|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/a-guide-to-security-information-and-event-management-siem/
课程评论:没有评论
课程名称:安全信息与事件管理指南 - SIEM 课程概述:本课程将带您深入了解安全信息与事件管理(SIEM)的各个方面。您将学习SIEM的基本概念、主要目标、深度防御、企业环境、日志管理、SIEM的必要性、使用案例、SIEM元素、SIEM的“三大要素”、SIEM流程、SIEM的典型功能、事件生命周期、安全运营中心(SOC)控制与管理、SIEM架构、SIEM的八大关键特性及部署选项。您将初步掌握Splunk的用户界面,能够使用其基本变换命令,创建报告和仪表板,了解如何保存和分享报告,以及创建警报。 课程内容包括: 1. 实时洞察安全信息和事件管理及安全事件管理。 2. 识别威胁和潜在 breaches,收集安全和合规的审计日志,进行调查并提供证据。 3. 学习深度防御(DiD)方法,该方法通过多层防御机制保护重要数据与信息。 4. 理解攻击者如何入侵以及企业环境的设置。 5. 学习SIEM和日志管理对企业的意义,以及如何有效使用以减少风险。 6. 了解由于数据泄露增多与合规要求,SIEM的必要性。 7. 正确构建SIEM使用案例的方法,并有效组织和优先级排序。 8. 深入学习SIEM元素、三大要素、流程、功能、事件生命周期、SOC控制和管理、SIEM架构、仪表板及使用案例。 9. 复习SIEM功能,学习SIEM的部署选项,包括自托管、自管理、混合模型和联合管理,理解SIEM的商业益处。 10. SIEM基础知识测验。 11. 集中在Splunk和FortiSIEM的安全运营中心(SOC)。 12. 网络概念复习,包括OSI与TCP/IP协议套件。 13. 了解网络攻击、伦理黑客、DoS、DDoS、SYN洪水和Metasploit。 14. 学习Maltego、网络杀伤链方法论、信息安全向量和勒索软件。 15. 掌握Splunk的用户界面,独立导航其功能,并学习如何将数据导入Splunk,使用搜索及搜索语言。 16-21. 学习Splunk的基本变换命令,创建报告、仪表板、保存和分享报告,并创建警报。 22. 通过案例研究深入了解Fortinet的FortiSIEM。 23-27. 学习病毒类型、安全设备、事件响应、IMAP4邮件基础及漏洞管理。 28. 网络安全角色和SOC角色的面试准备!获取关于如何为SOC角色面试准备的见解,了解网络安全角色的样本职位描述及面试技巧。 本课程适合希望入门或提升SIEM技能的专业人士。讲师提供了丰富的实例和深刻的见解,评价良好,深受学员喜爱,尤其适合希望成为SOC分析师的人士。
In this course you will go through an Introduction to SIEM, its Key objectives, Defence in depth, Corporate environment, Log management, Why siem is necessary, Use cases, Elements of siem, Big 3 for siem, SIEM process flow, Typical features of siem, Event life cycle, Soc controls and Management, SIEM Architecture, 8 critical features of SIEM and SIEM Deployment options. You will also get an introduction to Splunk's user interface and will be conversant with the UI. You can start using the Splunk's basic transforming commands, can create reports and dashboards, you will know how to save and share reports and also can create alerts.Section 1You will gain real time insights on Security information and event management and Security event managerSection 2You will identify threats and possible breaches and collect audit logs for security and compliance. You will be able to conduct investigations and provide evidence.Section 3You will learn that Defense in Depth (DiD) is an approach to cybersecurity in which a series of defensive mechanisms are layered in order to protect valuable data and information.Section 4You can understand how an attacker can come in and tries to understand how a corporate environment is setup of a target.Section 5You will learn what SIEM and Log Management mean for businesses & how to use them more effectively to mitigate risk for your company.Section 6You will learn that SIEM is necessary because of the rise in data breaches and to meet stringent compliance requirementsSection 7Learn the right approach to building SIEM use cases, how to organize and prioritize use cases effectively.Section 8You will learn the SIEM elements, Big 3, Process flow, Features, Event life cycle, SOC controls and mgmt, SIEM architecture, Dashboards and Use casesSection 9You will revisit features of SIEM and learn SIEM deployment options like self-hosted, self-managed to Hybrid-model, Jointly-managed. You will understand the business benefits of SIEM. Section 10SIEM Essentials QuizSection 11Security Operations Center - SOC with Splunk & FortiSIEMSection 12Network Concepts Refresher, OSI, TCPIP Protocol SuiteSection 13Cyber Security Attacks, Ethical Hacking, DoS, DDoS, SYN Flooding, MetasploitSection 14Maltego, Cyber Killchain methodology, Information security vectors, Ransomware Section 15You will understand Splunk's user interface -UI. You will be able to navigate UI features on your own: Navigating splunk web: splunk home, splunk bar, splunk web,getting date into splunk, how to specify data inputs, where splunk stores data, getting tutorial data into splunk, using splunk search, search actions and modes, search results tools, events, what are fields, extracted fields, find and select fields,run more targeted searches, use the search language, learn with search assistant Section 16-21You can start using the Splunk's basic transforming commands, can create reports and dashboards, you will know how to save and share reports and also can create alerts after completing these sections.Section 22You will go through a live case study on how Fortinet's FortiSIEM works right from the foundation.Section 23-27Learn the types of viruses, security devices, incidence response, IMAP4 based Email & vulnerability managementSection 28Interview Preparation for Cyber Security Roles & SOC Roles!Gain Insights from this Live Case study of how to prepare for an Interview for a SOC Role. You will find the Subject matter expert guiding the Interviewee to crack an Interview.Understanding the Cyber Security Role using a sample Job DescriptionRisk Based Approach InsightsInterview Questions, NIST 863-53 & NIST 800-171A Guide to Malware Incident Prevention and HandlingPractical Interview Technical Hints & TipsTestimonials:Good content delivered by very knowledgeable individual SifisoExcellent course for the professionals who want to enter/know SIEM or to improve their existing skill set.. Lecturer is a real time professional who has in-depth knowledge of what he is teaching and making sure that it reaches to listeners.Also for the guys who want to learn Splunk RamThis course lays the foundation for SIEM, the instructor is a working professional and gave real time examples which made it easier to understand. Expecting more sections to be added, Highly recommend to Beginners! Souha DjimIt has in-depth knowledge of Splunk and is very insightful Megha SahaiOne of the Best Mehedi HasanYes.I got a very good understanding of SIEM and way to go further. Thanks Udemy for this wonderful course. WIll subscribe to new courses in future as and when my need increases. Chandrasekaran LakshmananIt is a very good one because I am in the cyber Security field. I would recommend it to my friends. Jeffery OsuyaThis is very very important Tutorial series for those who are seeking to increase their skillset and knowledge. This very valuable for me and my carrier. Thank you. Yes, Its a perfect match according to my career, as i want to become the SOC analyst. It is a right course for me. Syed Ali HassnainIt is a great learning session & useful for learners & professionals , thank u for given wonderful opportunity to learn Madupalli SatheeshGoing good. Excited to go thorough the remaining course. Sumanta Banerjee