Microsoft Sentinel course with hands on sims for beginners

所在平台: Udemy

课程主页: https://www.udemy.com/course/microsoft-sentinel-course-with-hands-on-sims/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**Microsoft Sentinel 入门与实操课程总结** 本课程专为初学者设计,旨在帮助学员掌握 Microsoft Sentinel 的核心概念和实操技能。课程提供由经验丰富的讲师(拥有20多年教学经验,且是微软认证讲师)讲解的生动易懂的授课内容,并结合无代码实操模拟,即使是零基础学员也能轻松上手。 **课程核心内容包括:** * **Microsoft 环境基础:** 介绍 Active Directory 域、RAS、DMZ、虚拟化以及 Microsoft 云服务(包括 Azure AD 重命名为 Entra ID)的基础知识。 * **Microsoft Sentinel 工作区:** 涵盖工作区的创建、配置、角色管理、日志类型、数据保留与存储,以及数据连接器和数据引入的设置。 * **数据连接与日志收集:** 深入讲解数据源识别、设置连接器以引入数据(包括 M365 Defender、Defender for Cloud、CEF/Syslog、Windows 安全事件日志)以及威胁情报连接器的管理。 * **分析规则与威胁检测:** 学习各种分析规则的应用,包括 Fusion 规则、安全分析规则、计划查询规则(自定义)、近实时 (NRT) 规则和内容中心规则。 * **Watchlists 和威胁指标:** 了解 Watchlists 和威胁指标在 Sentinel 中的作用。 * **分类、标准化与 SOAR:** 学习如何使用实体进行数据分类与分析,以及 ASIM 查询和 ASIM 解析器管理。 * **自动化与响应:** 掌握自动化规则和 Playbook 的使用,包括通过分析规则触发自动化,以及通过 Playbook 响应告警和事件。 * **告警与事件处理:** 讲解告警和事件的生成、分类、分级(triaging)以及调查和响应流程,并支持多工作区事件调查。 * **工作簿(Workbooks)与可视化:** 学习工作簿模板的自定义和管理,以及实现自定义工作簿和高级可视化。 * **威胁狩猎与实体行为分析:** 探索 MITRE ATT&CK 攻击向量,使用内容库的狩猎查询,自定义狩猎查询,并利用书签进行数据调查。此外,还学习使用 Livestream 监控狩猎查询,检索归档日志数据,以及管理搜索作业。 * **实体行为分析(EBA):** 重点介绍 EBA 的设置、实体页面调查以及异常检测分析规则。 * **实操演练与后续:** 课程包含大量动手实践环节,并指导学员如何清理实验室环境、获取 Udemy 证书以及后续的学习路径。 本课程通过碎片化的知识点讲解和大量的实操练习,旨在为初学者建立坚实的 Microsoft Sentinel 基础,使其能够有效地进行威胁检测、事件响应和安全分析。

课程评论(0条)

课程详情

We really hope you'll agree, this training is way more than the average course on Udemy! Have access to the following:Training from an instructor of over 20 years who has trained thousands of people and also a Microsoft Certified TrainerLecture that explains the concepts in an easy to learn method for someone that is just starting out with this materialInstructor led hands on and simulations to practice that can be followed even if you have little to no experienceTOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:IntroductionWelcome to the courseUnderstanding the Microsoft EnvironmentFoundations of Active Directory DomainsFoundations of RAS, DMZ, and VirtualizationFoundations of the Microsoft Cloud ServicesDONT SKIP: The first thing to know about Microsoft cloud servicesDONT SKIP: Azure AD is now renamed to Entra IDQuestions for John ChristopherPerforming hands on activitiesDONT SKIP: Using Assignments in the courseCreating a free Microsoft 365 AccountGetting your free Azure creditUnderstanding and setting up a Microsoft Sentinel WorkspaceOverview of Microsoft SentinelConfiguring a Microsoft Sentinel workspaceManaging roles regarding SentinelManaging log types, log retention, and data storage in SentinelWorking with data connectors and ingestion in Microsoft SentinelMicrosoft Sentinel data source identificationSetting up connectors for ingesting data into Microsoft SentinelConnecting Sentinel with Microsoft 365 Defender and Defender for CloudCommon Event Format (CEF) and Syslog event collectionsWindows Security Event Collection setup in Microsoft SentinelManaging threat intelligence connectors in Microsoft SentinelWorking with custom log tablesUsing analytics rules in Microsoft SentinelUnderstanding analytics rules in Microsoft SentinelFusion rule configurationSecurity analytics rulesWorking with scheduled query rules in Microsoft SentinelCustom scheduled query rulesWorking with near-real-time (NRT) analytics rulesContent hub analytics rulesWatchlists in Microsoft SentinelThreat indicators in Microsoft SentinelClassification, normalization & security orchestration automated response (SOAR)Working with using entities for classifying and analyzing dataAdvanced Security Information Model(ASIM) queries with Microsoft SentinelASIM parser managementUsing automation rulesUsing playbooks in Microsoft SentinelAutomation rule triggering using analytic rulesAlert and incident playbook triggeringDealing with Incidents and Workbooks for analyzes and interpretation of dataIncident generation in Microsoft SentinelUnderstanding the concepts of triaging incidents in SentinelMicrosoft Sentinel incident investigationHow to respond to Microsoft Sentinel incidentsMulti-workspace incident investigationWorkbook template customization and managementImplementing custom workbooks in Microsoft SentinelWorking with advanced visualizationsThreat hunting and entity behavior analytics in Microsoft SentinelMITRE ATT & CK attack vectors in Microsoft SentinelUsing hunting queries from the content galleryHunting query customizationData investigations with hunting bookmarksUsing Livestream to monitor hunting queriesHow archived log data can be retrieved in Microsoft SentinelSearch job management in Microsoft SentinelEntity Behavior Analytics settingsEntity page investigation of threatsAnomaly detection analytics rules in Microsoft SentinelConclusionCleaning up your lab environmentGetting a Udemy certificateBONUS Where do I go from here?

课程标签

0人关注该课程

主题相关的课程