C%3C%2FFONT%3E%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%3E%26nbsp%3Band%20read%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-monitor-your-data%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E.%3C%2FFONT%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWorkbooks%20can%20be%20interactive%20and%20enable%20much%20more%20than%20just%20charting.%20With%20Workbooks%2C%20you%20can%20create%20apps%20or%20extension%20modules%20for%20Azure%20Sentinel%20to%20complement%20built-in%20functionality.%20We%20also%20use%20workbooks%20to%20extend%20the%20features%20of%20Azure%20Sentinel.%20Few%20examples%20of%20such%20apps%20you%20can%20both%20use%20and%20learn%20from%20are%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EThe%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fannouncing-the-investigation-insights-workbook%2Fba-p%2F1816903%22%20target%3D%22_self%22%3EInvestigation%20Insights%20Workbook%3C%2FA%3E%26nbsp%3Bprovides%20an%20alternative%20approach%20for%20investigating%20incidents.%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fgraph-visualization-of-external-teams-collaborations-in-azure%2Fba-p%2F1356847%22%20target%3D%22_self%22%3EGraph%20Visualization%20of%20External%20Teams%20Collaborations%3C%2FA%3E%20enables%20hunting%20for%20risky%20Teams%20use.%3C%2FLI%3E%0A%3CLI%3EThe%26nbsp%3B%3CU%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fhow-to-use-azure-sentinel-to-follow-a-users-travel-and-map-their%2Fba-p%2F981716%22%20target%3D%22_self%22%3Eusers'%20travel%20map%3C%2FA%3E%3C%2FU%3E%26nbsp%3Bworkbook%26nbsp%3Ballows%20investigating%20geo-location%20alerts.%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EThe%20insecure%20protocols%20workbook%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-insecure-protocols-workbook-implementation-guide%2Fba-p%2F1197564%22%20target%3D%22_blank%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E(Implementation%20Guide%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-insecure-protocols-workbook-reimagined%2Fba-p%2F1558375%22%20target%3D%22_self%22%3Erecent%20enhancements%3C%2FA%3E%3CSTRONG%3E%2C%26nbsp%3B%3C%2FSTRONG%3Eand%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DxzHDWbBX6h8%26amp%3Blist%3DPLmAptfqzxVEWkrUwV-B1Ob3qW-QPW_Ydu%26amp%3Bindex%3D8%26amp%3Bt%3D0s%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Eoverview%20video%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E)%20let%20you%20identify%20the%20use%20of%20insecure%20protocols%20in%20your%20network.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3ELastly%2C%20learn%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fusing-the-sentinel-api-to-view-data-in-a-workbook%2Fba-p%2F1386436%22%20target%3D%22_self%22%3Ehow%20to%20integrate%20information%20from%20any%20source%20using%20API%20calls%20in%20a%20workbook%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EYou%20can%20find%20dozens%20of%20workbooks%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FAzure-Sentinel%2Ftree%2Fmaster%2FWorkbooks%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EWorkbooks%20folder%3C%2FA%3E%20in%20the%20Azure%20Sentinel%20GitHub.%20Some%20of%20those%20are%20available%20in%20the%20Azure%20Sentinel%20workbooks%20gallery%20and%20some%20are%20not.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId--1291360207%22%20id%3D%22toc-hId--1291360207%22%20id%3D%22toc-hId--1291360207%22%20id%3D%22toc-hId--1291360207%22%20id%3D%22toc-hId--1291360207%22%20id%3D%22toc-hId--1291360207%22%20id%3D%22toc-hId--1291360207%22%20id%3D%22toc-hId--1291360207%22%3EReporting%20and%20other%20visualization%20options%3C%2FH3%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWorkbooks%20can%20serve%20for%20reporting.%20For%20more%20advanced%20reporting%20capabilities%20such%20as%20reports%20scheduling%20and%20distribution%20or%20pivot%20tables%2C%20you%20might%20want%20to%20use%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EPower%20BI%2C%20which%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Fpowerbi%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Enatively%20integrates%20with%20Log%20Analytics%20and%20Sentinel%3C%2FA%3E.