Week 7
Sentinel Analytics Rules & Advanced KQL
- Build a custom analytics rule from scratch and test it live
- Investigate a multi-alert incident from open to closed
- Advanced KQL: joins, summarise, let statements
Week 8
Entra ID, Defender for Identity & Credential Attacks
- Detect and investigate a password spray and an MFA fatigue attack
- Work a Defender for Identity DCSync alert end-to-end
- Recommend a Conditional Access policy that prevents the attack
Week 9
Defender for Endpoint & EDR Investigation
- Decode a Base64 PowerShell command and determine intent
- Isolate a confirmed malware device and write the containment ticket
- Threat & Vulnerability Management — prioritise CVEs by exposure
Week 10
Defender for Office 365 & Cloud Apps
- Investigate a Business Email Compromise — trace, contain, document
- Identify shadow IT and draft a block policy using MDCA
- Audit OAuth app permissions and flag high-risk consents
Week 11
Threat Intelligence & MITRE ATT&CK
- Map a real APT group's TTPs in ATT&CK Navigator
- Enrich 10 IOCs across VirusTotal, OTX, and AbuseIPDB
- Import a threat watchlist into Sentinel and build a firing rule
Week 12
Log Analysis, Malware Triage & Incident Response
- Reconstruct a full attack timeline from a 72-hour Event Log export
- Static malware analysis — strings, PE headers, VirusTotal
- Ransomware IR tabletop — rotate through every lifecycle role