CHƯƠNG 12 AZ-500 2 labs Defender & Sentinel 30–35% Chương cuối

Microsoft Sentinel, KQL & Security Operations

Xây dựng SIEM/SOAR với Microsoft Sentinel — kết nối data connectors, viết KQL, tạo analytics rule, điều tra và đóng incident, tự động hóa phản ứng bảo mật.

🎯 Mục Tiêu Chương

  • Triển khai Microsoft Sentinel trên Log Analytics Workspace.
  • Kết nối Azure Activity, Defender for Cloud và Entra ID data connectors.
  • Viết KQL cơ bản để query và phân tích log.
  • Tạo Scheduled Analytics Rule tự động sinh incident.
  • Điều tra, triage và đóng incident theo quy trình SOC chuẩn.

📚 12.1 Microsoft Sentinel Overview

Microsoft Sentinel là cloud-native SIEM (Security Information and Event Management) và SOAR (Security Orchestration, Automation and Response) built on Azure Log Analytics.

Collect

Data connectors thu thập log từ Azure, Microsoft 365, on-premises và multi-cloud

Detect & Investigate

Analytics rules phát hiện threats, incident management và investigation graph

Respond

Automation rules và playbooks (Logic Apps) tự động hóa phản ứng với incidents

Data Connectors chính cho AZ-500
Azure Activity: Tất cả thao tác trên subscription — create, delete, role assign...
Microsoft Defender for Cloud: Alerts và recommendations từ Defender
Microsoft Entra ID: Sign-in logs, audit logs, risky users
Windows Security Events: Event log từ Windows Server qua AMA
Microsoft 365 Defender: Alerts từ Defender for Endpoint/Office/Identity
Syslog / CEF: Linux syslog, network appliances qua AMA agent
2026 — Azure Monitor Agent (AMA): AMA thay thế MMA (Microsoft Monitoring Agent) và OMS agent. Dùng Data Collection Rules (DCR) để cấu hình collection linh hoạt. Khi deploy Sentinel connector cho Windows/Linux, dùng AMA-based connector thay vì connector legacy.

📚 12.3 Kusto Query Language (KQL)

KQL là ngôn ngữ query cho Log Analytics và Sentinel. Cú pháp pipe | — mỗi operator nhận output từ operator trước.

Lọc & Chiếu
  • where — lọc theo điều kiện
  • project — chọn cột hiển thị
  • project-away — bỏ cột không cần
  • extend — thêm cột tính toán
Tổng hợp & Sắp xếp
  • summarize — group + aggregate
  • count() — đếm số dòng
  • order by — sắp xếp
  • top N by — lấy N dòng đầu
Thời gian & Join
  • ago(24h) — 24 giờ trước
  • TimeGenerated > ago(7d)
  • join kind=inner
  • parse — tách string
Phát hiện thao tác xóa resource trong 24 giờ:
KQL — Microsoft Sentinel / Log Analytics
AzureActivity
| where TimeGenerated > ago(24h)
| where OperationNameValue has "delete"
| project TimeGenerated, Caller, OperationNameValue, ResourceGroup, ActivityStatusValue
| order by TimeGenerated desc
Tổng hợp hoạt động theo user trong 7 ngày (dùng cho workbook):
KQL — Microsoft Sentinel / Log Analytics
AzureActivity
| where TimeGenerated > ago(7d)
| summarize TotalEvents=count() by Caller, OperationNameValue
| order by TotalEvents desc
Phát hiện sign-in thất bại nhiều lần (brute force pattern):
KQL — Entra ID SignInLogs
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != "0"
| summarize FailedAttempts=count() by UserPrincipalName, IPAddress
| where FailedAttempts >= 10
| order by FailedAttempts desc
Phát hiện role assignment mới (privilege escalation):
KQL — AzureActivity
AzureActivity
| where TimeGenerated > ago(24h)
| where OperationNameValue == "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE"
| where ActivityStatusValue == "Success"
| project TimeGenerated, Caller, ResourceGroup, Properties
| order by TimeGenerated desc

📚 12.4 Analytics Rules

Analytics Rules chạy KQL định kỳ, khi kết quả match điều kiện → tạo Alert → Incident. Đây là cơ chế phát hiện threat chính của Sentinel.

Scheduled Query Rule
  • • KQL query chạy theo schedule (mỗi 5 phút — 24 giờ)
  • • Lookup period (data range): tối đa 14 ngày
  • Entity mapping: map column → Account/IP/Host entity
  • Alert grouping: gom nhiều alert thành 1 incident
  • • Severity: Informational/Low/Medium/High
Loại Rule khác
  • Microsoft Security Rule: tự động tạo incident từ alert của Defender products
  • Fusion Rule: ML-based correlation nhiều signal → low-fidelity threats
  • ML Behavior Analytics: anomaly detection tự động
  • Threat Intelligence: match IOC với log

📚 12.5 Incident Response Workflow

Quy trình chuẩn SOC khi xử lý incident trong Sentinel:

1
Triage — Đánh giá ban đầu

Xem severity, tactics, entities liên quan. Gán owner và đổi status từ NewActive.

2
Investigate — Investigation Graph

Xem entity liên quan (User, IP, Host, Process). Drill-down timeline của từng entity. Chạy hunting query để tìm thêm evidence.

3
Respond — Containment & Eradication

Chạy playbook (disable user, block IP, isolate VM). Thêm comment ghi nhận findings. Update evidence.

4
Close — Đóng Incident

Chọn Close reason: True Positive, False Positive, Benign Positive, Undetermined. Ghi comment lý do đóng. Status → Closed.

📚 12.6 Automation Rules & Playbooks

Automation Rule

Rule đơn giản, không cần code. Trigger: khi incident tạo hoặc update. Actions:

  • • Assign owner tự động
  • • Thay đổi severity
  • • Thêm tag
  • • Chạy playbook
  • • Đóng incident (cho false positive pattern)
Playbook (Logic App)

Workflow phức tạp với nhiều steps và conditions:

  • • Notify Teams channel về incident
  • • Gửi email với incident details
  • • Disable Entra user bị compromise
  • • Block IP trên firewall
  • • Tạo ticket trong ServiceNow/Jira

🧪 Lab Trong Chương

✅ Checklist Cuối Chương

  • Deploy được Microsoft Sentinel trên Log Analytics Workspace.
  • Kết nối được Azure Activity và ít nhất 1 data connector khác.
  • Viết được KQL cơ bản: where, project, summarize, order by.
  • Tạo được Scheduled Analytics Rule và xác nhận incident sinh ra.
  • Điều tra và đóng incident với lý do phù hợp (True/False Positive).

Hoàn thành 12 Chương AZ-500!

Bạn đã đi qua toàn bộ nội dung lý thuyết — từ Identity Security đến Sentinel. Tiếp theo: Capstone Project tổng hợp end-to-end.

Zalo