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EExcel%2C%20which%20can%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Flog-query%2Flog-excel%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Euse%20Log%20Analytics%20and%20Sentinel%20as%20the%20data%20source%3C%2FA%3E%20(and%20see%20a%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DRx7rJhjzTZA%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ea%20video%20on%20how%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E)%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EJupyter%20notebooks%20covered%20later%20in%20the%20hunting%20module%20are%20also%20a%20great%20visualization%20tool.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1067069907%22%20id%3D%22toc-hId-1067069907%22%20id%3D%22toc-hId-1067069907%22%20id%3D%22toc-hId-1067069907%22%20id%3D%22toc-hId-1067069907%22%20id%3D%22toc-hId-1067069907%22%20id%3D%22toc-hId-1067069907%22%20id%3D%22toc-hId-1067069907%22%3EModule%20Y%3A%20Notebooks%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DTgRRJeoyAYw%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Eshort%20introduction%20video%3C%2FA%3E%3CFONT%20size%3D%222%22%3E%20%3CBR%20%2F%3E%3C%2FFONT%3E%3CFONT%20size%3D%224%22%3EGet%20Deeper%3F%20Watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FrewdNeX6H94%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_19JAN2021_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhgtEKc1QwMM83p99%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EJupyter%20notebooks%20are%20fully%20integrated%20with%20Azure%20Sentinel.%20While%20usually%20considered%20an%20important%20tool%20in%20the%20hunter's%20tool%20chest%20and%20discussed%20the%20webinars%20in%20the%20hunting%20section%20below%2C%20their%20value%20is%20much%20broader.%20Notebooks%20can%20serve%20for%20advanced%20visualization%2C%20an%20investigation%20guide%2C%20and%20for%20sophisticated%20automation.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20understand%20them%20better%2C%20watch%20the%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DTgRRJeoyAYw%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EIntroduction%20to%20notebooks%3C%2FA%3E%26nbsp%3Bvideo.%20Get%20started%20using%20the%20Notebooks%20webinar%20(%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FrewdNeX6H94%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_19JAN2021_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhgtEKc1QwMM83p99%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E)%20or%20by%20reading%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fnotebooks%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAn%20important%20part%20of%20the%20integration%20is%20implemented%20by%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fmsticpy-python-defender-tools%2Fba-p%2F648929%22%20target%3D%22_self%22%3EMSTICPY%3C%2FA%3E%2C%20a%20Python%20library%20developed%20by%20our%20research%20team%20for%20use%20with%20Jupyter%20notebooks%20that%20adds%20Azure%20Sentinel%20interfaces%20and%20sophisticated%20security%20capabilities%20to%20your%20notebooks.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--740384556%22%20id%3D%22toc-hId--740384556%22%20id%3D%22toc-hId--740384556%22%20id%3D%22toc-hId--740384556%22%20id%3D%22toc-hId--740384556%22%20id%3D%22toc-hId--740384556%22%20id%3D%22toc-hId--740384556%22%20id%3D%22toc-hId--740384556%22%3EModule%2011%3A%20Use%20cases%20and%20solutions%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20%22Tackling%20Identity%22%20Webinar%3A%20%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Fyoutu.be%2FBcxiY32famg%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EYouTube%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%20style%3D%22background-color%3A%20transparent%3B%22%20data-preserver-spaces%3D%22true%22%3E%2C%26nbsp%3B%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmghxbFa4WcLrfBJwe%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%20style%3D%22background-color%3A%20transparent%3B%22%20data-preserver-spaces%3D%22true%22%3E%2C%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmghskgL3XiweyXwF_%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EUsing%20connectors%2C%20rules%2C%20playbooks%2C%20and%20workbooks%20enables%20you%20to%20implement%20%3CSTRONG%3Euse%20cases%3C%2FSTRONG%3E%3A%20the%20SIEM%20term%20for%20a%20content%20pack%20intended%20to%20detect%20and%20respond%20to%20a%20threat.