Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
07Create detections and perform investigations using Microsoft Sentinel8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management0/56 units complete
Learning path 07 · Create detections and perform investigations using Microsoft Sentinel

8 modules · 56 units · Analytics, automation, playbooks, incidents, UEBA, ASIM, workbooks, and content management

0%

Study focus

Detection and response

Build analytics rules, automate triage, run playbooks, and manage security incidents.

Analytics and content

Apply UEBA, ASIM, KQL, workbooks, Content Hub solutions, and repository-based deployment.

8 modules · 56 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

01

Module 1

Threat detection with Microsoft Sentinel analytics

Focus: rule types, templates, custom logic, incident creation, entities, and lifecycle management.
0/9
01 / 09Introduction

Sentinel analytics turns ingested telemetry into alerts and incidents. Choose a detection method, define actionable logic, map entities, tune noise, and maintain the rule as threats and sources evolve.

Official moduleObjectives and prerequisites
02 / 09Exercise - Detect threats with Microsoft Sentinel analytics

Deploy a Sentinel workspace and test VM, install the Azure Activity solution, and connect subscription activity through Azure Policy. Retain the resources for the later detection exercise and monitor Azure cost.

Official exercisePrepare the lab
03 / 09What is Microsoft Sentinel Analytics?

Analytics correlates signals from endpoints, identities, networks, cloud services, and threat intelligence. Use cases include compromised accounts, suspicious behavior, exfiltration, insider threats, incident investigation, and hunting. Filter templates by severity, type, ATT&CK tactics, and source.

Official lessonAnalytics purpose and page
04 / 09Types of analytics rules
TypeUse
Scheduled / NRTCustom KQL on a schedule or near real time.
FusionML correlation of low-fidelity signals into multistage incidents.
Microsoft securityIncidents from connected Microsoft security alerts.
ML / anomalyMicrosoft-managed behavioral detections.
Threat intelligenceObservable matches against organizational events.
Exam takeaway: scheduled rules are customizable; managed Fusion and ML logic is not.
Official lessonAnalytics rule families
05 / 09Create an analytics rule from templates

Templates expose severity, required sources, ATT&CK mapping, and rule type. Scheduled and Microsoft security templates allow query or alert-filter tuning; Fusion and ML templates are generally enabled or disabled. A disabled Create rule action often indicates a missing connector.

Official lessonTemplate workflow
06 / 09Create an analytics rule from wizard
  1. Define metadata, severity, and ATT&CK mapping.
  2. Enter KQL and set frequency, lookback, threshold, and grouping.
  3. Map query columns to entities and custom details.
  4. Configure incidents and automated response.
  5. Validate and monitor the rule.

Entity mapping powers correlation, graphs, timelines, and investigation pivots.

Official lessonCustom rule wizard
07 / 09Manage analytics rules

Enable, disable, edit, duplicate, export, delete, and monitor rules. Tune KQL, thresholds, grouping, suppression, and exclusions using false-positive and missed-detection evidence. Document ownership, data dependencies, expected volume, and change history.

Official lessonRule lifecycle and tuning
08 / 09Exercise - Detect threats with Microsoft Sentinel analytics

Create a detection for successful Azure VM deletion, map caller and IP entities, generate test activity, and verify the alert and incident.

Official exerciseBuild and validate a detection
09 / 09Summary

Effective analytics begins with the right data, uses the appropriate rule type, maps entities, creates actionable incidents, and is continuously measured and tuned.

Official moduleSummary and assessment
End of learning pathCreate detections and perform investigations using Microsoft Sentinel