Product placement
Microsoft Sentinel (SIEM): acts - it is a security information and event management system that is used to collect, detect, investigate, and respond to cyber threats. Removing it would change the entire project. Microsoft Defender: appears - it is a brand name mentioned in the caption, but not actively used or demonstrated in the slides. Removing it would not change what happens in the video. Azure free account / trial: acts - it is a prerequisite for setting up the lab, and is mentioned as a step in the process. Removing it would change the setup process. Log Analytics Workspace: acts - it is a component of Microsoft Sentinel used for storing and analyzing log data. Removing it would break the project setup. Windows VM: acts - it is used as a lab machine to generate logs. Removing it would change the project setup. Sysmon: acts - it is used to generate richer logs. Removing it would change the project setup. KQL: acts - it is a query language used to analyze logs and confirm events. Removing it would change the project setup. GitHub README: acts - it is a deliverable for the project, used to document findings. Removing it would change the project deliverables.