AI5 PROFESSIONAL CERTIFICATE · BY TGC INDIA · UPDATED AUGUST 2026
Microsoft Security Copilot for SOC Analysts
Investigate alerts, summarise incidents and document response work across Microsoft security tools with analyst review.
NEXT START OPTIONS
Choose a live batch.
COURSE OVERVIEW
What this course
is built to do.
Use Microsoft Security Copilot with Sentinel and Defender XDR to investigate alerts, build evidence-backed incident summaries and improve analyst response without surrendering judgement to the model.
Each module combines a live trainer demonstration, guided lab, assignment and review before the next stage.
CONNECTED CAREER DIRECTIONS
IS THIS COURSE RIGHT FOR YOU?
Choose it for the right reason.
You investigate alerts in a security operations setting
Your organisation uses Microsoft Sentinel or Defender XDR
You need analyst-led AI methods with evidence and audit trails
YOUR LEARNING ARC
From guided foundation to finished work.
Orient
Understand Security Copilot, plugins, data boundaries and prompts.
Investigate
Triage alerts and connect evidence across Microsoft tools.
Respond
Build timelines, KQL support and incident reports.
Validate
Test difficult cases, measure quality and present a SOC capstone.
INDUSTRY TASKS
Practise the work, not only the tool.
- Triage a simulated identity incident
- Produce a cited incident timeline across Sentinel and Defender
- Build a reusable analyst promptbook with verification steps
LED
YOUR TRAINING TEAM
Learn from experienced working professionals.
Live demonstrations, guided practice and direct project feedback are part of the course. Trainers update examples and tool coverage as professional practice changes.
WHAT YOU WILL BE ABLE TO DO
Course outcomes
Investigate alerts with evidence
A triage record linking each conclusion to verified Microsoft security data.
Create and validate KQL hunts
A query pack with explanations, tests and false-positive notes.
Document incident response
A timeline and audience-specific reports based on checked evidence.
Standardise analyst use
A tested promptbook with permissions, quality measures and review rules.
TAKE THE NEXT STEP
Need fees, syllabus or the right batch?
An AI5 Academy advisor can help you compare mode, schedule and starting level.
DETAILED COURSE FLOW
5 learning modules
Use Microsoft Security Copilot as an analyst assistant across Sentinel and Defender XDR while keeping evidence, response decisions and accountability with the SOC team.
Security Copilot foundations and data boundaries
Understand the product architecture, connected security sources and safe prompting practices.
- Security Copilot experiences and plugin model
- Sentinel, Defender XDR and identity context
- Promptbooks, sessions and evidence references
- Permissions, sensitive data and audit records
Map a sample Microsoft security environment and define which analyst roles may access each data source.
Security Copilot access and use map
Alert triage and guided investigation
Move from an alert to a defensible investigation plan without accepting model conclusions blindly.
- Alert context, entities and incident queues
- Hypothesis-led prompts and follow-up questions
- Identity, endpoint, email and cloud evidence
- False positives, missing evidence and escalation
Investigate a simulated alert, verify every cited event and record alternative explanations.
Alert triage worksheet and evidence log
KQL, hunting and evidence correlation
Use AI to support query creation while manually validating syntax, scope and results.
- KQL structure, tables and time windows
- Query generation and explanation
- Entity correlation and attack-path analysis
- Performance, false matches and reusable hunts
Create and test KQL queries for a simulated identity or endpoint incident and explain each result.
Validated KQL hunting pack
Incident response and reporting
Turn verified evidence into a timeline, response plan and communication suitable for different stakeholders.
- Incident scope, severity and ATT&CK mapping
- Containment and remediation decision support
- Executive, technical and regulatory summaries
- Post-incident review and detection improvement
Prepare a full incident timeline and separate analyst, management and handover reports.
Incident response documentation pack
SOC promptbook and evaluation capstone
Create repeatable Security Copilot practice that is tested for accuracy, access and analyst usefulness.
- Promptbook structure and team standards
- Normal, ambiguous and adversarial test cases
- Accuracy, time saved and analyst override rates
- Change control, review dates and team adoption
Build and evaluate a SOC promptbook on a simulated multi-stage incident and present its operating limits.
Security Copilot SOC capstone
HOW THE TRAINING WORKS
Learn it. Apply it. Get it reviewed. Improve it.
Every important skill moves through explanation, demonstration, guided use and independent application. Trainer feedback is used to revise the work before it becomes part of the final portfolio.
Concept briefing
The trainer explains the principle, use case, limitations and the quality standard expected.
Live demonstration
A complete task is demonstrated while the trainer explains decisions, checks and common mistakes.
Guided lab
Learners repeat the method with support, ask questions and correct problems during the session.
Applied assignment
The same method is used on a different brief so the learner must make independent decisions.
Review and revision
Work is checked against a rubric, revised after feedback and prepared for project presentation.
PORTFOLIO WORK
Projects you can show
Guided practice brief
Plan, produce, test and present a finished piece with trainer feedback.
Individual application
Plan, produce, test and present a finished piece with trainer feedback.
Workflow build
Plan, produce, test and present a finished piece with trainer feedback.
Industry-style assignment
Plan, produce, test and present a finished piece with trainer feedback.
Quality review
Plan, produce, test and present a finished piece with trainer feedback.
Final capstone
Plan, produce, test and present a finished piece with trainer feedback.
TAKE THE NEXT STEP
Need fees, syllabus or the right batch?
An AI5 Academy advisor can help you compare mode, schedule and starting level.
TOOLS COVERED
COMMON QUESTIONS
Before you apply
Is Sentinel experience required?
Basic SOC and alert knowledge is required; guided Sentinel and Defender exercises are included.
+Does Copilot make incident decisions?
No. Analysts verify evidence, choose actions and approve every response step.
+Is KQL covered?
Yes. Learners create, explain and test KQL queries with AI assistance and manual validation.
+Do I need coding experience?
No, unless the course level says otherwise. Your advisor will check the right starting level.
+Are classes live or recorded?
Classes are trainer-led in the classroom or live online. Recordings may support revision but do not replace class.
+Will I receive a certificate?
Yes. Course completion requires attendance, assignments and the final project.
+Can working professionals join?
Yes. Weekday, weekend and selected fast-track schedules are available.
+NEXT BATCH
Choose your course.
Choose your schedule.
Online or offline. Weekdays or weekends. Regular or fast track. Speak with an AI5 Academy advisor about the right starting level.
Toll free1800 1020 418Fees & syllabus