CrowdStrike: For SOC Analysts

所在平台: Udemy

课程主页: https://www.udemy.com/course/crowdstrike-for-soc-analysts/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**CrowdStrike: For SOC Analysts 课程总结** 本课程旨在为SOC分析师提供使用CrowdStrike平台进行威胁检测和事件响应的全面指导。 **核心内容:** * **控制台概览 (Module 1):** 熟悉CrowdStrike控制台的用户界面、功能和导航,为后续学习打下基础。 * **工作重点 (Module 2):** 学习如何在动态威胁环境中有效优先处理任务,识别CrowdStrike控制台中的关键区域,优化SOC工作效率。 * **事件分类 (Module 3):** 掌握快速分类检测事件的技巧,评估事件的严重性、范围,并决定初步应对措施。 * **实用开源工具 (Module 4):** 了解与CrowdStrike平台互补的开源工具,学习如何利用这些工具增强威胁情报和调查能力。 * **事件搜索 / Splunk查询 (Module 5):** 深入学习高级事件搜索技术,掌握使用Splunk创建强大查询的方法,进行主机分析和利用端点日志。 * **实时响应功能 (Module 6):** 掌握CrowdStrike的实时响应能力,学习遏制策略、远程操作、脚本编写等即时响应技能。 * **沙盒与阻断操作 (Module 7):** 探索CrowdStrike沙盒环境及其在威胁分析中的作用,学习有效实施阻断操作以阻止威胁。 * **白名单/排除项 (Module 8):** 了解白名单和排除项的管理,如何在安全性和运营效率之间取得平衡。 * **综合实践 (Module 9):** 通过模拟真实场景,将所学知识付诸实践,经历从检测到解决的端到端事件响应过程。 * **未来发展 (Module 10):** 探讨网络安全领域的职业发展路径,发现持续学习、专业化和技能提升的途径,以应对不断变化的威胁。 本课程将全面提升SOC分析师在CrowdStrike平台上的实操能力,助力更有效的威胁检测与响应。

课程评论(0条)

课程详情

Module 1: Console Overview Get acquainted with the CrowdStrike console, your command center for proactive threat detection and incident response. Explore its interface, functionalities, and navigation to ensure a solid foundation for the rest of the course.Module 2: Where to Spend Your Time Learn to prioritize effectively in a dynamic threat landscape. Understand the critical areas of focus within the CrowdStrike console to optimize your time and as it pertains to SOC work.Module 3: Triaging a Detection Master the art of rapid detection triage. Develop skills to assess the severity of a detection, determine its scope, and decide on appropriate immediate actions.Module 4: Useful Open Source Tools to Use Discover a curated toolkit of open-source resources that complement the CrowdStrike platform. Explore how to leverage these tools to enhance your threat intelligence and investigative capabilities.Module 5: Event Search / Splunk Queries Delve into advanced event search techniques and learn how to craft powerful queries in Splunk. Learn how to conduct host analysis and leveraging endpoint logs to your advantage.Module 6: Real-Time Response Features Equip yourself with CrowdStrike's real-time response arsenal. Dive into containment strategies, remote actions, scripting, and other instant response capabilities.Module 7: Sandbox & Blocking Actions Explore the CrowdStrike sandbox environment and understand its role in threat analysis. Learn to implement blocking actions effectively to halt threats in their tracks.Module 8: Whitelisting / Exclusions Navigate the nuances of whitelisting and exclusions. Gain insights into striking the right balance between security and operational efficiency.Module 9: Putting It All Together Immerse yourself in realistic scenarios where you'll apply your newfound knowledge. Walk through end-to-end incident response processes, from detection to resolution.Module 10: Where to Go Next Chart your future course in the realm of cybersecurity. Discover avenues for continued learning, specialization, and skill refinement to stay ahead in the ever-evolving threat landscape.

课程标签

0人关注该课程

主题相关的课程