Exercise - Perform a simulated attack to validate the Analytic and Automation rules

Completed

Now it's time to validate that our Microsoft Sentinel deployment is receiving security events and creating incidents from virtual machines that run Windows.

In this exercise, you learn how to perform a simulated attack to validate that the Analytic and Automation rules create an incident and assign it to the Operator1. You perform a Privilege Escalation attack on vm1.

Note

To complete this exercise, you need to complete the previous three exercises and have an Azure subscription.

Launch the exercise and follow the instructions.

Button to launch exercise.