Guaranteed sessions from 1 enrollee • No postponement risk except force majeure • 60% hands-on
Key information
Duration1 day(s) / 6 h
Price550 € excl. VAT
LevelAdvanced
CertifyingNo
TailoredCustomizable programme
Upcoming sessions
25 Janv. 2027
15 Fév. 2027
15 Mars 2027
19 Avr. 2027
10 Mai 2027
Would you like to schedule this training on a specific date? Contact us by email or via the contact form.
Description of the training: Microsoft Sentinel SC-5001 Training Course: SIEM and advanced security operations
About the Microsoft Sentinel SC-5001 Training Course
This Microsoft Sentinel – SIEM and advanced security operations training teaches you to configure, operate and monitor a modern SIEM/SOAR security platform in Azure. You will learn to collect, analyse and correlate security events from various sources, write KQL queries to extract insights and build effective detection rules. The course also covers creating custom dashboards, automation through Azure Logic Apps playbooks, and the workflows of an operational SOC. Hands-on labs based on real scenarios will let you identify and respond to cybersecurity threats. By the end, you will be able to run advanced security operations with Microsoft Sentinel. You may also be interested in our Cloudflare Training Course and our Microsoft 365 Security – Complete IT Admins Bootcamp Training Course.
Good to know
Good to know before you enrol
This training includes plenty of hands-on exercises (around 60% practice) for better learning. Our sessions are guaranteed from a single registrant, with no risk of postponement (except in cases of force majeure). A preliminary discussion takes place between the participant and/or a company representative to fully take into account the participant’s profile (level, needs, professional context, challenges, etc.). Assessment: during the training, the trainer assesses participants’ progress through quizzes, role-play and practical exercises. Participants receive a certificate of completion at the end of the training. This training is part of our Cybersecurity Training Courses catalogue. Explore our other cybersecurity training courses to strengthen the protection of your information system against today’s threats.
Objectives of the training: Microsoft Sentinel SC-5001 Training Course: SIEM and advanced security operations
Learning objectives of the Microsoft Sentinel SC-5001 Training Course
By the end of the training, participants will be able to:
- Understand the fundamentals of SIEM/SOAR cybersecurity in a cloud environment
- Master the configuration, administration and monitoring of Azure Sentinel for threat detection and incident response
- Collect, normalise and analyse security data from various sources (logs, events, cloud/on-premises solutions)
- Implement detection rules, behavioural analytics and automation playbooks for incident response
- Develop actionable dashboards and reports for operational threat intelligence
- Apply best practices to operate a modern SIEM/SOAR Security Operations Centre (SOC)
Prerequisites of the training: Microsoft Sentinel SC-5001 Training Course: SIEM and advanced security operations
Prerequisites for the Microsoft Sentinel SC-5001 Training Course
Basic knowledge of cybersecurity, networks and threat models. Familiarity with logs, system events and KQL syntax (an introduction is a plus). Familiarity with Microsoft Azure (portal, resources, RBAC). Because every participant is unique, a personalised discussion with our expert lets us design a training course perfectly aligned with their objectives, level and professional challenges.
Target audience of the training: Microsoft Sentinel SC-5001 Training Course: SIEM and advanced security operations
Target audience
Security engineers, SOC analysts and SIEM managers. Cloud and DevOps administrators involved in security monitoring. Security architects or cybersecurity consultants who want to master Microsoft Sentinel for advanced security operations.
Detailed programme of the training: Microsoft Sentinel SC-5001 Training Course: SIEM and advanced security operations
Download the programme (PDF)
Introduction to SIEM and SOAR
- Key concepts of SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation and Response)
- Overview of Azure Sentinel features
Architecture and data collection
- Sentinel architecture, Log Analytics workspaces
- Data connectors: Azure, Windows, Linux, firewalls, Microsoft 365 and third-party sources
- Log normalisation and formats
Kusto Query Language (KQL)
- KQL fundamentals
- Search queries, aggregations and trend visualisation
- Query optimisation for performance
Analytics rules and intelligent detections
- Creating analytics rules based on conditions, trends and behaviours
- Using Machine Learning & predefined templates
- Testing for false positives / negatives
Incidents and investigations
- Designing investigations: trigrams, indicators and pivots
- Exploring entities and correlations between alerts
- Tracing attacks using investigation graphs
Playbooks and automation
- Introduction to Azure Logic Apps playbooks for automated response
- Playbook examples for quarantine, IP blocking and notifications
- Integration with Teams, email and ticketing
Dashboards and reporting
- Creating custom dashboards
- Publishing reports for compliance and management
- Real-time dashboards
Practical scenarios and SOC workflows
- Demonstrations of real detections: phishing, lateral movement, brute force, exfiltration
- Setting up a structured SOC alert and response process
Best practices and continuous security
- Cost management, log retention, data protection
- Periodic update of rules and tuning of playbooks
Why choose this training
- focuses on operating a cloud SIEM with Microsoft Sentinel
- covers detection, investigation and automated incident response
- emphasises real SOC use cases and continuous security best practices
- prepares you for the Microsoft SC-5001 exam
FAQ
What is Microsoft Sentinel?
Microsoft Sentinel is Microsoft’s cloud-native solution that combines SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation and Response). It collects logs from across your environment, detects threats with analytics rules and KQL, and automates response through playbooks. At MFE-IT it is delivered in a small group and tailored to your context.
What is the difference between Microsoft Sentinel and Microsoft Defender?
Microsoft Defender XDR focuses on detection and response across the Microsoft ecosystem (endpoints, identities, email, M365 SaaS). Microsoft Sentinel is a general-purpose SIEM that ingests data from any source (cloud, on-premises, third party) and centralises security operations.
What is the KQL language in Microsoft Sentinel?
KQL (Kusto Query Language) is the query language of Microsoft Sentinel and Azure Monitor, inspired by SQL but optimised for log and time-series analysis. It lets you filter, aggregate and correlate events to build detections and investigations.
How long is the Sentinel SC-5001 training at MFE-IT?
The training lasts 1 day (6 hours), fully tailored, with a maximum of 3 participants per session. It covers Sentinel architecture, data connectors, ASIM tables and schema, KQL, analytics rules, investigations and playbooks.