|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/fortinet-fortisiem-a-step-by-step-bootcamp/
课程评论:没有评论
课程名称:Fortinet FortiSIEM - 步步深入的训练营 课程概述:您想进入SIEM领域吗?您想学习领先的SIEM技术之一吗?您想了解相关概念并在Fortinet FortiSIEM上进行实践操作吗?那么这门课程非常适合您。通过循序渐进的学习,您将掌握Fortinet FortiSIEM:一个可扩展的多租户安全信息和事件管理(SIEM)解决方案,提供实时的基础设施和用户意识,以支持威胁检测、分析和报告。FortiSIEM提供了一个可操作的安全智能平台,用于通过单一视图监控安全、绩效和合规性。全球范围内,FortiSIEM在管理服务、技术、金融服务、医疗保健和政府等行业拥有数百个客户。全球公司使用FortiSIEM的以下场景包括:威胁管理和情报提供情境意识与异常检测;减轻PCI、HIPAA和SOX的合规性担忧;管理“警报过载”;处理“工具过多”报告问题;在不要求管理员编写复杂规则的情况下检测异常用户和实体行为(UEBA);解决管理服务提供商(MSPs)/受管理安全服务提供商(MSSPs)在满足服务水平协议(SLA)方面的痛点。Fortinet FortiSIEM之前称为FortiSIEM AccelOps。 课程内容涵盖以下主题: - 介绍 - 基础知识与参考架构 - 扩展架构 - 分布式事件关联 - 集群架构 - 许可协议 - 高可用性与灾难恢复 - ClickHouse - FortiSIEM容量规划 - ClickHouse - 全功能主管安装 - FortiCollector安装与注册 - FSM图形用户界面简化 - Windows代理安装、注册及模板关联 - 通过分析页面进行搜索 - 事件、规则开发与故障排除 - Sysmon日志集成到FortiSIEM - Sigma规则与Sysmon规则开发 - 命令行、Powershell审计与Sigma规则翻译 - 攻击场景、文件完整性监控与Linux代理安装 - 仪表板与业务服务 - 报告 - 设备发现 - FortiGate - SNMP、SSH、SYSLOG及NETFLOW - 发现设置、CMDB组、业务服务与自定义属性 - 上传新许可证文件 - NFS存档与保留政策 - 验证与搜索存档 - ClickHouse热层磁盘的添加以延长在线保留 - 数据与控制平面的分离 - 向FortiSIEM添加网络接口 - FortiSIEM许可和部件号码的深入解析 该课程适合希望从基础开始,逐步深入学习Fortinet FortiSIEM的用户。
Do you want to enter the SIEM field? Do you want to learn one of the leaders SIEM technologies? Do you want to understand the concepts and gain the handson on Fortinet FortiSIEM? Then this course is designed for you. Through baby steps you will learn Fortinet FortiSIEM FortiSIEM is a highly scalable multi-tenant Security Information and Event Management (SIEM) solution that provides real time infrastructure and user awareness for threat detection, analysis and reporting. FortiSIEM provides an actionable security intelligence platform to monitor security, performance and compliance through a single pane of glass.FortiSIEM has hundreds of customers worldwide in markets including managed services, technology, financial services, healthcare, and government. Companies around the world use FortiSIEM for the following use cases:Threat management and intelligence that provide situational awareness and anomaly detectionAlleviating compliance mandate concerns for PCI, HIPAA and SOXManaging "alert overload"Handling the "too many tools" reporting issueDetect unusual user and entity behavior (UEBA) without requiring the Administrator to write complex rules.Addressing the MSPs/MSSPs pain of meeting service level agreementsFortinet FortiSIEM was previously known as FortiSIEM, AccelOps.The course is covering below topics- Introduction- Foundations and Reference Architecture- Scale-Out Architecture- Distributed Event Correlation- Clustering Architecture- Licensing- High Availability and Disaster Recovery - ClickHouse- FortiSIEM Sizing - ClickHouse- All-In-One Supervisor Installation- FortiCollector Installation & Registeration- FSM GUI simplified- Windows Agent Installation, Registeration and Template Association- Search via Analytics page- Incidents, Rules Development and Troubleshooting- Sysmon Log Integration into FortiSIEM- Sigma Rules and Sysmon Rule Development- Command Line_Powershell Auditing and Sigma Rule Translation- Attack Scenario, File Integrity Monitoring and Linux Agent Installation- Dashboards and Business Services- Reports- Device Discovery - FortiGate - SNMP, SSH, SYSLOG, and NETFLOW- Discovery Settings, CMDB Groups, Business Services and Custom Properties- Upload New License File- NFS Archive and Retention Policy- Validate and Search Archives- ClickHouse Warm Tier disk addition to Extend Online Retention- Splitting Data & Control Planes - Adding Network Interface to FortiSIEM- Deep Dive on FortiSIEM Licensing and Part Numbers