Summary
In this chapter, we took a different approach to explain concepts. After familiarizing yourself with the portal, you learned about modern attacks and followed along with our SOC analysts as they worked through their incident queue. In the example, you were shown how to triage, manage, and investigate incidents, as well as how to follow through with a broader threat hunt leveraging advanced hunting, culminating in findings that drove configuration changes and custom detections that improved the security posture of the environment. We didn’t exhaustively cover every concept or tool available as we have in previous chapters. Rather than just listing all the possibilities, we decided to focus on real examples that hopefully help illustrate how things might work in practice, giving those who don’t use MDE for security operations daily a primer on how things can work and, hopefully, giving those that do some insights they didn’t have before.
At this point...