|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/cyber-threat-hunting
课程评论:没有评论
课程名称:网络威胁猎捕 课程概述:本课程旨在教授可重复、可记录的网络威胁猎捕方法与工具,以提高你的威胁猎捕效果。学习路径通过六个课程,帮助你构建核心猎捕技能,包括情报收集、调查技术和修复方法。完成课程后,你将具备在组织中开展网络威胁猎捕活动的知识和技能,从而实现对可能威胁的主动防御。 课程大纲: 1. **网络威胁猎捕导论**:介绍网络威胁猎捕的定义、所需技能、假设建模、实施的益处等。 2. **威胁猎捕工件与类型**:探讨有效威胁猎捕程序所需的要素,学习工件、妥协指标、战术、技术和程序、痛苦金字塔等知识。 3. **威胁猎捕技术与生成性AI**:探讨异常活动及调查的概念,帮助威胁猎捕者识别异常是否构成威胁,利用生成性AI快速发现恶意活动。 4. **威胁猎捕方法论**:研究结构化和非结构化猎捕的差异,以及基于实体的猎捕方法。 5. **威胁猎捕数据与技术**:介绍不同的数据源,包括SIEM、EDR和XDR日志、威胁情报平台等,指导如何在这些来源中进行猎捕。 6. **网络威胁猎捕过程**:学习如何构建猎捕,考虑所有因素,包括实验的教训和正确的执行方式。 7. **网络威胁猎捕场景**:使用真实案例展示不同的威胁猎捕场景,从假设形成到教训总结。 8. **网络基础威胁猎捕**:深度探讨DNS、DDoS和不规则流量等网络基础威胁,包括实验和演示,掌握寻找隐蔽恶意软件的方法。 9. **主机基础威胁猎捕**: walkthrough 各种主机基础威胁及指标,进行记忆取证、PowerShell及Windows事件日志解析等实验和演示。 该课程为希望提升网络安全技能的学习者提供了全面的培训,帮助他们有效地应对网络威胁。
Name:Cyber threat hunting introduction
Description:In this introductory module with Keatron Evans, you'll explore cyber threat hunting: defining it, skills required, hunt modeling with hypotheses, implementation benefits and more.
Name:Threat hunting artifacts and types
Description:In this module, you'll explore what's needed for a really effective threat-hunting program. You'll also learn about artifacts, indicators of compromise, tactics, techniques and procedures, the Pyramid of Pain and many more insights from Keatron.
Name:Threat hunting techniques and generative AI
Description:Explore the concepts of anomalous activity and investigation. The purpose of this module is to help the threat hunter identify whether an anomalous activity is a threat. Explore how to investigate, walking through the information and identifying any issues right away. In this course, Keatron uses generative AI to quickly find malicious activity.
Name:Threat hunting methodologies
Description:In this module, you'll explore the differences between structured and unstructured hunts with Keatron. You will also get into entity-driven hunting.
Name:Threat hunting data and technologies
Description:In this course, Keatron will take you through different data sources that you may hunt through. These include SIEMs, EDR and XDR logs, threat intelligence platforms and several other data sources.
Name:Cyber threat hunting process
Description:In this course, you will learn how to build a hunt. Keatron gets into the details of all the things the learner must consider when building out a hunt and scoping. We also discuss lessons learned and proper execution.
Name:Cyber threat hunting scenarios
Description:In this course, you'll see how different threat hunting scenarios play out. We will use real-world examples to illustrate how we form a hypothesis all the way through lessons learned.
Name:Hunting for network-based threats
Description:In this course, we will go on a deep dive with Keatron concerning network-based threats, including DNS, DDoS and irregular traffic, plus more. This course will include some labs and demonstrations. Locate even the hardest-to-find malware with these techniques.
Name:Hunting for host-based threats
Description:In this course, Keatron will walk through various host-based threats and indicators. There will be labs and demonstrations that include memory forensics, PowerShell and Windows event log parsing.
Learn repeatable, documentable cyber threat hunting methodologies and types of tools that will make your threat hunting more effective. This learning path progresses through six courses, in which you will build core hunting skills such as intelligence gathering, investigation techniques and remediation methods. Upon completion, you'll have the knowledge and skills to carry out cyber threat hunting activities with an organization that will ultimately deliver proactive defenses against possible de