Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security analyst is investigating a critical incident in Microsoft Sentinel involving a compromised user account. The analyst needs to quickly pivot from the incident details to view all related alerts, entities, and events in a graphical format to understand the attack chain and relationships. Which Microsoft Sentinel feature provides this visual representation?

  1. AInvestigation graph
  2. BAnalytics rules
  3. CEntity behavior analytics
  4. DHunting workbook
Show answer & explanation

Correct answer: A. Investigation graph

The investigation graph in Microsoft Sentinel provides a visual map of all connected entities, alerts, and events related to an incident, allowing analysts to explore relationships and understand the full scope of an attack.

Why the other options are wrong

  • B. Analytics rules are used to detect threats and generate incidents, not to visualize incident relationships.
  • C. Entity behavior analytics (UEBA) helps detect anomalous behavior, but it's not the primary feature for visualizing the connections within a specific incident post-detection.
  • D. Hunting workbooks are for proactive threat hunting and visualization of query results, not for interactive incident investigation graphs.

Microsoft Sentinel Investigation Graph

The Microsoft Sentinel Investigation Graph provides a visual, interactive representation of an incident, showing all related alerts, entities (users, hosts, IP addresses), and their connections, helping analysts understand the attack chain.

  • Visualizes incident relationships.
  • Shows alerts, entities, and events.
  • Helps understand attack chain and scope.

Memory trick: To 'Graph' out the incident's connections, use the 'Investigation Graph'.

More Mitigate threats using Microsoft Sentinel questions