In this course, we’ll dive deep into identity threat hunting using Microsoft’s security ecosystem. You’ll learn how to use Kusto Query Language (KQL) to detect identity threats and anomalies in Microsoft Entra, set up real-time alerts, and automate investigations to reduce response time. We’ll explore how Microsoft Sentinel and Defender XDR work together to provide end-to-end visibility into identity-based attacks, privilege misuse, and suspicious sign-in patterns. You’ll leverage automation, analytics, and advanced hunting techniques to stay ahead of evolving threats, with a major focus on building and refining KQL queries

Identity Threat Hunting: A Modern KQL Approach

Explore how to leverage Kusto Query Language (KQL) queries in Microsoft Sentinel and Microsoft Defender to build a proactive identity security strategy. You’ll learn how to detect anomalies in sign-in patterns, identify privilege escalations, investigate risky OAuth grants using advanced KQL queries. You’ll obtain the skills to transform raw identity data into actionable insights to respond to attacks.

Retake this course?
Retaking this course from the beginning will reset all of your tracked progress.
Retake