%20You%20can%20deploy%20Sentinel%20built-in%20use%20cases%20by%20activating%20the%20suggested%20rules%20when%20connecting%20each%20Connector.%26nbsp%3BA%20%3CSTRONG%3Esolution%3C%2FSTRONG%3E%20is%20a%20group%20of%20use%20cases%20addressing%20a%20specific%20threat%20domain.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CSTRONG%3EThe%20Webinar%20%22Tackling%20Identity%22%20%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2Fyoutu.be%2FBcxiY32famg%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3E(YouTube%3C%2FA%3E%3CSPAN%20style%3D%22background-color%3A%20transparent%3B%22%20data-preserver-spaces%3D%22true%22%3E%2C%26nbsp%3B%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmghxbFa4WcLrfBJwe%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%20style%3D%22background-color%3A%20transparent%3B%22%20data-preserver-spaces%3D%22true%22%3E%2C%26nbsp%3B%3C%2FSPAN%3E%3CA%20class%3D%22_e75a791d-denali-editor-page-rtfLink%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmghskgL3XiweyXwF_%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPresentation%3C%2FA%3E)%3C%2FSTRONG%3E%20explains%20what%20a%20use%20case%20is%2C%20how%20to%20approach%20its%20design%2C%20and%20presents%20several%20use%20cases%20that%20collectively%20address%20identity%20threats.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EAnother%20very%20relevant%20solution%20area%20is%20%3CSTRONG%3Eprotecting%20remote%20work%3C%2FSTRONG%3E.%20Watch%20our%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D09JfbjQdzpg%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Eignite%20session%20on%20protection%20remote%20work%3C%2FA%3E%2C%20and%20read%20more%20on%20the%20specific%20use%20cases%3A%3C%2FSPAN%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fprotecting-your-teams-with-azure-sentinel%2Fba-p%2F1265761%22%20target%3D%22_self%22%3EMicrosoft%20Teams%20hunting%20use%20cases%3C%2FA%3E%26nbsp%3Band%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fgraph-visualization-of-external-teams-collaborations-in-azure%2Fba-p%2F1356847%22%20target%3D%22_self%22%3EGraph%20Visualization%20of%20External%20Microsoft%20Teams%20Collaborations%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fmonitoring-zoom-with-azure-sentinel%2Fba-p%2F1341516%22%20target%3D%22_self%22%3EMonitoring%20Zoom%20with%20Azure%20Sentinel%3C%2FA%3E%3A%20custom%20connectors%2C%20analytic%20rules%2C%20and%20hunting%20queries.%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fmonitoring-windows-virtual-desktop-environments-fall-2019%2Fba-p%2F1356632%22%20target%3D%22_self%22%3EMonitoring%20Windows%20Virtual%20Desktop%20with%20Azure%20Sentinel%3C%2FA%3E%3A%20use%20Windows%20Security%20Events%2C%20Azure%20AD%20Sign-in%20logs%2C%20Microsoft%20365%20defender%20for%20endpoints%2C%20and%20WVD%20diagnostics%20logs%20to%20detect%20and%20hunt%20for%20WVD%20threats.%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsecure-working-from-home-deep-insights-at-enrolled-mem-assets%2Fba-p%2F1424255%22%20target%3D%22_self%22%3EMonitor%20Microsoft%20endpoint%20Manager%20%2F%20Intune%3C%2FA%3E%3C%2FSPAN%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%2C%20using%20queries%20and%20workbooks.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3EAnd%20lastly%2C%20focusing%20on%20recent%20attacks%2C%20learn%20how%20to%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fmonitoring-the-software-supply-chain-with-azure-sentinel%2Fba-p%2F2176463%22%20target%3D%22_self%22%3Emonitor%20the%20software%20supply%20chain%20with%20Azure%20Sentinel%3C%2FA%3E.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20data-preserver-spaces%3D%22true%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1747128277%22%20id%3D%22toc-hId-1747128277%22%20id%3D%22toc-hId-1747128277%22%20id%3D%22toc-hId-1747128277%22%20id%3D%22toc-hId-1747128277%22%20id%3D%22toc-hId-1747128277%22%20id%3D%22toc-hId-1747128277%22%20id%3D%22toc-hId-1747128277%22%3E%3CFONT%20size%3D%226%22%20color%3D%22%230000FF%22%3EPart%204%3A%20Operating%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--60326186%22%20id%3D%22toc-hId--60326186%22%20id%3D%22toc-hId--60326186%22%20id%3D%22toc-hId--60326186%22%20id%3D%22toc-hId--60326186%22%20id%3D%22toc-hId--60326186%22%20id%3D%22toc-hId--60326186%22%20id%3D%22toc-hId--60326186%22%3EModule%2012%3A%20Handling%20incidents%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20%22day%20in%20a%20life%22%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FHloK6Ay4h1M%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmghEg_9Z2NjQ_DDpo%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs%2521AnEPjr8tHcNmghALzkfTkg-dTmfH%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAfter%20building%20your%20SOC%2C%20you%20need%20to%20start%20using%20it.