Visão Geral
O curso Microsoft Sentinel Advanced Administration foi desenvolvido para profissionais responsáveis pela administração, arquitetura e evolução de ambientes Microsoft Sentinel em organizações de médio e grande porte. O treinamento aborda recursos avançados de integração, normalização de dados, detecção de ameaças, automação de resposta, inteligência de ameaças e operações avançadas de SOC.
Durante o curso, os participantes aprenderão a projetar arquiteturas escaláveis, implementar ambientes multi-tenant, desenvolver regras avançadas de detecção, utilizar recursos de UEBA, integrar fontes de inteligência de ameaças e automatizar processos de resposta utilizando Microsoft Sentinel e Azure Logic Apps.
Conteúdo Programatico
Module 1: Advanced Microsoft Sentinel Architecture
- Advanced Sentinel Architecture
- Enterprise Security Monitoring Design
- High-Scale Deployment Strategies
- Data Ingestion Architecture
- Security Operations Architecture
- Governance and Operational Best Practices
Module 2: Multi-Tenant Security Operations
- Multi-Tenant Concepts
- Lighthouse Architecture
- Tenant Segregation Models
- Cross-Tenant Monitoring
- Access Control Strategies
- Operational Governance
Module 3: Advanced Data Connectors
- Connector Architecture
- Advanced Microsoft Connectors
- Third-Party Integrations
- API-Based Integrations
- Custom Log Sources
- Connector Health Monitoring
Module 4: Log Normalization and Data Management
- Log Normalization Concepts
- Data Quality Management
- Schema Standardization
- Data Transformation Techniques
- Ingestion Optimization
- Operational Monitoring
Module 5: Azure Sentinel Information Model (ASIM)
- ASIM Architecture
- Normalized Schemas
- Parsers and Transformations
- ASIM Implementation
- Query Optimization
- Cross-Source Correlation
Module 6: Custom Analytics Rules
- Detection Engineering Concepts
- Analytics Rule Architecture
- Custom Detection Development
- Correlation Rules
- Advanced Alert Logic
- Detection Validation and Tuning
Module 7: User and Entity Behavior Analytics (UEBA)
- UEBA Fundamentals
- Behavioral Analytics Models
- Entity Risk Scoring
- Insider Threat Detection
- Anomaly Detection
- Investigation Techniques
Module 8: Watchlists Administration
- Watchlists Fundamentals
- Data Sources and Import Methods
- Dynamic Watchlists
- Correlation with Analytics Rules
- Investigation Workflows
- Operational Best Practices
Module 9: Advanced Workbooks
- Workbook Architecture
- Advanced Visualizations
- Interactive Dashboards
- Security KPI Development
- Executive Dashboards
- SOC Operational Dashboards
Module 10: SOAR with Azure Logic Apps
- SOAR Architecture
- Logic Apps Fundamentals
- Automated Investigation
- Automated Containment Actions
- Incident Response Automation
- Workflow Optimization
Module 11: Threat Intelligence Integration
- Threat Intelligence Framework
- IOC Management
- Threat Intelligence Platforms
- TAXII and STIX Integration
- Threat Enrichment
- Intelligence-Driven Detection
Module 12: Content Hub Administration
- Content Hub Overview
- Solution Packages
- Analytics Content
- Community Content
- Deployment and Maintenance
- Content Lifecycle Management
Module 13: Microsoft Defender XDR Integration
- Defender XDR Architecture
- Unified Security Operations
- Incident Synchronization
- Threat Intelligence Sharing
- Cross-Platform Investigation
- Unified SOC Operations
Module 14: Advanced Security Operations
- Advanced Threat Detection
- Threat Hunting Integration
- Detection Optimization
- False Positive Reduction
- Security Metrics and Reporting
- Continuous Improvement Processes
Module 15: Enterprise SOC Design with Sentinel
- SOC Architecture Design
- Tiered Operations Model
- Governance Frameworks
- Operational Procedures
- Maturity Assessment
- Security Operations Roadmap
Laboratórios Práticos
- Implementação de arquitetura corporativa Microsoft Sentinel
- Configuração de ambiente Multi-Tenant com Azure Lighthouse
- Integração avançada de fontes de dados
- Implementação de normalização utilizando ASIM
- Desenvolvimento de Analytics Rules personalizadas
- Configuração e análise de UEBA
- Administração de Watchlists corporativas
- Desenvolvimento de Workbooks avançados
- Construção de Playbooks utilizando Azure Logic Apps
- Integração de fontes de Threat Intelligence
- Implantação de soluções através do Content Hub
- Integração operacional com Microsoft Defender XDR
- Criação de processos automatizados de investigação
- Otimização de regras para redução de falsos positivos
- Simulação completa de operações de SOC corporativo