IBM Qradar Certified Administrator/Analyst

所在平台: Udemy

课程主页: https://www.udemy.com/course/ibm-qradar-certified-administratoranalyst/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** IBM QRadar 认证管理员/分析师 **课程概述:** 本课程为中级水平,旨在帮助安全分析师验证其对 IBM Security QRadar SIEM V7.4.3+ 的全面知识。学员将掌握基础网络知识、基础 IT 安全知识、SIEM 和 QRadar 概念,并了解如何通过图形用户界面登录、导航和解释产品功能。此外,学员还将能够识别攻击事件的原因,并在 QRadar 部署中访问、解读和报告安全信息。 **推荐技能/先修知识:** * SIEM 概念 * TCP/IP 网络知识 * IT 安全概念 * 通用 IT 技能(浏览器导航等) * 互联网安全攻击类型知识(包括但不限于 MITRE ATT&CK 框架) * 其他需要额外许可的功能(如 QRadar Network Insights, QRadar Incident Forensics) **核心能力领域:** * **攻击事件和日志分析:** 评估初始攻击事件,分析完全匹配及部分匹配的规则,解读攻击事件及相关 IP 地址,识别 MITRE 威胁组织和攻击者,进行攻击事件管理,理解攻击事件的严重性,识别解析不正确的事件及其来源(已存储事件),创建自定义搜索,解释使用正则表达式的规则,创建和管理参考集并填充数据,安装 QRadar 内容包(使用 QRadar Assistant App),分析使用事件和流量数据的规则,理解构建块(主机定义、类别定义、端口定义)。 * **规则与构建块理解:** 审查和建议网络层级更新,审查和建议构建块和规则更新,描述不同类型的规则(行为、异常、阈值规则)。 * **搜索与报告:** 投资事件和流量参数,执行 AQL 查询,按特定日志源类型搜索和过滤日志,配置搜索利用时间序列,分析潜在的 IoCs,分解触发的规则以确定攻击事件原因,推荐 QRadar SIEM 调优更改(在攻击事件分析识别问题后),区分潜在威胁与可能的误报,在日志分析中添加基于参考集的过滤器,为攻击事件提供更多细节而调查载荷,建议根据载荷数据添加新的自定义属性,对攻击事件数据执行“右键单击调查”。 * **仪表板与报告:** 使用默认 QRadar 仪表板创建、查看和维护基于常用搜索的仪表板,使用 Pulse 创建、查看和维护基于常用搜索的仪表板,执行高级搜索,解释每种搜索类型的不同用途,过滤搜索结果,构建威胁报告,执行快速搜索,查看触发最频繁的规则,报告攻击事件中关联的事件,以 CSV 或 XML 格式导出搜索结果,创建和生成计划内及手动报告,创建高级报告,与其他用户共享报告,使用索引和非索引属性进行搜索。

课程评论(0条)

课程详情

This intermediate level certification is intended for security analysts who wish to validate their comprehensive knowledge of IBM Security QRadar SIEM V7.4.3+.These security analysts will understand basic networking, basic IT security, SIEM and QRadar concepts. They will also understand how to log in to, navigate within, and explain capabilities of the product using the graphical user interface. Additionally, they will also be able to identify causes of offenses, and access, interpret, and report security information in a QRadar deployment.Recommended SkillsPrerequisite KnowledgeKnowledge and foundational skills one must possess before acquiring skills measured on the certification test. These foundational skills are NOT measured on the test.Knowledge of SIEM conceptsKnowledge of TCP/IP NetworkingKnowledge of IT Security conceptsGeneral IT skills (browser navigation etc...)Knowledge of Internet security attack types, including but not limited to the MITRE ATT & CK FrameworkAdditional features that need additional licenses including but not limited to QRadar Network Insights, QRadar Incident ForensicsKey Areas of CompetencyOffense and log analysisUnderstanding reference dataRule and building block understandingSearching and reporting, regular and adhoc reportsUnderstanding basic QRadar tuning and network hierarchyBasic concepts of multi-domain QRadar instancesDetails:Triage initial offenseAnalyze fully matched and partially matched rulesAnalyze an offense and associated IP addressesRecognize MITRE threat groups and actorsPerform offense managementDescribe the use of the magnitude of an offenseIdentify events not correctly parsed and their source (Stored events)Outline simple offense naming mechanismsCreate customized searchesInterpret rules that test for regular expressionsCreate and manage reference sets and populate them with dataInstall QRadar Content Packs using the QRadar Assistant AppAnalyze rules that use Event and Flow dataAnalyze Building Blocks: Host definition, category definition, Port definitionReview and recommend updates to the network hierarchyReview and recommend updates to building blocks and rulesDescribe the different types of rules, including behavioral, anomaly and threshold rulesInvestigate Event and Flow parametersPerform AQL querySearch & filter logs by specific log source typeConfigure a search to utilize time seriesAnalyze potential IoCsBreak down triggered rules to identify the reason for the offenseRecommend changes to tune QRadar SIEM after offense analysis identifies issuesDistinguish potential threats from probable false positivesAdd a reference set based filter in log analysisInvestigate the payload for additional details on the offenseRecommend adding new custom properties based on payload dataPerform "right-click Investigations" on offense dataUse the default QRadar dashboard to create, view, and maintain a dashboard based on common searchesUse Pulse to create, view, and maintain a dashboard based on common searchesPerform an advanced searchExplain the different uses for each search typeFilter search resultsBuild threat reportsPerform a quick searchView the most commonly triggered rulesReport events correlated in the offenseExport Search results in CSV or XMLCreate reports and advanced reports out of offensesShare reports with usersSearch using indexed and non-indexed propertiesCreate and generate scheduled and manual reports

课程标签

0人关注该课程

主题相关的课程