%20The%20%22day%20in%20a%20SOC%20analyst%20life%22%20webinar%20(%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FHloK6Ay4h1M%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs%2521AnEPjr8tHcNmghEg_9Z2NjQ_DDpo%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%3CSPAN%20style%3D%22background-color%3A%20transparent%3B%22%3E%2C%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs%2521AnEPjr8tHcNmghALzkfTkg-dTmfH%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPresentation%3C%2FA%3E)%20walks%20you%20through%20using%20Azure%20Sentinel%20in%20the%20SOC%20to%20triage%2C%20investigate%20and%20respond%20to%20incidents.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20might%20also%20want%20to%20read%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Ftutorial-investigate-cases%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Edocumentation%20article%20on%20incident%20investigation%3C%2FA%3E.%20As%20part%20of%20the%20investigation%2C%20you%20will%20also%20use%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fidentify-threats-with-entity-behavior-analytics%23entity-pages%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Eentity%20pages%3C%2FA%3E%20to%20get%20more%20information%20about%20entities%20related%20to%20your%20incident%20or%20identified%20as%20part%20of%20your%20investigation.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIncident%20investigation%20in%20Azure%20Sentinel%20extends%20beyond%20the%20core%20incident%20investigation%20functionality.%20We%20can%20build%20additional%20investigation%20tools%20using%20Workbooks%20and%20Notebooks%20(the%20latter%20are%20discussed%20later%2C%20under%20hunting).%20You%20can%20also%20build%20additional%20investigation%20tools%20or%20modify%20ours%20to%20your%20specific%20needs.%20Examples%20include%3A%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EThe%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fannouncing-the-investigation-insights-workbook%2Fba-p%2F1816903%22%20target%3D%22_self%22%3EInvestigation%20Insights%20Workbook%3C%2FA%3E%26nbsp%3Bprovides%20an%20alternative%20approach%20for%20investigating%20incidents.%3C%2FLI%3E%0A%3CLI%3ENotebooks%20enhance%20the%20investigation%20experience.%20Read%20'%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fwhy-use-jupyter-for-security-investigations%2Fba-p%2F475729%22%20target%3D%22_blank%22%3EWhy%20Use%20Jupyter%20for%20Security%20Investigations%3F%3C%2FA%3E%22%20and%20learn%20how%20to%20investigate%20with%20Azure%20Sentinel%20%26amp%3B%20Jupyter%20Notebooks%3A%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsecurity-investigation-with-azure-sentinel-and-jupyter-notebooks%2Fba-p%2F432921%22%20target%3D%22_blank%22%3Epart%201%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsecurity-investigation-with-azure-sentinel-and-jupyter-notebooks%2Fba-p%2F483466%22%20target%3D%22_blank%22%3Epart%202%3C%2FA%3E%2C%20and%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsecurity-investigation-with-azure-sentinel-and-jupyter-notebooks%2Fba-p%2F561413%22%20target%3D%22_blank%22%3Epart%203%3C%2FA%3E.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--1169618708%22%20id%3D%22toc-hId--1169618708%22%20id%3D%22toc-hId--1169618708%22%20id%3D%22toc-hId--1169618708%22%20id%3D%22toc-hId--1169618708%22%20id%3D%22toc-hId--1169618708%22%20id%3D%22toc-hId--1169618708%22%20id%3D%22toc-hId--1169618708%22%3EModule%2013%3A%20Hunting%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F6ueR09PLoLU%3Ft%3D1451%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_T_H_12AUG20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmg1WdPYaITzG7W1Sp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3CBR%20%2F%3E%3CFONT%20size%3D%222%22%3E(Note%20that%20the%20Webinar%20starts%20with%20an%20update%20on%20new%20features%2C%20to%20learn%20about%20hunting%2C%20start%20at%20slide%2012.