Detection Engineering Masterclass: Part 2

所在平台: Udemy

课程主页: https://www.udemy.com/course/detection-engineering-masterclass-part-2/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:检测工程硕士班:第二部分 课程概述: 欢迎参加《检测工程硕士班:第二部分》!在购买之前,请确保您已完成第一部分。本课程首先将教授安全运营和检测工程的理论知识,随后我们将使用VirtualBox和Elastic的安全产品来构建家庭实验室。接下来,我们将逐步进行三个不同的攻击场景,每一个场景的复杂性都会增加。我们会根据攻击创建检测,并学习如何记录这些检测。然后我们将深入Python编程,编写验证脚本并了解如何通过API与Elastic进行交互。最后,我们将把所有检测内容托管在GitHub上,并通过自主的GitHub Action自动化与Elastic同步。此外,我们还将讲解如何编写脚本以收集重要的指标和可视化信息。 课程内容涵盖检测工程生命周期的全部,及其技术实现。尽管本课程面向初学者,但任何先前的知识都将帮助您更快地适应学习内容。熟悉安全运营、日志搜索、安全分析或任何相关技能将对学习有所帮助(但并非必须)。 第二部分概述: 这是检测工程两部分系列课程中的第二部分,旨在为有兴趣从事安全分析、检测工程和安全架构的人士提供入门指导。第一部分是课程的核心内容,将涉及: - 检测工程理论 - 实验室设置 - 日志管理与SIEM工具的使用 - 运行攻击场景以生成日志和创建警报 - 学习如何使用Atomic Red Team进行测试 第二部分重点关注“代码即检测”的理念,内容将着重于Python和GitHub(别担心!我会逐步引导您)。完成这两部分课程后,您将拥有一个完整的检测工程架构,能够: - 执行攻击性测试 - 查看日志 - 制作警报 - 使用标准化模板保存警报 - 通过代码强化模板数据 - 编程将警报推送至SIEM - 定期运行检测数据的指标 整个课程时长约11小时,但完全完成需要约20-40小时。所有编写的代码将可在课程的GitHub上获取,以便您在不想深入Python部分时跳过。 课程要求: - 能够在本地计算机上运行2-3个虚拟机: - Ubuntu Linux - ParrotOS - Windows 11 - 最低要求: - CPU核心:4 - RAM:8GB - 硬盘空间:50GB - 推荐要求: - CPU核心:6+ - RAM:16GB+ - 硬盘空间:50GB+ 虽然您可以在主机仅有几个核心和8GB RAM的情况下勉强运行,但为虚拟机分配更多资源将使整个过程更加顺畅。感谢您的参与!

课程评论(0条)

课程详情

Welcome to the Detection Engineering Masterclass: Part 2!Don't Purchase if you haven't gone through Part 1!Two Part Course OverviewThis course will first teach the theory behind security operations and detection engineering. We'll then start building out our home lab using VirtualBox and Elastic's security offering. Then we'll run through three different attack scenarios, each more complex than the one prior. We'll make detections off of our attacks, and learn how to document our detections. Next we'll dive more into coding and Python by writing validation scripts and learning out to interact with Elastic through their API. Wrapping everything up, we'll host all our detections on GitHub and sync with Elastic through our own GitHub Action automations. As a cherry on top, we'll have a final section on how to write scripts to gather important metrics and visualizations.This course takes students from A-Z on the detection engineering lifecycle and technical implementation of a detection engineering architecture.While this course is marketed as entry level, any prerequisite knowledge will help in the courses learning curve. Familiarity with security operations, searching logs, security analysis, or any related skillset will be helpful (but ultimately not required).Part Two OverviewThis is part two of a two part series on Detection Engineering! This course is meant to kickstart anyone interested in security analysis, detection engineering, and security architecture. The first part is the meat of the course, where we will go over:Detection Engineering TheorySetting Up our LabWorking with Logging and our SIEMRunning Attack Scenarios to generate logs and create alertsLearn how to use Atomic Red Team for testingThe second part deals with detection as code philosophies, which will be very Python and GitHub heavy (but don't worry! I'll walk you through everything step by step.)By the end of this two part course, you'll have a full stack detection engineering architecture. You'll be able to:Run offensive testsReview the logsMake alertsSave alerts using a standardized templateEnforce template data through codeProgrammatically push the alerts to the SIEMRun periodic metrics off the detection dataThe entire course runs ~11 or so hours in length, but should take ~20-40 hours to complete fully. All code written will be available on the course GitHub in case you'd like to skip the Python heavy sections.RequirementsThe ability to run 2-3 VMs on a local machine:Ubuntu LinuxParrotOSWindows 11Minimum RequirementsCPU Cores: 4RAM: 8gbHard Drive Space: 50GBRecommended RequirementsCPU Cores: 6+RAM: 16GB+ Hard Drive Space: 50GB+You can technically get by with the main host having only a couple cores and 8 gigs of RAM, but any additional resources that can be assigned to your VMs will make the process smoother.Thanks for stopping by!

课程标签

0人关注该课程

主题相关的课程