Cloud-native SIEM for intelligent security analytics and threat intelligence.
Next-gen endpoint protection, threat intelligence, and response.
Microsoft Defender for Endpoint — enterprise endpoint security platform for preventative protection.
Microsoft Defender for Identity — identify, detect, and investigate advanced threats and insider risks.
Microsoft Defender for Office 365 — safeguard emails and collaboration tools from malicious links and phishing.
IT Service Management platform to track, triage, and resolve security incidents.
Kusto Query Language — powerful querying to analyze vast amounts of security data in Sentinel.
Falcon Query Language — advanced threat hunting within the CrowdStrike ecosystem.
Automate repetitive tasks and orchestrate complex incident response playbooks.
Trace credential theft via MDO alerts, analyze headers, and contain compromised mailboxes before lateral movement begins.
Detect anomalous Kerberos activity in Sentinel, correlate with MDI signals, and execute identity containment playbooks.
Hunt living-off-the-land techniques using MDE advanced hunting queries and CrowdStrike Falcon telemetry.
Lead end-to-end containment, draft executive communications, and present findings in a simulated board-level briefing.
Operate a full 8-hour shift: triage queue, escalate P1s, write KQL detections, and hand off to the next analyst — exactly as you will on the job.
Complete the form below. Our team reviews every application within 48 hours.
Next cohort: starting soon