This overview is based on the Blog post “Become an Azure Sentinel Ninja: The Complete Level 400 Training created by Ofer Shezaf

As not everyone has the same maturity level when starting their Azure Sentinel Learning Path, I created, with the help of Javier Soriano, a 3 level (Beginner/Advanced/Expert) approach to get to the level you want, often related to your role in the organisation.

Table of contents

Beginner (BDM, presales roles)

  • The Basics

  • Technical overview

  • Azure Sentinel role

Advanced (Security Analyst)

  • Technical overview

  • Cloud architecture and multi-workspace/tenant support

  • Handling incidents

  • Hunting

Expert (SOC engineer)

  • Technical overview

  • Cloud architecture and multi-workspace/tenant support

  • KQL

  • Write rules

  • Creating playbooks

  • Developing workbooks

  • Hunting

Advanced Topics

  • Automating and integrating

  • Deploying and Managing Azure Sentinel as Code

  • Roadmap - since it requires an NDA, contact your Microsoft contact for details.

  • Where to go next?

  • Extra Resources

———————

Beginner (BDM, presales roles)

The Basics

BackToTop

Technical overview (Level 200)

If you want to get an initial overview of Azure Sentinel’s technical capabilities

Learn more

You can read more about the features described in the Webinar here:

BackToTop

Azure Sentinel role (Level 200)

What is the typical use case for Azure Sentinel? What are customers finding in it, and also, how is it priced? All in this presentation

Learn more :

———————

BackToTop

Advanced (Security Analyst)

Technical overview (Level 200)

If you want to get an initial overview of Azure Sentinel’s technical capabilities

Learn more

You can read more about the features described in the Webinar here:

BackToTop

Cloud architecture and multi-workspace/tenant support

An Azure Sentinel instance is called a workspace. Multiple workspaces are often necessary and can act together as a single Azure Sentinel system. The first half of the Webinar above discusses Azure Sentinel’s workspace architecture.

Learn more

BackToTop

Handling incidents

After building your SOC, you need to start using it. Watch the day in a SOC analyst life to learn how to use Azure Sentinel in the SOC:

BackToTop

Hunting

Whatever is your methodology and use case for hunting, Azure Sentinel is a great hunting platform.

Learn more

BackToTop

———————

Expert (SOC engineer)

Technical overview (Level 200)

If you want to get an initial overview of Azure Sentinel’s technical capabilities

Learn more

You can read more about the features described in the Webinar here:

BackToTop

Cloud architecture and multi-workspace/tenant support

An Azure Sentinel instance is called a workspace. Multiple workspaces are often necessary and can act together as a single Azure Sentinel system. The first half of the Webinar above discusses Azure Sentinel’s workspace architecture.

Learn more

BackToTop

KQL

Most Azure Sentinel capabilities use KQL or Kusto Query Language. When you search in your logs, write rules, creating hunting queries or create workbooks, you use KQL.

The KQL Webinar is planned for June 2nd. Meanwhile, to learn KQL, use these resources:

In addition to KQL, to applying it to Azure Sentinel requires understanding the table schemas used by Azure Sentinel

BackToTop

Write rules

Learn more

Writing rules also requires understanding the table schemas used by Azure Sentinel

BackToTop

Creating playbooks

Start with the presentation

Learn more:

BackToTop

Developing workbooks

As we work to develop training materials for workbooks, start with the workbooks documentation

You might also want to refer to these workbook examples:

BackToTop

Hunting

Whatever is your methodology and use case for hunting, Azure Sentinel is a great hunting platform.

Learn more

BackToTop

———————

Advanced Topics

Extending and integrating Azure Sentinel

BackToTop

Deploying and Managing Azure Sentinel as Code

BackToTop

Roadmap

Since roadmap information is provided under NDA, please reach out to your Microsoft account team to discuss an Azure Sentinel roadmap presentation.

BackToTop

Where do I go from here?

BackToTop

Extra Resources

  • Build an Azure Sentinel Lab with prerecorded Data and a Custom Logs Pipe via ARM Templates 🚀 (Blog)
  • Azure Sentinel’s Resources in one place! (Blog)
  • PACKT: Learn Azure Sentinel (eBook/Print)
  • MICROSOFT PRESS: Azure Sentinel Planning (eBook/Print)
  • Implementing and Administering Azure Sentinel (Lynda.com)
  • Step-by-Step Guide to Deploy Azure Sentinel (Blog)

BackToTop