Creating Custom Analytics Rules and Investigating Incidents in Microsoft Sentinel
Learn how to create custom analytics rules in Microsoft Sentinel, map entities to enrich alerts, and investigate incidents generated from suspicious activities.

Lab overview
Custom analytics rules in Microsoft Sentinel enable you to define specific criteria for detecting malicious activities based on your unique security needs. These rules allow you to identify and mitigate advanced threats that may not be covered by built-in analytics. Additionally, Sentinel provides robust incident management capabilities that consolidate alerts into incidents, streamlining the investigation and response process.
In this lab, you will learn to create a custom scheduled query rule to detect suspicious inbox rule creation activities, leveraging the OfficeActivity_CL custom log table. You will then explore the incident generated by the rule, reviewing mapped entities and related data to understand how Sentinel aids in threat detection and investigation.
Objectives
Upon completion of this lab, you will be able to:
- Define custom analytics rules in Microsoft Sentinel using KQL (Kusto Query Language).
- Create dynamic alert titles to enhance incident context.
- Map entities to enrich alert information and group related alerts into incidents.
- Investigate generated incidents and understand the contextual data provided by Sentinel.
Who is this Lab For?
This lab is designed for:
- Security Analysts who want to learn how to customize detection rules for tailored threat detection.
- SOC Teams interested in enhancing incident triage and investigation processes.
- Developers and IT Professionals looking to integrate advanced security monitoring into their environments.
Verified against your live environment
An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed — not multiple choice, real-world proficiency.
More labs like this
Investigating and Handling Incidents in Microsoft Sentinel
Learn to handle incidents in Microsoft Sentinel by investigating suspicious activity, analyzing IP insights, and automating responses with custom rules.
Deploying Your First Microsoft Sentinel Workspace on Azure
Learn to set up Microsoft Sentinel workspace, connect it to a Log Analytics workspace, and prepare for advanced security monitoring and threat detection.
Implement Network Security Groups (NSGs) and Application Security Groups (ASGs) in Azure
Secure Azure VMs using Network Security Groups and Application Security Groups. Create rules, control traffic flow, and implement least privilege access.
Related reading
Environment
Every lab includes
- Real environment, pre-credentialed
- Automated checks on every step
- Isolated sandbox, auto cleanup
- AI-recommended next steps
Lab curriculum
- 01
Logging into Azure Account using Azure Portal
- 02
Creating a Custom Analytics Rule
1 automated check
- 03
Investigating Incidents Triggered by the Custom Rule
Skills validated
Not the lab you were looking for?
Browse 150+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.