- Mitigating threats with Microsoft Defender for Endpoint
- Protection against threats
- Deploying the environment
- Implementing Windows 10 security enhancements with
- Managing alerts and incidents
- Performing device investigations
- Performing actions on a device
- Performing evidence and entity investigations
- Configuring and managing automation
- Configuring alerts and detections
- Threat and vulnerability management
- Mitigating threats with Microsoft 365 Defender
- Introduction to threat protection with Microsoft 365
- Mitigating incidents
- Protecting identities with Azure AD Identity Protection
- Remediating risks with Microsoft Defender for Office 365
- Securing the environment
- Securing cloud apps and services with Microsoft Cloud App Security
- Responding to data loss prevention alerts
- Managing insider risk
- Defending against threats with Azure Defender
- Planning cloud workload protection measures
- Explaining cloud workload protection
- Connecting Azure resources
- Connecting non-Azure resources
- Remediating security alerts
- Creating queries for Azure Sentinel with Kusto Query Language (KQL)
- Constructing KQL statements for Azure Sentinel
- Analysing query results with KQL
- Creating multi-table statements with KQL
- Working with data in Azure Sentinel using Kusto Query Language
- Configuring your Azure Sentinel environment
- Introduction to Azure Sentinel
- Creating and managing workspaces
- Querying logs
- Using watchlists
- Using threat intelligence
- Connecting logs to Azure Sentinel
- Connecting data using data connectors
- Connecting Microsoft services
- Connecting to Microsoft 365 Defender
- Connecting Windows hosts
- Connecting Common Event Format logs
- Connecting Syslog data sources
- Connecting threat indicators
- Creating detections and performing investigations with Azure Sentinel
- Detecting threats with Azure Sentinel analytics
- Responding to threats with Azure Sentinel playbooks
- Managing security incidents
- Using entity behaviour analytics
- Querying, visualising and monitoring data
- Performing threat hunting in Azure Sentinel
- Threat hunting
- Threat hunting using notebooks