Detection Engineering Masterclass: Part 1

所在平台: Udemy

课程主页: https://www.udemy.com/course/detection-engineering-masterclass-part-1/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:检测工程大师班:第一部分 课程概述: 欢迎参加检测工程大师班:第一部分!本课程将分为两个部分进行。在第一部分中,我们将学习安全运营和检测工程的理论知识,接着开始使用VirtualBox和Elastic的安全产品搭建我们的家庭实验室。随后,我们将执行三种不同的攻击场景,每一个都比前一个更复杂。通过这些攻击生成日志,我们将进行检测并学习如何记录我们的检测结果。接下来,我们将深入学习编码和Python,编写验证脚本并学习如何通过Elastic的API进行交互。最后,我们会将所有的检测结果托管在GitHub上,并通过GitHub Action自动化与Elastic进行同步。课程的最后部分将介绍如何编写脚本来收集重要的指标和可视化信息。本课程将带领学生全面了解检测工程的生命周期以及检测工程架构的技术实施。 第一部分概述: 这是两个部分系列课程的第一部分,旨在为有兴趣于安全分析、检测工程和安全架构的人提供一个起点。在这一部分中,我们会重点讲解: - 检测工程理论 - 搭建实验室 - 与日志和SIEM的协作 - 运行攻击场景以生成日志和创建警报 - 学习如何使用Atomic Red Team进行测试 第二部分将集中于“检测即代码”的理念,着重于Python和GitHub的应用。课程结束时,学员将掌握完整的检测工程架构,能够: - 运行攻击性测试 - 审查日志 - 制作警报 - 使用标准化模板保存警报 - 通过代码强制执行模板数据 - 将警报程序化推送到SIEM - 定期运行基于检测数据的指标 整个课程时长约为11小时,但完成所有内容可能需要20-40小时。所有编写的代码将在课程的GitHub上提供,以便希望跳过Python重点部分的学员使用。 课程要求: - 能够在本地机器上运行2-3个虚拟机,包括Ubuntu Linux、ParrotOS和Windows 11 - 最低要求:CPU核心数4,内存8GB,硬盘空间50GB - 推荐要求:CPU核心数6及以上,内存16GB及以上,硬盘空间50GB及以上 感谢您的关注!

课程评论(0条)

课程详情

Welcome to the Detection Engineering Masterclass: Part 1!Two Part Course OverviewThis course will first teach the theory behind security operations and detection engineering. We'll then start building out our home lab using VirtualBox and Elastic's security offering. Then we'll run through three different attack scenarios, each more complex than the one prior. We'll make detections off of our attacks, and learn how to document our detections. Next we'll dive more into coding and Python by writing validation scripts and learning out to interact with Elastic through their API. Wrapping everything up, we'll host all our detections on GitHub and sync with Elastic through our own GitHub Action automations. As a cherry on top, we'll have a final section on how to write scripts to gather important metrics and visualizations.This course takes students from A-Z on the detection engineering lifecycle and technical implementation of a detection engineering architecture.While this course is marketed as entry level, any prerequisite knowledge will help in the courses learning curve. Familiarity with security operations, searching logs, security analysis, or any related skillset will be helpful (but ultimately not required).Part One OverviewThis is part one of a two part series on Detection Engineering! This course is meant to kickstart anyone interested in security analysis, detection engineering, and security architecture. The first part is the meat of the course, where we will go over:Detection Engineering TheorySetting Up our LabWorking with Logging and our SIEMRunning Attack Scenarios to generate logs and create alertsLearn how to use Atomic Red Team for testingThe second part deals with detection as code philosophies, which will be very Python and GitHub heavy (but don't worry! I'll walk you through everything step by step.)By the end of this two part course, you'll have a full stack detection engineering architecture. You'll be able to:Run offensive testsReview the logsMake alertsSave alerts using a standardized templateEnforce template data through codeProgrammatically push the alerts to the SIEMRun periodic metrics off the detection dataThe entire course runs ~11 or so hours in length, but should take ~20-40 hours to complete fully. All code written will be available on the course GitHub in case you'd like to skip the Python heavy sections.RequirementsThe ability to run 2-3 VMs on a local machine:Ubuntu LinuxParrotOSWindows 11Minimum RequirementsCPU Cores: 4RAM: 8gbHard Drive Space: 50GBRecommended RequirementsCPU Cores: 6+RAM: 16GB+ Hard Drive Space: 50GB+You can technically get by with the main host having only a couple cores and 8 gigs of RAM, but any additional resources that can be assigned to your VMs will make the process smoother.Thanks for stopping by!

课程标签

0人关注该课程

主题相关的课程