Why it worked
The content provides a practical, project-based approach to learning a valuable cybersecurity skill, directly addressing the common need for job seekers to demonstrate real-world experience.
Summary
This slideshow outlines a cybersecurity project focused on building a mini SOC using Microsoft Sentinel. It details why this project is valuable for job seekers, what they will build, and how to document it for their CV.
Structure
- 1Introduction to the project and its value
- 2Setting up the Microsoft Sentinel lab
- 3Connecting data sources
- 4Generating alerts and creating rules
- 5Investigating incidents
- 6Writing up the project and adding it to a CV
Product placement
Microsoft Sentinel (SIEM): acts - it is a security information and event management system that is used to collect, detect, investigate, and respond to cyber threats. Removing it would change the entire project. Microsoft Defender: appears - it is a brand name mentioned in the caption, but not actively used or demonstrated in the slides. Removing it would not change what happens in the video. Azure free account / trial: acts - it is a prerequisite for setting up the lab, and is mentioned as a step in the process. Removing it would change the setup process. Log Analytics Workspace: acts - it is a component of Microsoft Sentinel used for storing and analyzing log data. Removing it would break the project setup. Windows VM: acts - it is used as a lab machine to generate logs. Removing it would change the project setup. Sysmon: acts - it is used to generate richer logs. Removing it would change the project setup. KQL: acts - it is a query language used to analyze logs and confirm events. Removing it would change the project setup. GitHub README: acts - it is a deliverable for the project, used to document findings. Removing it would change the project deliverables.