%20The%20Youtube%20link%20is%20already%20set%20to%20start%20there)%3C%2FFONT%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhile%20most%20of%20the%20discussion%20so%20far%20focused%20on%20detection%20and%20incident%20management%2C%20hunting%20is%20another%20important%20use%20case%20for%20Azure%20Sentinel.%20Hunting%20is%20a%20proactive%20search%20for%20threats%20rather%20than%20a%20reactive%20response%20to%20alerts.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20understand%20more%20about%20what%20hunting%20is%20and%20how%20Azure%20Sentinel%20supports%20it%2C%26nbsp%3B%3CSTRONG%3EWatch%20the%20hunting%20intro%20Webinar%20(%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2F6ueR09PLoLU%3Ft%3D1451%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_T_H_12AUG20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmg1WdPYaITzG7W1Sp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck)%3C%2FA%3E%3C%2FSTRONG%3E.%26nbsp%3BNote%20that%20the%20Webinar%20starts%20with%20an%20update%20on%20new%20features.%20To%20learn%20about%20hunting%2C%20start%20at%20slide%2012.%20The%20Youtube%20link%20is%20already%20set%20to%20start%20there.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhile%20the%20intro%20webinar%20focuses%20on%20tools%2C%20hunting%20is%20all%20about%20security.%20Our%20%3CSTRONG%3Esecurity%20research%20team%20webinar%20on%20hunting%20(%3C%2FSTRONG%3E%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%20style%3D%22background-color%3A%20%23ffffff%3B%20outline%3A%200px%3B%22%3E%3CSTRONG%3E%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20outline%3A%200px%3B%22%20title%3D%22MP4%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmghQwthryNWI5Yfuh%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FBTEV_b6-vtg%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20title%3D%22Deck%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmghNdbqppq1myNzG_%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EPresentation%3C%2FA%3E)%3C%2FSTRONG%3E%26nbsp%3B%3C%2FFONT%3Efocuses%20on%20how%20to%20actually%20hunt.%20The%20follow-up%20%3CSTRONG%3EAWS%26nbsp%3B%3C%2FSTRONG%3E%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%20style%3D%22background-color%3A%20%23ffffff%3B%20outline%3A%200px%3B%22%3E%3CSPAN%3E%3CSTRONG%3EThreat%20Hunting%20using%20Sentinel%20Webinar%20(%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmglA7u6-1zE5isojJ%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FbSH-JOKl2Kk%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgk4O1CkCI9sLtRYi%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E)%3C%2FSTRONG%3E%20really%20drives%20the%20point%20by%20showing%20an%20end-to-end%20hunting%20scenario%20on%20a%20high-value%20target%20environment.%20Lastly%2C%20you%20can%20learn%20how%20to%20do%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsolarwinds-post-compromise-hunting-with-azure-sentinel%2Fba-p%2F1995095%22%20target%3D%22_self%22%3ESolarWinds%20Post-Compromise%20Hunting%20with%20Azure%20Sentinel%3C%2FA%3E%3C%2FSPAN%3E%3C%2FFONT%3E%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%20style%3D%22background-color%3A%20%23ffffff%3B%20outline%3A%200px%3B%22%3E%3CSPAN%3E%26nbsp%3Band%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fweb-shell-threat-hunting-with-azure-sentinel%2Fba-p%2F2234968%22%20target%3D%22_self%22%3EWebShell%20hunting%3C%2FA%3E%20motivated%20by%20the%20latest%26nbsp%3Brecent%20vulnerabilities%20in%26nbsp%3Bon-premises%26nbsp%3BMicrosoft%20Exchange%26nbsp%3Bservers.