Session

Incident investigations and threat hunting with Microsoft Sentinel Graph

This session focuses on real‑world incident investigation and proactive threat hunting using Microsoft Sentinel, with a deep dive into the Sentinel Graph and entity relationships. We will walk through how security teams can pivot from alerts to incidents, understand attacker behavior through graph‑based investigations, and move seamlessly between investigation and hunting scenarios.
Through live demos, you will see how Sentinel correlates signals across users, devices, identities, and resources, enabling faster root‑cause analysis and more effective threat hunting. We will cover practical investigation workflows, advanced hunting techniques, and how to leverage graph context to uncover hidden attack paths and related activity.
Attendees will leave with actionable guidance on how to operationalize Sentinel for day‑to‑day SOC investigations and improve detection confidence and response speed using graph‑driven insights.

Uros Babic

Lead Product Engineer - Microsoft Security DevOps at Global CoE SoftwareOne team, Microsoft Security MVP, MCT

Belgrade, Serbia

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top