|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/in-the-trenches-security-operations-center
课程评论:没有评论
课程名称:《前线作战:安全运营中心》 课程概述:随着网络攻击、数据泄露和其他网络事件的不断增加,攻击的复杂性和技术水平也在不断提升。各个组织亟需规划、准备并防御潜在的网络事件。安全运营中心(SOC)作为组织抵御网络事件的最前线,SOC分析师通过监控和响应网络及主机异常,深入分析可疑事件,并在必要时协助进行取证调查,发挥重要作用。本课程旨在为计划参加EC-Council CSA课程的学员提供基础知识。 课程大纲: 1. **实验室设置**:了解整个课程的目标、目的和概要,并学习如何搭建实验室环境。 2. **企业安全运营**:开始学习安全运营中心的概念、功能及其工作内容。 3. **黑客战术、技术与程序**:深入学习黑客常用的战术和技术,加深对安全运营中心的理解。 4. **现代企业的防御工具**:了解组织用于保护敏感数据的各种防护措施。 5. **事件监控与威胁捕捉**:学习当前组织采用的先进安全措施。 6. **漏洞管理**:认识到漏洞如何被利用进入组织的安全系统,学习漏洞管理的重要性。 7. **事件响应**:了解什么是事件,以及如何有效应对各种突发情况。 8. **课程总结与最终评论**:由讲师给出课程的总体总结与意见。 本课程为希望在网络安全领域发展的人士提供了一个全面的入门指导,使学员能够理解SOC在现代企业中的关键角色及其日常操作。
Name:Lab Setup
Description:Here, you will understand the goals, objectives, and summary of the entire course. You will get to know the author, his areas of expertise and his accomplishments. In this section, you will learn how to setup the lab environment to get started.
Name:Enterprise Security Operations
Description:In this section, you will start learning about Security Operations Center. You will also learn what they are, how the functions, and what they do.
Name:Hacker Tactics, Techniques, and Procedures
Description:In this section, you will start learning about Security Operations Center. You will also learn what they are, how the functions, and what they do.
Name:Defensive Tools for the Modern Enterprise
Description:In this section, you will learn various practices that organizations use to protect their sensitive data.
Name:Event Monitoring and Threat Hunting
Description:This section will teach you some other advanced practices being followed at various organizations as their security measures.
Name:Vulnerability Management
Description:Vulnerability can be easily used to enter your organizations security systems and steal or misuse your data. We will learn about vulnerabilties in this lesson.
Name:Incident Response
Description:Incident means any situation that appears and needs attention. This section will teach you about incidents and how to deal with them
Name:Course Conclusion and Final Comments
Description:Final thoughts by the instructor
Cyber-attacks, breaches, and incidents continue to grow. The sophistication and complexity of these attacks continue to evolve. More than ever organizations need to plan, prepare, and defend against a potential cyber incident. Security Operation Centers (SOCs) act as an organization's front-line defense against cyber incidents. SOC analyst accomplishes this by monitoring and responding to network and host anomalies, performing an in-depth analysis of suspicious events, and when necessary, aiding in forensic investigations. This course is designed to be a primer for anyone planning on taking the EC-Council CSA course. We will discuss the structure, organization, and general daily activities of SOC analysts. We will also look at several defensive tools including SEIMs, IDS, and IPS. We will talk about event monitoring and vulnerability management. Finally, we will talk about what to expect when an incident happens.