Running a SOC with Microsoft Defender XDR and Microsoft Sentinel: ingesting data, building detections, responding to incidents and hunting with KQL.
Sections from the books on security operations, free to read:
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them. SC-200
Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits. SC-200
How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice. SC-200
The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect. SC-200
The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits. SC-200
How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies. SC-200
Search the series glossary for Sentinel, or browse all 4,400 terms.
Know which Defender, Sentinel or KQL move fits the incident in front of you, and why.