%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1317894125%22%20id%3D%22toc-hId-1317894125%22%20id%3D%22toc-hId-1317894125%22%20id%3D%22toc-hId-1317894125%22%20id%3D%22toc-hId-1317894125%22%20id%3D%22toc-hId-1317894125%22%20id%3D%22toc-hId-1317894125%22%20id%3D%22toc-hId-1317894125%22%3EModule%2014%3A%20User%20and%20Entity%20Behavior%20Analytics%20(UEBA)%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20Webinar%3A%20%3C%2FSTRONG%3E%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_UEBA_29SEP20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FixBotw9Qidg%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhAM189I9gDuyoH7_%3Fe%3DDQ2Ocy%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck%3C%2FA%3E%3C%2FSTRONG%3E%3CSTRONG%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Sentinel%20newly%20introduced%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fidentify-threats-with-entity-behavior-analytics%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EUser%20and%20Entity%20Behavior%20Analytics%20(UEBA)%20module%3C%2FA%3E%26nbsp%3Benables%20you%20to%26nbsp%3Bidentify%20and%20investigate%20threats%20inside%20your%20organization%20and%20their%20potential%20impact%20-%20whether%20a%20compromised%20entity%20or%20a%20malicious%20insider.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ELearn%20more%20about%20UEBA%20in%20the%20UEBA%20Webinar%20(%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20color%3A%20%23063e6c%3B%20outline%3A%200px%3B%20text-align%3A%20center%3B%22%20href%3D%22https%3A%2F%2Faka.ms%2FAzS_UEBA_29SEP20_MP4%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20color%3A%20%23063e6c%3B%20outline%3A%200px%3B%20text-align%3A%20center%3B%22%20href%3D%22https%3A%2F%2Fyoutu.be%2FixBotw9Qidg%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%20color%3A%20%23063e6c%3B%20outline%3A%200px%3B%20text-align%3A%20center%3B%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhAM189I9gDuyoH7_%3Fe%3DDQ2Ocy%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EDeck)%3C%2FA%3E%26nbsp%3Band%20read%20about%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fguided-ueba-investigation-scenarios-to-empower-your-soc%2Fba-p%2F1857100%22%20target%3D%22_self%22%3Eusing%20UEBA%20for%20investigations%3C%2FA%3E%20in%20your%20SOC.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--489560338%22%20id%3D%22toc-hId--489560338%22%20id%3D%22toc-hId--489560338%22%20id%3D%22toc-hId--489560338%22%20id%3D%22toc-hId--489560338%22%20id%3D%22toc-hId--489560338%22%20id%3D%22toc-hId--489560338%22%20id%3D%22toc-hId--489560338%22%3EModule%2015%3A%20Monitoring%20Azure%20Sentinel's%20health%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20videos%20on%20monitoring%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DT6Vyo7gZYds%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Econnector%3C%2FA%3E%3CBR%20%2F%3E%2C%20%3C%2FSTRONG%3E%3CSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DjRucUysVpxI%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Esecurity%20operations%3C%2FA%3E%20health%20or%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FDmDU9QP_JlI%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Eworkspace%20audit%3C%2FA%3E.%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPart%20of%20operating%20a%20SIEM%20is%20making%20sure%20it%20works%20smoothly%20and%20an%20evolving%20area%20in%20Azure%20Sentinel.%20Use%20the%20following%20to%20monitor%20Azure%20Sentinel's%20health%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EMeasure%20the%20efficiency%20of%20your%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fmanage-soc-with-incident-metrics%23security-operations-efficiency-workbook%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ESecurity%20operations%3C%2FA%3E%26nbsp%3B(%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DjRucUysVpxI%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Evideo%3C%2FA%3E)%3C%2FLI%3E%0A%3CLI%3EMonitor%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fmonitor-data-connector-health%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EData%20connectors%20health%3C%2FA%3E%26nbsp%3B(%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DT6Vyo7gZYds%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Evideo%3C%2FA%3E)%20and%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fdata-connector-health-push-notification-alerts%2Fba-p%2F1996442%22%20target%3D%22_self%22%3Eget%20notifications%20on%20anomalies%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3EMonitor%20agents%20using%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Finsights%2Fsolution-agenthealth%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Eagents'%20health%20solution%3C%2FA%3E%26nbsp%3B(Windows%20only)%20and%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Finsights%2Fsolution-agenthealth%23azure-monitor-log-records