Rating 2.95 out of 5 (21 ratings in Udemy)
What you'll learn- Students will understand the first of its kind Azure cloud provisoned SAAS service called as Sentinel with complete hands on,
- Ability to comprehensively implement Azure Sentinel along wit practical walkthrough and Interview preparation.
- They will understand What Azure Sentinel is, how its different from other SIEM tools.
- Will get thourough understanding on Data Connectors
- Will be getting insight og Kusto Query Language(KQL) …
Rating 2.95 out of 5 (21 ratings in Udemy)
What you'll learn- Students will understand the first of its kind Azure cloud provisoned SAAS service called as Sentinel with complete hands on,
- Ability to comprehensively implement Azure Sentinel along wit practical walkthrough and Interview preparation.
- They will understand What Azure Sentinel is, how its different from other SIEM tools.
- Will get thourough understanding on Data Connectors
- Will be getting insight og Kusto Query Language(KQL)
- Pactical hands on for Native Connector to Azure Sentinel like Azure Security Center, Azure Activity etc.
- Pactical hands on for integrating external data connections like Firewall(Checkpoint,Paloalto), Antivirus(Symantec,Trendmicro)
- Implementation & Administration of Syslog Server to ingest log intermediatley
- Understanding Analytics Part via Investigation for various Incidents.
- Handling and responding to the Incident.
- Categorization of Incidents in Low,High,Medium etc and its relevance.
- Understanding Playbooks,Workbooks & Logic apps
DescriptionCloud based SIEM like Sentinel is the answer to the problems which are faced by mainstream SIEM tools with:
1. Efficient Automation by logic apps and playbooks.
2.Co-relation powered by Machine Learning Algorithms like Fusion.
3.Scalable with inbuilt Data Connectors and ability to design SaaS solution is always scalable.
4.Focused in noise reduction and focusing or reaching and remediation to those which can result in increase/breach of attack surface.
5.Built In the cloud .
6.Scope grows everyday hence integration of threat intel to handle them.