|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/microsoft-sentinel-expert-course-overview-interactive-new/
课程评论:没有评论
**课程名称:Microsoft Sentinel 完全专家忍者课程 (SC-200)** **课程概述:** 本课程旨在帮助学员成为 Microsoft Sentinel 专家,掌握下一代安全运营中心 (SOC) 的核心技能。学员将学习如何利用 Microsoft Sentinel 这一强大的云原生安全信息和事件管理 (SIEM) 及安全编排、自动化和响应 (SOAR) 解决方案,全面提升组织的安全防护能力。 **核心学习内容:** * **数据收集与集成:** 学会跨越所有用户、设备、应用程序和基础设施,在云端(包括本地和多云环境)大规模收集数据。 * **威胁检测:** 利用 Microsoft 强大的分析能力和业界领先的威胁情报,检测前所未见的威胁,并最大限度地减少误报。 * **威胁调查与搜寻:** 运用人工智能进行威胁调查,并利用 Microsoft 在网络安全领域多年的经验,在大规模范围内搜寻可疑活动。 * **事件响应:** 通过内置的自动化和编排功能,快速响应安全事件,自动化常见任务。 * **SISEM + SOAR 概念:** 理解 SIEM 和 SOAR 的基本原理及其在现代安全运营中的作用。 * **Microsoft Sentinel 部署与架构:** 掌握 Microsoft Sentinel 的部署方法、设计原则和整体架构。 * **威胁情报应用:** 学习如何利用威胁情报来增强检测和响应能力。 * **仪表板与报告:** 学习如何使用工作簿 (workbooks) 创建交互式报告,以可视化安全状态。 * **关联与自动化:** 通过分析规则将告警关联成事件,并利用 Playbooks 自动化常见任务,实现与 Azure 服务及现有工具的集成,简化安全编排。 * **深度调查:** 利用 Microsoft Sentinel 的深度调查工具,理解安全威胁的范围,找出根本原因,并通过交互式图谱深入分析实体间的关联。 **课程价值:** Microsoft Sentinel 是一款集成的解决方案,提供跨企业范围的智能安全分析和威胁情报,实现攻击检测、威胁可见性、主动搜寻和威胁响应。本课程将使学员能够 365 天 24/7 全天候监控组织的整个 IT 基础设施,实时检测和高效解决任何安全威胁,并通过及时的威胁分析持续改进组织的安全态势。
Microsoft Sentinel & The Next Gen-SOCLearn Microsoft Sentinel Today! Create interactive reports by using workbooksCollect data at cloud scale across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds.Detect previously undetected threats, and minimize false positives using Microsoft's analytics and unparalleled threat intelligence.Investigate threats with artificial intelligence, and hunt for suspicious activities at scale, tapping into years of cyber security work at Microsoft.Respond to incidents rapidly with built-in orchestration and automation of common tasks.Microsoft Sentinel monitors an organization's entire IT infrastructure, 365 days 24/7, to detect any threat or alert in real time and solve them as quickly and effectively as possible and timely analysis of threats to find ways to improve the organization's security posture. Learn What Is a SIEM + SOARLearn How To Deploy Microsoft SentinelLearn Microsoft Sentinel Design & ArchitectureLearn About Threat IntelligenceHuntingMicrosoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise. With Microsoft Sentinel, you get a single solution for attack detection, threat visibility, proactive hunting, and threat response.Deliver intelligent security analytics and threat intelligence across the enterprise. With Microsoft Sentinel, you get a single solution for attack detection, threat visibility, proactive hunting, and threat response.Correlate alerts into incidents by using analytics rulesAutomate and orchestrate common tasks by using playbooksAutomate your common tasks and simplify security orchestration with playbooks that integrate with Azure services and your existing tools.Investigate the scope and root cause of security threatsMicrosoft Sentinel deep investigation tools help you to understand the scope and find the root cause of a potential security threat. You can choose an entity on the interactive graph to ask interesting questions for a specific entity, and drill down into that entity and its connections to get to the root cause of the threat.