AI5 PROFESSIONAL CERTIFICATE · BY TGC INDIA · UPDATED AUGUST 2026

Microsoft Security Copilot for SOC Analysts

Investigate alerts, summarise incidents and document response work across Microsoft security tools with analyst review.

Get syllabus on WhatsApp →
Online + OfflineWeekdays + WeekendsRegular + Fast Track
The decision compass121

Business questions meet evidence, options and action.

ASKWEIGHDECIDE
Duration8 weeks
Learning modeClassroom + Live Online
ScheduleWeekdays + Weekends
TrackRegular + Fast Track*
Entry levelIntermediate
Projects6 substantial practical builds
22+years in training
20,000+learners across TGC
5classroom locations
Live onlinejoin from anywhere

NEXT START OPTIONS

Choose a live batch.

Full batch calendar →

COURSE OVERVIEW

What this course
is built to do.

Use Microsoft Security Copilot with Sentinel and Defender XDR to investigate alerts, build evidence-backed incident summaries and improve analyst response without surrendering judgement to the model.

Each module combines a live trainer demonstration, guided lab, assignment and review before the next stage.

WHO SHOULD JOINSOC analystsCybersecurity professionalsMicrosoft security administratorsIncident-response team members
PREREQUISITE

Basic security operations, alerts and incident-response knowledge. Familiarity with Microsoft Sentinel or Defender is helpful.

CONNECTED CAREER DIRECTIONS

Security Copilot AnalystSOC AnalystIncident Response AssociateMicrosoft Security Operations Specialist

IS THIS COURSE RIGHT FOR YOU?

Choose it for the right reason.

01

You investigate alerts in a security operations setting

02

Your organisation uses Microsoft Sentinel or Defender XDR

03

You need analyst-led AI methods with evidence and audit trails

YOUR LEARNING ARC

From guided foundation to finished work.

01

Orient

Understand Security Copilot, plugins, data boundaries and prompts.

02

Investigate

Triage alerts and connect evidence across Microsoft tools.

03

Respond

Build timelines, KQL support and incident reports.

04

Validate

Test difficult cases, measure quality and present a SOC capstone.

INDUSTRY TASKS

Practise the work, not only the tool.

  1. Triage a simulated identity incident
  2. Produce a cited incident timeline across Sentinel and Defender
  3. Build a reusable analyst promptbook with verification steps
PRO
LED

YOUR TRAINING TEAM

Learn from experienced working professionals.

Live demonstrations, guided practice and direct project feedback are part of the course. Trainers update examples and tool coverage as professional practice changes.

Meet our trainers ↗

WHAT YOU WILL BE ABLE TO DO

Course outcomes

01

Investigate alerts with evidence

A triage record linking each conclusion to verified Microsoft security data.

02

Create and validate KQL hunts

A query pack with explanations, tests and false-positive notes.

03

Document incident response

A timeline and audience-specific reports based on checked evidence.

04

Standardise analyst use

A tested promptbook with permissions, quality measures and review rules.

TAKE THE NEXT STEP

Need fees, syllabus or the right batch?

An AI5 Academy advisor can help you compare mode, schedule and starting level.

DETAILED COURSE FLOW

5 learning modules

Use Microsoft Security Copilot as an analyst assistant across Sentinel and Defender XDR while keeping evidence, response decisions and accountability with the SOC team.

MODULE 01

Security Copilot foundations and data boundaries

Understand the product architecture, connected security sources and safe prompting practices.

CORE TOPICS
  • Security Copilot experiences and plugin model
  • Sentinel, Defender XDR and identity context
  • Promptbooks, sessions and evidence references
  • Permissions, sensitive data and audit records
GUIDED PRACTICE

Map a sample Microsoft security environment and define which analyst roles may access each data source.

MODULE DELIVERABLE

Security Copilot access and use map

MODULE 02

Alert triage and guided investigation

Move from an alert to a defensible investigation plan without accepting model conclusions blindly.

CORE TOPICS
  • Alert context, entities and incident queues
  • Hypothesis-led prompts and follow-up questions
  • Identity, endpoint, email and cloud evidence
  • False positives, missing evidence and escalation
GUIDED PRACTICE

Investigate a simulated alert, verify every cited event and record alternative explanations.