%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EHeartbeat%20table%3C%2FA%3E%26nbsp%3B(Linux%20and%20Windows)%3C%2FLI%3E%0A%3CLI%3EMonitor%20your%20Log%20Analytics%20workspace%3A%20%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FDmDU9QP_JlI%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FAzSentinel_21JAN2021_MP4%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EMP4%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmhhoL2vqOkbtX4ye_%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%2C%20including%20query%20execution%20and%20ingest%20health%3C%2FLI%3E%0A%3CLI%3ECost%20management%20is%20also%20an%20important%20operational%20procedure%20in%20the%20SOC.%20Use%20the%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fingestion-cost-alert-playbook%2Fba-p%2F2006003%22%20target%3D%22_self%22%3EIngestion%20Cost%20Alert%20Playbook%3C%2FA%3E%26nbsp%3Bto%20ensure%20you%20are%20aware%20in%20time%20of%20any%20cost%20increase.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1997952495%22%20id%3D%22toc-hId-1997952495%22%20id%3D%22toc-hId-1997952495%22%20id%3D%22toc-hId-1997952495%22%20id%3D%22toc-hId-1997952495%22%20id%3D%22toc-hId-1997952495%22%20id%3D%22toc-hId-1997952495%22%20id%3D%22toc-hId-1997952495%22%3E%3CFONT%20size%3D%226%22%20color%3D%22%230000FF%22%3EPart%205%3A%20Advanced%20Topics%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-190498032%22%20id%3D%22toc-hId-190498032%22%20id%3D%22toc-hId-190498032%22%20id%3D%22toc-hId-190498032%22%20id%3D%22toc-hId-190498032%22%20id%3D%22toc-hId-190498032%22%20id%3D%22toc-hId-190498032%22%20id%3D%22toc-hId-190498032%22%3EModule%2016%3A%20Extending%20and%20Integrating%20using%26nbsp%3BAzure%20Sentinel%20APIs%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DgQDBkc-K-Y4%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Evideo%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3CFONT%20size%3D%222%22%3E%3CEM%3E%3CSTRONG%3E%20(5%20minutes)%3CBR%20%2F%3E%3CFONT%20size%3D%224%22%3EGet%20deeper%3F%20Watch%20the%20Webinar%3A%20%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmgjMmZquqAHtclQ5m%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FCu4dc88GH1k%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgjRd01jxCSmbydt0%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E%3C%2FFONT%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20a%20cloud-native%20SIEM%2C%20Azure%20Sentinel%20is%20an%20API%20first%20system.%20Every%20feature%20can%20be%20configured%20and%20used%20through%20an%20API%2C%20enabling%20easy%20integration%20with%20other%20systems%20and%20extending%20Sentinel%20with%20your%20own%20code.%20If%20API%20sounds%20intimidating%20to%20you%2C%20don't%20worry%3B%20whatever%20is%20available%20using%20the%20API%20is%20also%20available%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fnew-year-new-official-azure-sentinel-powershell-module%2Fba-p%2F2025041%22%20target%3D%22_self%22%3Eusing%20PowerShell%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20learn%20more%20about%20Azure%20Sentinel%20APIs%2C%20watch%20the%26nbsp%3Bshort%20introductory%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DgQDBkc-K-Y4%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Evideo%3C%2FA%3E%26nbsp%3Band%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-api-101%2Fba-p%2F1438928%22%20target%3D%22_self%22%3Eblog%20post%3C%2FA%3E.%20To%20get%20the%20details%2C%20watch%20the%20deep%20dive%20Webinar%20(%3CFONT%20face%3D%22%26quot%3BSegoeUI%26quot%3B%2C%26quot%3BLato%26quot%3B%2C%26quot%3BHelvetica%20Neue%26quot%3B%2CHelvetica%2CArial%2Csans-serif%22%3E%3CA%20href%3D%22https%3A%2F%2F1drv.ms%2Fv%2Fs!AnEPjr8tHcNmgjMmZquqAHtclQ5m%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMP4%3C%2FA%3E%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FCu4dc88GH1k%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EYouTube%3C%2FA%3E%3C%2FFONT%3E%2C%26nbsp%3B%3CA%20style%3D%22background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2F1drv.ms%2Fb%2Fs!AnEPjr8tHcNmgjRd01jxCSmbydt0%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EPresentation%3C%2FA%3E)%20and%20read%20the%20blog%20post%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fextending-azure-sentinel-apis-integration-and-management%2Fba-p%2