- 2 Sections
- 9 Lessons
- 2 Days
Expand all sectionsCollapse all sections
- Section: Day 1 — Foundations & Core Labs5
- 1.1Lesson 1.1: SOC in Microsoft — Roles, workflows, signal sources (Sentinel, Defender, Entra).
- 1.2Lesson 1.2: KQL Crash Course — Filters, time, parse, project, summarize.
- 1.3Lesson 1.3: Triage Workflow — Severity, enrichment, false vs. true positive.
- 1.4Lab A: KQL on Sentinel sample data — Find phishing, malware, and sign-in anomalies.
- 1.5Lab B: Incident in Sentinel — Investigate, contain, document a basic alert.
- Day 2 — Return, Q&A & Advanced Labs4
- 2.1Lesson 2.1: Field recap — what students tried at their company + Q&A.
- 2.2Lesson 2.2: Advanced KQL (ADX) — joins/union, parse_json, mv-expand, make-series, simple anomaly ideas.
- 2.3Lab C: Generate fresh telemetry — e.g., EICAR test, scheduled task creation, bulk failed logons; export to ADX.
- 2.4Lab D: Live log hunt in ADX — pivot across tables, build a timeline, derive IOAs/IOCs, write a short IR note (containment plan).
