SC-200 Lab 9 – Microsoft Sentinel: Threat Hunting, Workbooks & Notebooks

Microsoft Security Operations Analyst — Lab 9

Lab 9 – Microsoft Sentinel: Threat Hunting, Workbooks & Notebooks

SC-200: Microsoft Security Operations Analyst

Overview


Performed proactive threat hunting in Microsoft Sentinel using custom KQL hunting queries and Livestream, built and customized Sentinel workbooks for security data visualization, and used Jupyter notebooks for advanced investigation. Supplemented with Microsoft Learn exercises for threat hunting setup and data visualization.

Create Sentinel Workbooks: explore workbook templates, save and modify a template using Azure AD Audit logs, and create a custom workbook
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Tasks Completed


Perform Threat Hunting in Microsoft Sentinel: Sentinel Logs to Hunting query to Sentinel Livestream flow
Lab architecture diagram — Source: MicrosoftLearning/SC-200T00A-Microsoft-Security-Operations-Analyst, MIT License

Environment: Employer-provided Azure subscription (resources deleted after lab).

Source Material


Completed using Exercise 9: Workbooks, Lab 9 – Exercise 1: Threat Hunting, and Exercise 2: Notebooks from the SC-200T00A MicrosoftLearning GitHub repository; and Microsoft Learn exercises Threat Hunting Setup and Hunt for Threats in Sentinel. Completed in an employer-provided Azure subscription.