Setting up and optimising Microsoft Sentinel

Jason Smyth

Automation Engineer

Technical Writer

Cybersecurity Specialist

Azure

Azure DevOps

Finance

This consultation project involved setting up Microsoft Sentinel to help with the detection, investigation, and response to cybersecurity threats in the organisation's cloud landscape.
It started with the deployment of Content Types such as Content Hub Solutions, Data Connectors and Analytics Rules. Content Hub Solutions included those that scan for threats across Azure Services such as Azure Activity, Microsoft Defender for Cloud, Microsoft Defender XDR and Microsoft Entra ID.
Further scope within the project involved the maintenance of those data connectors against their Content Hub Solutions. Suggestions were also made for ongoing changes for add/update/delete Content Hub Solutions based on this review.
Part of the project involved reviewing Analytics Rules for missing/disabled threat detections and making a list of suggested changes/updates to increase their rule coverage.
I include an example image of the documentation that shows how to configure and manage Analytic/Detection Rules used in Microsoft Sentinel.
As this project is under NDA (Non-Disclosure Agreement), I am unable to share full details due to confidentiality reasons. Verification for this work can be confirmed by the project sponsor who has provided a recommendation/review:
Like this project
0

Posted Feb 24, 2025

Consulting for setting up and optimising Microsoft Sentinel and deploying Content Types such as Content Hub Solutions, Data Connectors and Analytics Rules.

Likes

0

Views

3

Timeline

Sep 18, 2023 - May 16, 2024

Tags

Automation Engineer

Technical Writer

Cybersecurity Specialist

Azure

Azure DevOps

Finance

Configure SIEM Security Operation using Microsoft Sentinel
Configure SIEM Security Operation using Microsoft Sentinel
Cyber Security Technical Interviewer
Cyber Security Technical Interviewer
Set up Automated Deployment of Microsoft Sentinel
Set up Automated Deployment of Microsoft Sentinel
Set up Microsoft Sentinel and Microsoft 365 Lighthouse
Set up Microsoft Sentinel and Microsoft 365 Lighthouse