Course overview
Modernize Microsoft security operations for the AI era. This Express workshop helps SOC analysts, incident responders, and threat hunters triage, investigate, hunt, and automate across Defender XDR, Microsoft Sentinel, Defender for Cloud workload signals, KQL, and Security Copilot-assisted workflows.
A hybrid SOC and analyst acceleration course using SC-200 concepts plus Security Copilot, Defender XDR, Microsoft Sentinel, Defender for Cloud AI workload signals, KQL, AI-era investigations, hunting, and automation. It is not a compressed SC-200 replacement.
Who this is for
SOC analysts, security operations analysts, incident responders, threat hunters, detection engineers, and security engineers supporting Microsoft security operations.
Prerequisites
Security operations fundamentals. Familiarity with Microsoft security tools, logs, incidents, and basic KQL concepts recommended.
Recommended prior course or experience: SC-900 or equivalent security fundamentals; Secure AI and Cloud Workloads Express for architects wanting preventive controls first.
Course outline
Microsoft security operations landscape
SOC analyst role and the security platform
Detect, triage, investigate, respond, hunt
Defender XDR, Sentinel, and Security Copilot
Escalation points and evidence standards
Defender XDR incidents and unified investigation
Microsoft Defender portal orientation
Incidents, alerts, entities, incident graph
Automated investigation and response
Advanced hunting across Defender data
Microsoft Sentinel as SIEM and SOAR
Data connectors, solutions, and content hub
Incidents, case management, and tasks
Workbooks, dashboards, and reporting
Unified operations in the Defender portal
KQL for detection, analysis, and hunting
KQL structure: filters, summarize, joins
Sentinel investigation queries
Defender advanced hunting queries
Turning questions into reusable KQL
Detection engineering and analytics
Built-in analytics rules and custom detections
Entity mapping, grouping, and tuning
Threat intelligence and MITRE ATT&CK
Detection lifecycle: query, test, tune, retire
Incident response and remediation
Triage severity, confidence, scope, impact
Reconstruct attack timelines across tools
Containment, remediation, and response
Documentation, closure, and lessons learned
Security Copilot-assisted SOC workflows
Prompting for summaries and next steps
Promptbooks for triage and reporting
Copilot with Defender XDR and Sentinel
Human validation and analyst accountability
AI workload and cloud signal scenarios
Defender for Cloud workload alerts
AI workload signals and resource context
Pivot from cloud alerts to identity and data
Escalation to cloud security architecture
Automation and operational improvement
Sentinel automation rules and playbooks
SOAR handoffs and approvals
Reusable notebooks and query libraries
SOC metrics and continuous improvement
Capstone SOC scenario
Triage a hybrid endpoint and identity incident
Use KQL, Defender, Sentinel, and Copilot
Write findings and escalation recommendations