1 · IngestContent Hub solutions and data connectors bring data into the workspace.
2 · AnalyzeKQL, analytics rules, UEBA, and threat intelligence identify suspicious behavior.
3 · InvestigateAlerts become correlated incidents with entities and timelines.
4 · RespondAutomation rules and playbooks enrich, route, contain, or remediate.
Workbooks visualize KQL results; hunting queries and notebooks support proactive investigation. Content Hub packages connectors, analytics, workbooks, hunting queries, and automation content for a product or scenario.
Exam takeaway: connector → table → analytics alert → incident → automation is the core operational chain.
Official lessonSentinel components and workflow