…
|
||
---|---|---|
.. | ||
Artifacts | ||
Images | ||
Modules | ||
README.md |
README.md
Welcome to Azure Sentinel Training Lab
Introduction
These labs help you get ramped up with Azure Sentinel and provide hands-on practical experience for product features, capabilities, and scenarios.
The lab deploys an Azure Sentinel workspace and ingests pre-recorded data to simulate scenarios that showcase various Azure Sentinel features. You should expect very little or no cost at all due to the size of the data (~10 MBs) and the fact that Azure Sentinel offers a 30-day free trial.
Prerequisites
To deploy Azure Sentinel Trainig Lab, you must have a Microsoft Azure subscription. If you do not have an existing Azure subscription, you can sign up for a free trial here.
Last release notes
- Version 0.2 - Azure Sentinel Training Lab Beta
Getting started
Below you can see all the modules that are part of this lab. Although in general they can be completed in any order, you must start with Module 1 as this deploys the lab environment itself.
Modules
Module 1 – Setting up the environment
- Enable Azure Activity data connector
- Enable Azure Defender data connector
- Enable Threat Intelligence TAXII data connector
- Analytics Rules overview
- Enable Microsoft incident creation rule
- Review Fusion Rule (Advanced Multistage Attack Detection)
- Create custom analytics rule
- Review resulting security incident
Module 4 – Incident Management
- Review Azure Sentinel incident tools and capabilities
- Handling Incident "Sign-ins from IPs that attempt sign-ins to disabled accounts"