|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/azure-sentinel-training-course-cloud-native-siem-in-cloud/
课程评论:没有评论
课程名称:Microsoft Sentinel快速入门 - Azure云中的SIEM 课程概述: 安·约翰逊(Ann Johnson)- 网络安全解决方案组的企业副总裁提到,许多客户在部署和维护SIEM解决方案上花费了大量时间,无法有效处理数据量或应对对手的灵活性。传统的本地SIEM需要基础设施和软件的结合成本,以及年限承诺或不灵活的合同。Azure Sentinel消除了这些痛点,它是一种具有成本效益的、云原生的SIEM,提供可预测的计费和灵活的承诺。 Azure Sentinel是一种云原生的安全信息与事件管理(SIEM)解决方案,提供实时安全洞察和自动化事件响应。此培训课程将教授您如何使用Azure Sentinel实施和管理云原生SIEM。在课程中,您将学习如何收集和分析来自云基础设施、本地系统和第三方服务的安全日志,并利用Azure Sentinel的内置分析和机器学习能力来检测和调查高级威胁。 课程内容包括: 1. 将Azure Sentinel与其他安全工具集成的高级技术,以及自动化事件响应的最佳实践。 2. 配置Azure Sentinel以满足组织特定安全需求(包括合规性和治理要求)的方法。 3. 云SIEM和SOC操作的重点,学习如何使用Azure Sentinel监控和保护云基础设施以及管理安全运营中心(SOC)。 4. 利用Azure Sentinel的内置报告和分析能力,获得组织安全态势的洞察并跟踪合规性。 5. 针对云时代的安全操作及Azure Sentinel如何帮助您应对云特有的安全挑战。 6. 安全威胁与趋势的最新动态,以及Azure Sentinel如何帮助您实时检测和响应这些威胁。 7. 深入了解Azure Sentinel的集成与自动化技术,如何与Azure安全中心、Azure Active Directory和Azure策略等工具集成,提升事件响应效率。 本课程还将探讨人工智能(AI)和机器学习(ML)在云安全中的应用,学习如何利用Azure Sentinel的内置AI和ML能力来实时检测和响应高级威胁,并使用其机器学习算法检测安全日志中的异常和可疑活动。 总之,Azure Sentinel培训课程旨在帮助安全专业人士、DevOps、SecOps、托管服务提供商(MSP)和托管安全服务提供商(MSSP)掌握使用Azure Sentinel实施和管理云原生SIEM所需的知识与技能。课程结束时,您将能够使用Azure Sentinel实时检测和响应安全威胁,自动化事件响应,获得组织安全态势的洞察,保护云基础设施,管理SOC,并满足行业标准的合规性。 课程分为五个部分: 1. 课程介绍 2. 开始使用Azure Sentinel 3. Azure Sentinel基础 4. 使用Azure Sentinel核心操作 5. Azure Sentinel总结与结束
Ann Johnson - Corporate Vice President - Cybersecurity Solutions Group said I commonly hear from customers that they're spending more time with deployment and maintenance of SIEM solutions, which leaves them unable to properly handle the volume of data or the agility of adversaries.Traditional on-premises SIEMs require a combination of infrastructure costs and software costs, all paired with annual commitments or inflexible contracts. We are removing those pain points, since Azure Sentinel is a cost-effective, cloud-native SIEM with predictable billing and flexible commitments.Azure Sentinel is a cloud-native security information and event management (SIEM) solution that provides real-time security insights and automated incident response. This training course will teach you how to implement and manage a cloud-native SIEM using Azure Sentinel.Throughout the course, you will learn how to collect and analyze security logs from various sources, including cloud infrastructure, on-premises systems, and third-party services. You will also learn how to use Azure Sentinel's built-in analytics and machine learning capabilities to detect and investigate advanced threats.The course will cover advanced techniques for integrating Azure Sentinel with other security tools and automating incident response. You will learn best practices for configuring Azure Sentinel to meet your organization's specific security needs, including compliance and governance requirements.One of the main focus of the course is on Cloud SIEM and SOC operations, where you will learn how to use Azure Sentinel to monitor and protect your cloud infrastructure, and how to use Azure Sentinel to manage your security operations center (SOC). Additionally, you will learn how to leverage Azure Sentinel's built-in reporting and analytics capabilities to gain insights into your organization's security posture and track compliance with industry standards.Throughout the course, you will also learn about security operations in the cloud era, and how Azure Sentinel can help you adapt your security operations to the unique challenges of the cloud. You will learn about the latest security threats and trends, and how Azure Sentinel can help you detect and respond to these threats in real-time.Another focus of the course is on the integration and automation techniques that Azure Sentinel offers, where you will learn how to integrate Azure Sentinel with other security tools, such as Azure Security Center, Azure Active Directory, and Azure Policy. Additionally, you will learn how to use Azure Sentinel's built-in automation capabilities to streamline incident response and improve the efficiency of your SOC.The course will also cover the usage of AI and ML in Cloud security, where you will learn how to leverage Azure Sentinel's built-in AI and ML capabilities to detect and respond to advanced threats in real-time. Additionally, you will learn how to use Azure Sentinel's built-in machine learning algorithms to detect anomalies and suspicious activity in your security logs.Overall, this Azure Sentinel Training Course is designed to help security professionals, DevOps and SecOps, Managed Service Provider (MSPs) and Managed Security Service Provider (MSSPs) gain the knowledge and skills needed to implement and manage a cloud-native SIEM using Azure Sentinel. By the end of the course, you will be able to use Azure Sentinel to detect and respond to security threats in real-time, automate incident response, and gain insights into your organization's security posture. You will also be able to protect your cloud infrastructure and manage your SOC, and comply with industry standards.Azure Sentinel Course is Divided to 5 SectionsCourse IntroductionGetting started With Azure SentinelAzure Sentinel BasicsWorking With Azure Sentinel Core OperationsAzure Sentinel Removal and Conclusion