F1116885%22%20target%3D%22_blank%22%3EExtending%20Azure%20Sentinel%3A%20APIs%2C%20Integration%2C%20and%20management%20automation%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--1616956431%22%20id%3D%22toc-hId--1616956431%22%20id%3D%22toc-hId--1616956431%22%20id%3D%22toc-hId--1616956431%22%20id%3D%22toc-hId--1616956431%22%20id%3D%22toc-hId--1616956431%22%20id%3D%22toc-hId--1616956431%22%20id%3D%22toc-hId--1616956431%22%3EModule%2017%3A%20Bring%20your%20own%20ML%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3E%3CFONT%20size%3D%224%22%3E%3CEM%3E%3CSTRONG%3EShort%20on%20time%3F%20watch%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DQDIuvZbmUmc%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Evideo%3C%2FA%3E%3C%2FSTRONG%3E%3CSTRONG%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FEM%3E%3C%2FFONT%3E%3C%2FPRE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAzure%20Sentinel%20provides%20a%20great%20platform%20for%20implementing%20your%20own%20Machine%20Learning%20algorithms.%20We%20call%20it%20Bring%20Your%20Own%20ML%20or%20BYOML%20for%20short.%20Obviously%2C%20this%20is%20intended%20for%20advanced%20users.%20If%20you%20are%20looking%20for%20built-in%20behavioral%20analytics%2C%20use%20our%20ML%20Analytic%20rules%2C%20UEBA%20module%2C%20or%20write%20your%20own%20behavioral%20analytics%20KQL%20based%20analytics%20rules.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20start%20with%20bringing%20your%20own%20ML%20to%20Azure%20Sentinel%2C%20watch%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DQDIuvZbmUmc%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Evideo%3C%2FA%3E%2C%20and%20read%20the%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fbuild-your-own-machine-learning-detections-in-the-ai-immersed%2Fba-p%2F1750920%22%20target%3D%22_self%22%3Eblog%20post%3C%2FA%3E.%20You%20might%20also%20want%20to%20refer%20to%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fbring-your-own-ml%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EBYOML%20documentation%3C%2FA%3E.%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fbring-your-own-ml%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsentinel%2Fbring-your-own-ml%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DQDIuvZbmUmc%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EAzure%20Sentinel%20Build-Your-Own%20ML%20Model%3C%2FA%3E%20video%3C%2FLI%3E%0A%3C%2FUL%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1246310%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20asked%20for%20it%2C%20and%20we%20deliver.%20Virtually%20to%20fit%20the%20era.%20Get%20deep%20into%20Azure%20Sentinel%20using%20the%20Level%20400%20learning%20program%20in%20this%20post.%20Now%20updated%20for%202021.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2335910%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2335910%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B-%20I%20have%20the%20same%20question%20as%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1036709%22%20target%3D%22_blank%22%3E%40FrancoisV500%3C%2FA%3E%26nbsp%3B-%20How%20much%20time%20should%20we%20plan%20for%20going%20through%20this%20training%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2379193%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2379193%22%20slang%3D%22en-US%22%3E%3CP%3EWhy%20are%20notebooks%20in%20Module%20%22Y%22%2C%20instead%20of%20a%20numbered%20module%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2419928%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2419928%22%20slang%3D%22en-US%22%3E%3CP%3EHow%20can%20i%20get%20completion%20certificate%3F%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2441383%22%20slang%3D%22en-US%22%3ERe%3A%20Become%20an%20Azure%20Sentinel%20Ninja%3A%20The%20complete%20level%20400%20training%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2441383%22%20slang%3D%22en-US%22%3E%3CP%3EGood%20night%20people.%3C%2FP%3E%3CP%3EIs%20there%20a%20%22certificate%22%20or%20something%20like%20that%20to%20show%20that%20I've%20finished%20the%20content%3F%3CBR%20%2F%3EI%20saw%20that%20Ninja%20Casb%20gives%20a%20certificate.%3CBR%20%2F%3ESomething%20like%20that%20would%20be%20nice.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Oct 18 2021 08:02 PM
Updated by: