|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/complete-soc-analyst-course-with-splunk-enterprise-2023/
课程评论:没有评论
课程名称:2024年完整的SOC分析师课程与Splunk企业版 课程概述:欢迎来到SiemHunters的完整SOC分析师课程!这门课程有潜力将您的职业生涯转变为网络安全防御领域。本课程由网络安全行业专家Gopi Pakanati先生和讲师Ramya Sri Pachala共同创作,旨在帮助您提升在网络威胁、终端保护、威胁情报等方面的技能,以便成为大型MSSP组织的SOC分析师。课程内容涵盖伦理黑客主题、现代网络攻击的检测以及零日漏洞的识别。 课程大纲: 1. 完整的Kali Linux命令行:了解攻击者如何在基础设施中执行进攻命令以获取未授权访问。 2. 高级网络威胁:了解现代攻击表面上的最新威胁和攻击。 3. SOC简介:理解SOC和基础设施的基本术语。 4. 本地日志与IOC:了解不同操作系统中的本地日志位置,并使用事件查看器理解Windows级别的日志和事件。 5. SIEM部署:理解Splunk企业版的部署(UF和HF)及其配置(输入、输出及转换文件)。 6. SIEM用例:理解威胁的用例创建,以识别恶意活动。 7. SIEM调查:调查最新的网络应用程序、网络和终端级别的威胁。 8. 威胁情报:利用威胁情报收集对手的策略和技术,包括操作、战术、技术和操作情报。 9. 事件响应:理解事件响应步骤以及事件的根本原因分析和消除过程。 10. Qualys Web应用程序:使用Qualys Guard进行扫描并处理VA(漏洞评估)报告。 11. Qualys Guard VM:使用Qualys Guard VM识别终端级别的威胁,处理卸载任务,理解漏洞并将报告共享给相关团队进行解决。 适合人群: - 有意成为MSSP组织的SOC分析师 - 网络安全或其他领域的应届毕业生 - 探索网络安全成为网络专家的人员 - 网络安全分析师 - 安全分析师 - 网络安全经理 - 基于Qualys Guard VM报告的IT专业人员 祝您好运,技术人员们!
Hi Techies..!Welcome to the Complete SOC Analyst Course from SiemHunters. This course that has potential to change your Professional life into defense side cyber security domain. this course made from our industrial cyber security expert Mr. Gopi Pakanati and Instructor Ramya Sri Pachala. In this course content helps to level up your skills in Cyber threats, endpoint protections, Threat Intelligence to become a soc analyst in large MSSP organizations. you will learn ethical hacking topics how to detect modern cyber attacks, and zero-day vulnerabilities. Course Outline: Complete Kali Linux Commands-Line: To understand the how attackers execute offensive commands in your infra to gain unauthorized access. Advanced Cyber Threats: To understand latest threats, and attacks in modern attack surface. Introduction of SOC: To understand basic terminology of soc and infraLocal Logging & IOC: Understand local log locations in different OS systems and working with event Viewer to understand the windows level logs and eventsSIEM Deployment: To understand Splunk enterprise deployment (UF & HF) along with configurations of (inputs, outputs, and transforms files)SIEM Use-cases: understanding use cases creation of the threats to identify the malicious activity. SIEM Investigations: Investigate latest threats in web applications, network and endpoint levelThreat Intelligence: Using threat intelligence to gather adversaries tactics, and techniques using operations, tactical, technical, and operations intelligence. Incident Response: Understanding the IR steps and root cause analysis of the incidents, and eradication processQualys Web Application: Working with qualys guard to initiate scans and working with VA (Vulnerability assessments) based ReportsQualys Guard VM: Working with qualys guard vm to identify the endpoint level threats, working with De-install tasks, and understanding the vulnerability and share the report to the respective teams for resolution, This Course designed for: who wanted to become a soc analyst in MSSP organizationsNew fresher graduates in cyber security or other fieldswho explore cyber security to become a cyber expertCyber security AnalystSecurity AnalystCyber Security ManagersQualys guard VM based reports IT Professionals All the best techies..!