Better Together: Next Gen SOC Powered by Microsoft Sentinel and Tanium

This lab focuses on integrating Tanium with Microsoft Sentinel to enhance SOC (Security Operations Center) capabilities. The integration utilizes Tanium connectors and Sentinel's real-time capabilities to offer several benefits:

Data Integration: Students will learn how to send data from Tanium to Sentinel and create incidents using the Tanium connection.
Incident Management: The lab involves leveraging both automated and manual incident actions, utilizing Tanium as a data source.
Real-time Remediation: Students will use Tanium's API for real-time remediation actions within Sentinel.

Pre-Req(s): Practical experience with Tanium, specifically Threat Response; Basic understanding of Microsoft Sentinel

Additional details:

Session Tag
Endpoint Management, Incident Response, XEM Core
Session Type
In-Person, Lab
Modules
Asset, Comply, Core, Microsoft, Threat Response
Difficulty
Intermediate
Focus
Administrator, Advanced Content, Integrations, Security Practitioner
Industry
Agriculture, Mining & Raw Materials, Construction, Education, Energy, Utilities & Waste, Entertainment, Facilities, Lodging & Resorts, Financial Services, Government - Federal, Government - Local, Healthcare & Life Sciences, Holding Companies & Conglomerates, Hospitals & Physicians Clinics, Insurance, Law Firms & Legal Services, Manufacturing, Construction & Wholesale Trade, Media & Internet, Media & Telecommunications, Non-Profit & Charitable Organizations, Professional & Business Services, Real Estate, Retail & Hospitality, Software & Technology, Transportation Services, Other, Agriculture, Mining & Raw Materials, Energy, Utilities & Waste, Facilities, Lodging & Resorts, Clinics, Manufacturing, Construction & Wholesale, Trade, Transportation Service, Hospitals & Physicians, Construction & Wholesale Trade