Many organizations with investments in Azure are naturally looking to integrate Azure Sentinel and customize it for their unique needs. But those with complex, hybrid environments, or with large volumes of data and legacy technology stacks find it difficult to focus more of their time on enabling Azure Sentinel's advanced capabilities for more proactive, measurable threat management. In this session, Saggie Haim will be joined by Microsoft's Azure Sentinel expert, Javier Soriano to show you what you can be doing now to further your cloud-native threat detection and response maturity. In this workshop, you'll learn how to: - Adopt an agile process for threat hunting with KQL query tricks - Create KPI-driven reports you never thought you could have - Optimize log ingestion and retention process and costs - Enrich and correlating events with Watchlists - Enable faster deployments and configurations with a CI/CD model