During this eight-hour workshop, we will demonstrate the capabilities of Microsoft Sentinel, LTIMindtree’s SOC process, frameworks and accelerators to enhance threat detection and response.
Microsoft Sentinel is a cloud-native scalable SIEM and SOAR solution. Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response.
- Collect data at cloud-scale across all the users, devices, applications and infrastructure both at on-premise and cloud
- Minimize false positives using AI/ML ( analytics) and threat intelligence
- Investigate threats using AI and hunt for adversaries hidden in the environment
- Rapid incident response to threats using built-in orchestration, automation playbooks and workflows
During this eight-hour workshop, we will demonstrate the capabilities of Microsoft Sentinel, LTIMindtree’s SOC process, frameworks and accelerators to enhance threat detection and response.
Build and Integrate:
- Rapid deployment of Microsoft Sentinel and its modules
- Provision Sentinel workspaces across different geographies to meet local/region data regulatory requirements
- Demonstrate log retention options and explain what works best in different scenarios
- Onboarding of various log sources using different log source integration methods
- Integration with collaboration tools such as Microsoft Teams, ServiceNow
- Integration with Azure Lighthouse for single-pane of glass monitoring
Manage and Operate:
- SOC detection channels and corresponding sources
- Incident detection, investigation and analysis using different use cases
- Use case development and enhancements
- Threat hunting framework and use cases
Enhance and Optimize:
- Demonstration of the workflow automation using Logicapps
- Incident prioritization
- SOC analyst efficiency
- Integration with OSINT threat intelligence
After this workshop, you will:
- Understand the benefits of cloud-native SIEM solutions
- Be assured of meeting local/regional data regulatory compliance requirements
- Understand rapid detection and response to evolving threats using Sentinel and LTIMindtree’s SOC process
- Know more about operational efficiency using LTIMindtree’s SOC accelerators and framework
- Gain visibility into threat and security posture