Microsoft Sentinel Threat Detection Training Course
| Course code | SD-CS-004 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security operations teams often collect more telemetry than they can investigate effectively. Microsoft Sentinel can centralise alerts, incidents and threat intelligence, but value depends on analysts being able to write efficient KQL queries, tune analytics rules, validate detections and manage incident workflows. This course addresses the practical gap between deploying Sentinel and operating it as a dependable detection platform: reducing false positives, finding suspicious behaviour across data sources and producing evidence that supports timely escalation or containment decisions.
Participants work through the Microsoft Sentinel detection engineering lifecycle, from data connector selection and normalisation to hunting queries, scheduled analytics rules, incidents, automation rules and playbooks. They learn to investigate using entity pages, incident graphs, bookmarks and Microsoft Defender XDR context; map detections to MITRE ATT&CK; construct KQL queries for authentication, endpoint and network telemetry; and measure whether a rule is producing actionable alerts. The course also covers watchlists, threat intelligence indicators, content templates and rule-tuning methods for maintaining detection quality.
Instructor-led demonstrations are followed by guided exercises in a Sentinel lab environment using realistic attack scenarios. Participants investigate alerts, pivot through logs, build and test detection rules, and design automated response paths. They leave with a documented detection use case pack containing KQL queries, analytics-rule logic, MITRE ATT&CK mappings, tuning recommendations and an incident response workflow that can be adapted to their own Microsoft Sentinel workspace.
The course is designed for practitioners who already work with security logs, SIEM platforms or Microsoft security tooling and need to build operational threat detection capability in Sentinel.
Course objectives
By the end of this course, participants will be able to:
- Configure Microsoft Sentinel data connectors and assess log-source coverage against detection requirements
- Write KQL queries to identify suspicious authentication, endpoint and network activity
- Build scheduled analytics rules with thresholds, entity mappings, alert details and incident settings
- Map detection logic and investigation findings to relevant MITRE ATT&CK techniques
- Investigate Sentinel incidents using entity pages, timelines, incident graphs and bookmarks
- Tune noisy analytics rules using baselining, exclusions, suppression and rule-performance evidence
- Create automation rules and Logic Apps playbooks for triage, enrichment and response actions
- Produce a detection use case pack containing tested queries, rule logic, tuning criteria and escalation guidance
Benefits of attending
For you
- Build evidence-based Sentinel detections rather than relying solely on out-of-the-box alert rules
- Gain practical KQL fluency for investigating authentication, endpoint and network threats
- Demonstrate detection engineering capability through a reusable, documented use case pack
- Improve incident triage decisions by correlating Sentinel incidents with entities, timelines and Defender context
- Prepare for SOC analyst, threat hunting or detection engineering responsibilities in Microsoft security environments
For your organisation
- Increase the proportion of Sentinel alerts that have clear investigative value and escalation criteria
- Reduce analyst time spent on repetitive triage through better tuning, automation rules and playbooks
- Improve visibility of attack techniques by mapping log coverage and detections to MITRE ATT&CK
- Create reusable detection documentation that supports consistent handover, audit and operational maintenance
- Strengthen response decisions by connecting SIEM investigation workflows with Microsoft Defender XDR evidence
Target competencies
Who should attend
- SOC Analysts — who investigate alerts and need repeatable methods for triage and escalation in Sentinel
- Security Engineers — who configure SIEM telemetry, analytics rules and automated response workflows
- Threat Hunters — who need to convert hypotheses into KQL-led hunts and production detections
- Detection Engineers — who develop, test and tune detection content against adversary behaviours
- Incident Responders — who need richer Sentinel investigations and Defender XDR context during active incidents
- Cloud Security Administrators — who manage Azure and Microsoft security services and need to operationalise their logs
Requirements and prerequisites
Participants should understand core security operations concepts, including alerts, incidents, indicators of compromise, log sources and basic incident triage. Experience reviewing Windows security events, Microsoft Entra ID sign-in logs, endpoint telemetry or firewall logs is helpful. Attendees should be comfortable navigating the Azure portal and working with tables, filters and simple query logic; prior KQL experience is useful but not essential. This is not a beginner cyber security course. Deep Azure administration, software development expertise, prior Microsoft Sentinel deployment experience and advanced digital forensics knowledge are not required.