MODULE DELIVERABLE

Alert triage worksheet and evidence log

MODULE 03

KQL, hunting and evidence correlation

Use AI to support query creation while manually validating syntax, scope and results.

CORE TOPICS
  • KQL structure, tables and time windows
  • Query generation and explanation
  • Entity correlation and attack-path analysis
  • Performance, false matches and reusable hunts
GUIDED PRACTICE

Create and test KQL queries for a simulated identity or endpoint incident and explain each result.

MODULE DELIVERABLE

Validated KQL hunting pack

MODULE 04

Incident response and reporting

Turn verified evidence into a timeline, response plan and communication suitable for different stakeholders.

CORE TOPICS
  • Incident scope, severity and ATT&CK mapping
  • Containment and remediation decision support
  • Executive, technical and regulatory summaries
  • Post-incident review and detection improvement
GUIDED PRACTICE

Prepare a full incident timeline and separate analyst, management and handover reports.

MODULE DELIVERABLE

Incident response documentation pack

MODULE 05

SOC promptbook and evaluation capstone

Create repeatable Security Copilot practice that is tested for accuracy, access and analyst usefulness.

CORE TOPICS
  • Promptbook structure and team standards
  • Normal, ambiguous and adversarial test cases
  • Accuracy, time saved and analyst override rates
  • Change control, review dates and team adoption
GUIDED PRACTICE

Build and evaluate a SOC promptbook on a simulated multi-stage incident and present its operating limits.

MODULE DELIVERABLE

Security Copilot SOC capstone

HOW THE TRAINING WORKS

Learn it. Apply it. Get it reviewed. Improve it.

Every important skill moves through explanation, demonstration, guided use and independent application. Trainer feedback is used to revise the work before it becomes part of the final portfolio.

01

Concept briefing

The trainer explains the principle, use case, limitations and the quality standard expected.

02

Live demonstration

A complete task is demonstrated while the trainer explains decisions, checks and common mistakes.

03

Guided lab

Learners repeat the method with support, ask questions and correct problems during the session.

04

Applied assignment

The same method is used on a different brief so the learner must make independent decisions.

05

Review and revision

Work is checked against a rubric, revised after feedback and prepared for project presentation.

PROGRESS IS CHECKED THROUGHClass exercisesModule deliverablesProject reviewsFinal capstone presentation

PORTFOLIO WORK

Projects you can show

01

Guided practice brief

Plan, produce, test and present a finished piece with trainer feedback.

02

Individual application

Plan, produce, test and present a finished piece with trainer feedback.

03

Workflow build

Plan, produce, test and present a finished piece with trainer feedback.

04

Industry-style assignment

Plan, produce, test and present a finished piece with trainer feedback.

05

Quality review

Plan, produce, test and present a finished piece with trainer feedback.

06

Final capstone

Plan, produce, test and present a finished piece with trainer feedback.

TAKE THE NEXT STEP

Need fees, syllabus or the right batch?

An AI5 Academy advisor can help you compare mode, schedule and starting level.

TOOLS COVERED

Security CopilotMicrosoft SentinelDefender XDRKQL
Tool coverage may be updated when the industry changes. Core methods remain part of the course.

COMMON QUESTIONS

Before you apply

Is Sentinel experience required?

Basic SOC and alert knowledge is required; guided Sentinel and Defender exercises are included.

Does Copilot make incident decisions?

No. Analysts verify evidence, choose actions and approve every response step.

Is KQL covered?

Yes. Learners create, explain and test KQL queries with AI assistance and manual validation.

Do I need coding experience?

No, unless the course level says otherwise. Your advisor will check the right starting level.

Are classes live or recorded?

Classes are trainer-led in the classroom or live online. Recordings may support revision but do not replace class.

Will I receive a certificate?

Yes. Course completion requires attendance, assignments and the final project.

Can working professionals join?

Yes. Weekday, weekend and selected fast-track schedules are available.

KNOW THIS SUBJECT WELL?Teach it at AI5 →

NEXT BATCH

Choose your course.
Choose your schedule.

Online or offline. Weekdays or weekends. Regular or fast track. Speak with an AI5 Academy advisor about the right starting level.

Call now1800 1020 418WAGet details
CallWhatsAppFees & syllabus