|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cyber-threat-intelligence-cti-101-beginners-guide-2025/
课程评论:没有评论
**课程名称:** 网络安全基础:网络威胁情报入门 (2025) **课程概述:** 本课程旨在为初学者提供构建网络安全领域热门技能的实践性知识,深入介绍网络威胁情报 (CTI)。学员将全面了解 CTI 的运作机制、其如何支持安全运营中心(SOC),并学习使用 Microsoft Sentinel 和 MISP 等真实工具收集、处理和响应威胁数据。课程还将探讨攻击者使用的 TTPs(战术、技术和程序),以及 CTI 在检测和防御这些威胁中的作用。 **学习内容:** * **第一部分:CTI 导论** * 理解 CTI 的定义及其在现代网络安全中的关键作用。 * 通过生动的类比,轻松掌握复杂概念。 * **第二部分:CTI 生命周期详解** * 学习 CTI 生命周期的各个阶段:引导、收集、处理、分析和传播。 * 了解每个阶段如何支持威胁检测,并实现主动防御策略。 * **第三部分:威胁情报类型** * 深入了解四种核心情报类型:战略情报、战术情报、操作情报和技术情报。 * 学习如何根据组织需求和威胁形势应用这些情报。 * **第四部分:实验 - Microsoft Sentinel 中的威胁情报** * 设置 Microsoft Azure 环境并部署 Microsoft Sentinel。 * 配置 Log Analytics,探索内容中心,并集成包括 TTPs 和 IOCs 在内的威胁情报源。 * 学习如何在云原生 SOC 平台中实现 CTI。 * **第五部分:分析师必备工具** * 探索前 5 名威胁情报工具,包括用于威胁共享和丰富化的 MISP。 * 学习如何利用这些工具,结合已知的 TTPs,跟踪、分析和防御真实世界的攻击。
Are you ready to dive into the world of Cyber Threat Intelligence (CTI) and build job-ready skills in one of the most in-demand areas of cybersecurity?This beginner-friendly course is designed to give you a clear, hands-on understanding of how Cyber Threat Intelligence works, how it supports Security Operations Centers (SOCs), and how you can start using real-world tools and platforms like Microsoft Sentinel and MISP to collect, process, and act on threat data. You'll also gain insights into TTPs (Tactics, Techniques, and Procedures) used by adversaries and how CTI helps detect and defend against them. What You'll Learn:Section 1: Introduction to CTIUnderstand what CTI is and why it's critical to modern cybersecurity.Learn through real-world analogies that make complex topics easy to grasp.Section 2: CTI Lifecycle ExplainedFollow the CTI lifecycle: Direction, Collection, Processing, Analysis, and Dissemination.Learn how each phase supports threat detection and enables a proactive defense strategy.Section 3: Types of Threat IntelligenceDive into the four core types: Strategic, Tactical, Operational, and Technical intelligence.Understand how to apply them based on organizational needs and threat landscapes.Section 4: Labs - Threat Intelligence in Microsoft SentinelSet up your Microsoft Azure environment and deploy Microsoft Sentinel.Configure Log Analytics, explore the Content Hub, and integrate threat intelligence feeds including TTPs and IOCs.Learn how to operationalize CTI in a cloud-native SOC platform.Section 5: Tools Every Analyst Should KnowExplore the top 5 threat intelligence tools, including MISP for threat sharing and enrichment.See how these tools help track, analyze, and defend against real-world attacks using known TTPs.