Specialization
Microsoft Sentinel SIEM Engineer
Master SIEM and SOAR with Microsoft Sentinel — log ingestion, KQL, analytics rules, incident investigation, threat hunting, workbooks, automation and Defender XDR integration.
LEARNING OUTCOMES
What you will learn
Sentinel architecture and data connectors
Kusto Query Language (KQL)
Analytics rules and incident management
Threat hunting and SOAR automation
Curriculum
Introduction to SIEM, SOC architecture, SIEM vs SOAR, security monitoring, MITRE ATT&CK framework, incident lifecycle
Sentinel architecture, Log Analytics workspace, data connectors, Sentinel portal, cost management, workspace design
Microsoft Defender XDR, Entra ID logs, Azure activity logs, Office 365 logs, Syslog, Windows security events, CEF
KQL fundamentals, filtering, parsing, joins, aggregations, hunting queries, workbook queries
Scheduled and NRT rules, Fusion detection, incident queue, investigation graph, entity mapping, alert tuning
Hunting queries, MITRE ATT&CK mapping, bookmarks, live investigation, Sentinel workbooks, dashboards, executive reporting
Automation rules, Logic Apps, playbooks, email notifications, Microsoft Teams integration, incident automation, response workflows
Deploy Sentinel for an enterprise SOC, connect log sources, create analytics rules, build hunting queries, dashboards and automation playbooks
Tools covered: Microsoft Sentinel, Log Analytics Workspace, Microsoft Defender XDR, Microsoft Entra ID, Defender for Endpoint, Defender for Office 365, Azure Monitor, Logic Apps, KQL
Program experience
Each cohort combines instructor-led sessions, guided practice, weekly assignments, capstone work and career preparation.