🎯 Mục Tiêu Chương
- Triển khai Microsoft Sentinel trên Log Analytics Workspace.
- Kết nối Azure Activity, Defender for Cloud và Entra ID data connectors.
- Viết KQL cơ bản để query và phân tích log.
- Tạo Scheduled Analytics Rule tự động sinh incident.
- Điều tra, triage và đóng incident theo quy trình SOC chuẩn.
📚 12.1 Microsoft Sentinel Overview
Microsoft Sentinel là cloud-native SIEM (Security Information and Event Management) và SOAR (Security Orchestration, Automation and Response) built on Azure Log Analytics.
Data connectors thu thập log từ Azure, Microsoft 365, on-premises và multi-cloud
Analytics rules phát hiện threats, incident management và investigation graph
Automation rules và playbooks (Logic Apps) tự động hóa phản ứng với incidents
📚 12.3 Kusto Query Language (KQL)
KQL là ngôn ngữ query cho Log Analytics và Sentinel. Cú pháp pipe | — mỗi operator nhận output từ operator trước.
where— lọc theo điều kiệnproject— chọn cột hiển thịproject-away— bỏ cột không cầnextend— thêm cột tính toán
summarize— group + aggregatecount()— đếm số dòngorder by— sắp xếptop N by— lấy N dòng đầu
ago(24h)— 24 giờ trướcTimeGenerated > ago(7d)join kind=innerparse— tách string
AzureActivity
| where TimeGenerated > ago(24h)
| where OperationNameValue has "delete"
| project TimeGenerated, Caller, OperationNameValue, ResourceGroup, ActivityStatusValue
| order by TimeGenerated desc
AzureActivity
| where TimeGenerated > ago(7d)
| summarize TotalEvents=count() by Caller, OperationNameValue
| order by TotalEvents desc
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType != "0"
| summarize FailedAttempts=count() by UserPrincipalName, IPAddress
| where FailedAttempts >= 10
| order by FailedAttempts desc
AzureActivity
| where TimeGenerated > ago(24h)
| where OperationNameValue == "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE"
| where ActivityStatusValue == "Success"
| project TimeGenerated, Caller, ResourceGroup, Properties
| order by TimeGenerated desc
📚 12.4 Analytics Rules
Analytics Rules chạy KQL định kỳ, khi kết quả match điều kiện → tạo Alert → Incident. Đây là cơ chế phát hiện threat chính của Sentinel.
- • KQL query chạy theo schedule (mỗi 5 phút — 24 giờ)
- • Lookup period (data range): tối đa 14 ngày
- • Entity mapping: map column → Account/IP/Host entity
- • Alert grouping: gom nhiều alert thành 1 incident
- • Severity: Informational/Low/Medium/High
- • Microsoft Security Rule: tự động tạo incident từ alert của Defender products
- • Fusion Rule: ML-based correlation nhiều signal → low-fidelity threats
- • ML Behavior Analytics: anomaly detection tự động
- • Threat Intelligence: match IOC với log
📚 12.5 Incident Response Workflow
Quy trình chuẩn SOC khi xử lý incident trong Sentinel:
Xem severity, tactics, entities liên quan. Gán owner và đổi status từ New → Active.
Xem entity liên quan (User, IP, Host, Process). Drill-down timeline của từng entity. Chạy hunting query để tìm thêm evidence.
Chạy playbook (disable user, block IP, isolate VM). Thêm comment ghi nhận findings. Update evidence.
Chọn Close reason: True Positive, False Positive, Benign Positive, Undetermined. Ghi comment lý do đóng. Status → Closed.
📚 12.6 Automation Rules & Playbooks
Rule đơn giản, không cần code. Trigger: khi incident tạo hoặc update. Actions:
- • Assign owner tự động
- • Thay đổi severity
- • Thêm tag
- • Chạy playbook
- • Đóng incident (cho false positive pattern)
Workflow phức tạp với nhiều steps và conditions:
- • Notify Teams channel về incident
- • Gửi email với incident details
- • Disable Entra user bị compromise
- • Block IP trên firewall
- • Tạo ticket trong ServiceNow/Jira
🧪 Lab Trong Chương
Triển khai Sentinel, kết nối Azure Activity & tạo Analytics Rule
Tạo Log Analytics Workspace, bật Sentinel, kết nối Azure Activity connector, tạo hành động test trong Azure, viết KQL query AzureActivity, tạo scheduled analytics rule phát hiện thao tác delete nhạy cảm, kiểm tra incident sinh ra.
AzureActivity
| where TimeGenerated > ago(24h)
| where OperationNameValue has "delete"
| project TimeGenerated, Caller, OperationNameValue, ResourceGroup, ActivityStatusValue
| order by TimeGenerated desc
Điều tra Incident & tạo Workbook giám sát bảo mật
Mở incident từ lab trước, gán owner, đổi status, xem entity liên quan, thêm comment điều tra, chạy hunting query, tạo workbook hiển thị hoạt động nhạy cảm theo user, đóng incident với lý do phù hợp.
AzureActivity
| where TimeGenerated > ago(7d)
| summarize TotalEvents=count() by Caller, OperationNameValue
| order by TotalEvents desc
✅ Checklist Cuối Chương
- Deploy được Microsoft Sentinel trên Log Analytics Workspace.
- Kết nối được Azure Activity và ít nhất 1 data connector khác.
- Viết được KQL cơ bản: where, project, summarize, order by.
- Tạo được Scheduled Analytics Rule và xác nhận incident sinh ra.
- Điều tra và đóng incident với lý do phù hợp (True/False Positive).
Hoàn thành 12 Chương AZ-500!
Bạn đã đi qua toàn bộ nội dung lý thuyết — từ Identity Security đến Sentinel. Tiếp theo: Capstone Project tổng hợp end-to-end.