IBM QRadar SIEM - A Step-by-Step BootCamp

所在平台: Udemy

课程主页: https://www.udemy.com/course/ibm-qradar-siem-a-step-by-step-bootcamp/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:IBM QRadar SIEM - 入门训练营** **课程概述:** 本课程专为希望进入安全信息和事件管理(SIEM)领域,并掌握行业领先的IBM QRadar SIEM技术的学习者设计。通过循序渐进的方式,您将深入理解SIEM核心概念,并获得QRadar的实际操作经验。 **学习重点:** * **QRadar架构与组件:** 了解QRadar的整体架构和各个组成部分。 * **安装与配置:** 掌握 all-in-one 安装方法。 * **界面操作与事件/流量分析:** 熟悉Console GUI,理解事件和流量的捕获、重放,以及深入调查事件和流量。 * **告警(Offense)管理:** 掌握告警的构成、重要性评估、保留、关联和保护。 * **事件解析与排错:** 识别和处理未正确解析的事件及其源头。 * **定制化搜索与规则:** 学习创建自定义搜索,设计规则和Building Blocks。 * **日志集成与DSM开发:** 了解日志集成机制,学习自定义设备支持模块(DSM)的开发。 * **AQL查询与自定义属性:** 使用AQL(Ariel Query Language)进行数据查询,创建自定义属性。 * **WinCollect:** 掌握Windows事件日志的收集。 * **X-Force App Exchange与内容包:** 学习安装和使用X-Force App Exchange上的应用程序,以及QRadar Content Packs的安装与故障排除。 * **QRadar Assistant App:** 学习使用QRadar Assistant App进行内容包的安装。 * **参考数据管理:** 理解和管理参考数据类型。 * **Building Blocks分析与调优:** 分析Building Blocks的配置,并进行调优。 * **用例管理器与威胁情报:** 学习使用Use Case Manager app,理解MITRE威胁组和行为者。 * **仪表盘与报告:** 设计和生成各种仪表盘和报告。 * **Clean SIM 模型:** 理解Clean SIM模型的概念。 * **攻击模拟与日志剖析:** 进行攻击模拟,并使用Sysmon进行进程剖析。 * **规则路由与许可:** 了解规则路由选项、组合选项以及License Giveback。 * **备份与恢复:** 掌握QRadar的备份和恢复操作。 * **与其他系统集成:** 学习将QRadar告警集成到FortiSOAR,并通过Postman进行API调用,实现与FortiGate防火墙的集成,以阻止用户PC访问互联网。 **新增内容(2024年10月25日):** * **QRadar升级规划与流程:** * 升级规划 * 备份策略 * CentOS-base App 的缓解措施 * QRadar升级流程 * WinCollect Agent 依赖关系及托管代理自动更新 本课程旨在为学员提供全面的QRadar实操技能,帮助他们在SIEM领域脱颖而出。

课程评论(0条)

课程详情

Do you want to enter the SIEM field? Do you want to learn one of the leaders SIEM technologies? Do you want to understand the concepts and gain the hands-on on IBM QRadar SIEM? Then this course is designed for you. Through baby steps you will learn IBM QRadar SIEMImportant topics that you will learn about in this course include but not limited to the following:The course is covering below topics:- QRadar architecture- QRadar components- All-In-One installation- Console GUI demystified, QRadar Services and Replay Events & Flows- Offense, Event, Flow investigation- Describe the use of the magnitude of an offense- Offense management (retention, chaining, protection)- Identify events not correctly parsed and their source- Customized searches- Log Integration and DSM Development- Rules and Building Block Design- AQL queries- Custom properties- WinCollect- X-Force App Exchange, Content Packs and Pulse Installation and Troubleshooting- QRadar Assistant App- Install QRadar Content Packs using the QRadar Assistant App- Reference Data Types and Management- Analyze Building Blocks Host definition, category definition, Port definition- Tuning building blocks and Tuning Methodology- Use Case Manager app, MITRE threat groups and actors- Dashboarding and Reporting- Clean SIM Model- Attack Simulation and Sysmon Process Profiling- Rule Routing options, Rule Routing combination options and License Giveback- Backup and restore- Ingesting QRadar offenses into FortiSOAR- Custom Integration with FortiGate Firewall to Block User's PC from Accessing the Internet- Postman - An API Call Development Methodology-- Below new section and lessons added on 25 October 2024 --New Section Name: QRadar Upgrade Planning and ProceduresNew Lessons in section:- Upgrade Planning- Backups- Mitigate Centos-base Apps- QRadar Upgrade Procedures- Wincollect Agents Dependencies and Managed Agents Auto-Update

课程标签

0人关注该课程

主题相关的课程