Note: Read the Hackathon rules first, if you haven't already.

Check out the documentation, code samples, videos, webinars, tutorials, and guides to help you get started, building your submissions! Remember to build end-to-end solutions that includes multiple Microsoft Sentinel content types or Microsoft Sentinel content (workbooks, analytics, and more) or extend Microsoft Sentinel capabilities via APIs and feel free to mix and match different types of content and data sources to deliver richer end-to-end experiences. Be creative!

Questions? Post on the Hackathon Discussion Forums or reach out to the Microsoft Sentinel Hackathon team

----------------------------------------------------------------------------------------------------

Step 1. Create and Configure Microsoft Sentinel

First, create and configure an Azure Sentinel workspace, if you have not done so already.  

  1. Go to https://aka.ms/AzureSentinel - Get set up with your Azure free account. Reach out to Microsoft Sentinel Hackathon team for additional credits.
  2. Go to the Microsoft Sentinel dashboard in the Azure portal.
  3. Explore the documentation and quickstarts (Step 2.a. below helps with not only ingesting data sets but also deploying Microsoft Sentinel and configuring onboarding options in the deployment template. Read up on this option before going ahead with setting up Microsoft Sentinel from scratch.)
  4. Next, it’s all about onboarding to Microsoft Sentinel and the onboarding quickstart is your key here.  

Step 2. Setup Data

Then, start setting up data so that you can try out different use cases in Microsoft Sentinel and get ideas for your submission. There are multiple options here. These are all optional and you can choose from one or many of these depending on the variety of data you wish to explore. 

  1. Azure-Sentinel2Go expedites the deployment of an Microsoft Sentinel lab along with other Azure resources and a data ingestion pipeline to consume pre-recorded datasets for Microsoft products for research purposes. This ingests pre-recorded datasets.
  2. Ingest sample data from some non-Microsoft security products without having access to those products. This is using the Microsoft Sentinel custom log ingest tool that helps ingest these in Azure Log Analytics workspace as custom logs. You can also use the tool to bring in your own data in Microsoft Sentinel as well as custom logs. Go through the steps in the ingest tool readme for this.  
  3.  Connect with different types of Microsoft as well as non-Microsoft data by following steps in the documentation. To enable this for Microsoft data sources, you can leverage one or more the following free trials to get started:
    1. Get access to Azure Services with a free 12-month subscription and a $200 credit (Step #1) includes free trial of Azure Security Center (Standard)
    2. Get access to Enterprise Mobility and Security E5 90-day free trial for access to Cloud Application Security (CAS), Azure Active Directory Information Protection (AADIP), Azure Information Protection (AIP), Intune and other products depending on your scenario
    3. Get access to Windows Defender Advanced Threat Protection 60-day free trial, depending on your scenario
    4. Get the Azure Active Directory Premium subscription for up-to 100 licenses for a month
  4. Leverage existing Microsoft Sentinel data connectors and/or data connectors in existing Microsoft Sentinel solutions

     

Documentation

Training Videos

  • Microsoft Sentinel level 400 training – Summarizes videos and webinars that can get you ramped up on Microsoft Sentinel and covers in depths on different Microsoft Sentinel use cases. These cover a range of training videos starting with content development on Microsoft Sentinel all the way to extending and integrating with Microsoft Sentinel.

Get Inspiration

You can discover more examples by reviewing content and solutions in the Microsoft Sentinel GitHub repository and blogs.

Community

Got Questions?

  • Post a question in the Discussions forum if you need help!
  • We’ll organize a couple of online Office hours to help with answering any questions or to connect on the Hackathon in general. Tune in for further updates on this.

Find a team

No one is an expert at everything, so you may want to consider looking for a teammate to help you iron out the kinks and fill in the blanks of your submission. We’ve got a few tips for finding a teammate in case you need them.

Use the competition Participants page to connect

In our experience, it’s more fun to code with a friend. On the Participants tab, you can:

  • Look for teammates by introducing yourself to the community. Mention any ideas you have and what kind of teammates you’re looking for.
  • Sort participants by the number of projects and followers they have or by registration date.
  • Search participants by name, skills, and portfolio info.
  • Reach out to potential teammates and get to know each other.
  • Collaborate on something amazing!