Training methodology
Each day combines instructor-led walkthroughs of Microsoft Sentinel features with structured lab work in realistic investigation and detection scenarios. Participants query supplied log data, analyse alerts, inspect entities and incidents, and build rules in a controlled Sentinel workspace. Short case discussions examine false-positive reduction, escalation choices and coverage gaps. Working in pairs and small groups, participants review each other’s detection logic against MITRE ATT&CK and operational requirements. The final day includes application planning, where each participant prioritises a detection use case for implementation in their own environment.
Course outline
Day 1: Sentinel architecture, telemetry and investigation foundations
- Microsoft Sentinel workspace architecture and core service components
- Log Analytics tables, retention and ingestion considerations
- Data connector selection for identity, endpoint, cloud and network telemetry
- Common Security Log and ASIM normalisation concepts
- Microsoft Sentinel incidents, alerts, entities and evidence relationships
- MITRE ATT&CK as a framework for detection coverage
- KQL query structure, operators and time-bound filtering
Workshop: Participants connect and explore sample telemetry, then produce a log-source coverage map for a defined attack scenario.
Day 2: KQL investigation and proactive threat hunting
- KQL filtering, projection, sorting and summarisation techniques
- Joins, unions and parsing methods for correlating security events
- Investigating Microsoft Entra ID sign-in anomalies with KQL
- Endpoint process, file and network activity analysis
- Querying firewall and network security telemetry
- Hunting query design from adversary hypotheses
- Bookmarks, query results and investigation evidence capture
Workshop: Participants investigate a suspected account compromise and produce a bookmarked KQL evidence trail with an initial triage recommendation.
Day 3: Detection engineering with analytics rules
- Scheduled, near-real-time, fusion and anomaly analytics rule types
- Translating threat scenarios into testable detection logic
- Rule thresholds, lookback periods and query scheduling
- Entity mapping for accounts, hosts, IP addresses and URLs
- Alert details, custom details and incident grouping configuration
- MITRE ATT&CK tactic and technique tagging in analytics rules
- Content hub solutions, templates and version-controlled detection content
Workshop: Participants build and test a scheduled analytics rule for suspicious sign-in behaviour, including entity mappings and ATT&CK coverage.
Day 4: Incident management, tuning and response automation
- Incident queue management, ownership, status and severity decisions
- Entity pages, incident graphs and investigation timelines
- Microsoft Defender XDR incident and device context
- False-positive analysis using alert samples and baseline behaviour
- Rule tuning through exclusions, suppression and threshold changes
- Automation rules for incident assignment, tagging and prioritisation
- Logic Apps playbooks for enrichment, notification and containment workflows
Workshop: Participants tune a noisy detection and design an automation workflow that enriches, assigns and routes the resulting incident.
Day 5: Detection operations and implementation planning
- Detection lifecycle governance from use case to retirement
- Measuring rule fidelity, alert volume and investigation effort
- Coverage-gap analysis using MITRE ATT&CK matrices
- Watchlists for high-value assets, approved accounts and contextual enrichment
- Threat intelligence indicators and matching analytics
- Detection documentation, testing criteria and change control
- Prioritised Sentinel implementation roadmap development
Workshop: Participants complete a detection use case pack and present a prioritised 90-day improvement plan for their Sentinel operating model.
Tools & standards covered
Microsoft Sentinel, Kusto Query Language (KQL), Microsoft Defender XDR, MITRE ATT&CK
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
05 – 09 Oct 2026Book
Dar es Salaam · USD 3,500 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Cape Town · USD 4,200 -
19 – 23 Oct 2026Book
Dubai · USD 4,500 -
26 – 30 Oct 2026Book
Nairobi · USD 3,000 -
26 – 30 Oct 2026Book
Cape Town · USD 4,200 -
26 – 30 Oct 2026Book
Dubai · USD 4,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Splunk Enterprise Security SIEM Operations Training Course
Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…
IBM QRadar SIEM Administration and Offence Investigation Training Course
IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires mor…
Cyber Security for IT Auditors and Assurance Teams Training Course
IT auditors and assurance teams are expected to provide defensible conclusions on cyber risk, yet many audits still rely on high-level polic…
NIST Cybersecurity Framework Implementation Training Course
Organisations often have security controls, policies, audit findings and risk registers in separate places, yet cannot clearly show how thos…