Creating Custom Analytics Rules and Investigating Incidents in Microsoft Sentinel
Learn how to create custom analytics rules in Microsoft Sentinel, map entities to enrich alerts, and investigate incidents generated from suspicious activities.

Lab overview
Custom analytics rules in Microsoft Sentinel enable you to define specific criteria for detecting malicious activities based on your unique security needs. These rules allow you to identify and mitigate advanced threats that may not be covered by built-in analytics. Additionally, Sentinel provides robust incident management capabilities that consolidate alerts into incidents, streamlining the investigation and response process.
In this lab, you will learn to create a custom scheduled query rule to detect suspicious inbox rule creation activities, leveraging the OfficeActivity_CL custom log table. You will then explore the incident generated by the rule, reviewing mapped entities and related data to understand how Sentinel aids in threat detection and investigation.
Objectives
Upon completion of this lab, you will be able to:
- Define custom analytics rules in Microsoft Sentinel using KQL (Kusto Query Language).
- Create dynamic alert titles to enhance incident context.
- Map entities to enrich alert information and group related alerts into incidents.
- Investigate generated incidents and understand the contextual data provided by Sentinel.
Who is this Lab For?
This lab is designed for:
- Security Analysts who want to learn how to customize detection rules for tailored threat detection.
- SOC Teams interested in enhancing incident triage and investigation processes.
- Developers and IT Professionals looking to integrate advanced security monitoring into their environments.
Verified against your live environment
An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed, not multiple choice, real-world proficiency.
More labs like this
Investigating and Handling Incidents in Microsoft Sentinel
Learn to handle incidents in Microsoft Sentinel by investigating suspicious activity, analyzing IP insights, and automating responses with custom rules.
Transform Logs at Ingestion with DCRs Custom Tables and ASIM in Microsoft Sentinel
Build a DCR with a custom table, write a transformKql to parse and drop noisy fields, and map output to an ASIM parser.
Detect Multi-Stage Attacks with Microsoft Sentinel Fusion Rules
Configure Fusion source signals, create entity-mapped analytics rules, and trace multi-stage attack chains using the investigation graph in Microsoft Sentinel.
Environment
Every lab includes
- Real environment, pre-credentialed
- Automated checks on every step
- Isolated sandbox, auto cleanup
- AI-recommended next steps
Lab curriculum
- 01
Logging into Azure Account using Azure Portal
- 02
Creating a Custom Analytics Rule
1 automated check
- 03
Investigating Incidents Triggered by the Custom Rule
Not the lab you were looking for?
Browse 200+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.