Overview
Microsoft Sentinel, formerly Azure Sentinel, is a security information and event management (SIEM) platform built for the cloud. It gives organisations a complete and integrated security solution. It is made to help organisations find security threats, look into them, and respond to them in real-time. Built on Microsoft Azure, the platform uses artificial intelligence and machine learning algorithms to protect against advanced threats. The solution helps you monitor and analyse security-related data in real time. This includes logs and alerts from firewalls, endpoints, and applications, among other places.Components of Microsoft Sentinel
Microsoft Sentinel is a complete security system made up of the following parts:- Sentinel Dashboard: A unified security dashboard gives real-time visibility into security events and alerts. This allows organisations to quickly spot security incidents and take action.
- Resource analysis for a single machine
- Machine learning
- Rule management
- Sentinel Hunting: Advanced threat-hunting capabilities allow organisations to look for potential security threats in their environment before they happen.
- Sentinel Automation and Response (SAR): A security orchestration, automation, and response (SOAR) solution that automates responding to security incidents. This allows organisations to do so quickly and effectively.
- Sentinel Analytics: A set of analytics tools powered by machine learning and artificial intelligence that help organisations find security threats. This lets us find and respond to security threats in real-time.
- Sentinel Data Connectors: With pre-built data connectors, companies can easily connect Microsoft Sentinel to their security data sources, such as firewalls, endpoints, and cloud services.
- Sentinel API: A powerful API lets organisations automate security workflows and add Sentinel to their existing security tools and systems.
- Sentinel Workspace: A collaborative workspace lets organisations share security information and collaborate with other security team members on security incidents.
Stages of Microsoft Sentinel
Microsoft Sentinel can be categorised into the following broad stages:




