SC-200 Lab 7 – Microsoft Sentinel: Analytics Rules, Detections & ASIM

Microsoft Security Operations Analyst — Lab 7

Lab 7 – Microsoft Sentinel: Analytics Rules, Detections & ASIM

SC-200: Microsoft Security Operations Analyst

Overview


Built Sentinel analytics rules from scheduled queries, configured entity behavior analytics, simulated three real-world attack patterns against a connected server, wrote KQL detection rules for each attack, and implemented ASIM (Advanced Security Information Model) normalization parsers. Supplemented with Microsoft Learn exercises for Sentinel analytics setup and threat detection.

Prepare for simulated attacks: onboard WinServer to Azure Arc and understand three attack types — persistence registry key, user add privilege elevation, and DNS C2
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Tasks Completed


Create Detections: three scheduled query rules detecting persistence registry key, privilege elevation user add, and C2 DNS query attacks
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Environment: Employer-provided Azure subscription (resources deleted after lab).

Source Material


Completed using Exercise 2: Scheduled Query, Exercise 3: Entity Behavior, Exercise 4: Understand Attacks, Exercise 5: Perform Attacks, Exercise 6: Create Detections, and Exercise 8: ASIM from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises Analyze Data Setup and Detect Threats with Sentinel Analytics. Completed in an employer-provided Azure subscription.