OT-ICS Cybersecurity SOC/SIEM Implementation with WSUS & AD

所在平台: Udemy

课程主页: https://www.udemy.com/course/ics-soc-siem/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:OT-ICS网络安全SOC/SIEM实施与WSUS和AD 概述:欢迎参加我们的ICS网络安全综合课程,涵盖从头到尾的部署。该课程内容涉及保护工业自动化和控制系统网络安全所需的关键概念。我们将深入探讨关键的网络安全组件,如安全信息和事件管理(SIEM),主要关注Elasticsearch-Logstash-Kibana(ELK Stack)、SIEM仪表盘/Kibana查询及网络监控/NOC操作仪表盘:Grafana。 课程将介绍终端检测与响应/主机入侵检测(EDR/HIDS)工具Wazuh,日志管理工具Beats/Sysmon(Windows事件日志收集器及更多),资产管理工具OSQuery - FleetDM,终端可视化工具Sysmon,恶意软件检测工具Strelka,防火墙pfsense及基于Snort的入侵防御系统(IPS)。此外,我们还将探讨网络查询工具Nmap、使用Nessus进行的漏洞管理、Windows Server的Active Directory、WSUS(Windows Server更新服务)、Modbus通信、DNP3通信和OPC服务器-客户端通信。 该课程完全以实践为主,在每一章节中,我们将安装、配置或部署Azure基础设施中的相关应用,过程简单易懂。我向您保证,您将在课程结束时获得全面的ICS网络安全知识,包括保护系统所需的关键概念和工具。现在就报名,获取在这一重要领域的宝贵知识和专业技能。 课程环境在Azure中部署,使用成本最低的区域和最低资源要求。所有步骤都有指导和详细解释,使您能够轻松创建自己的ICS SOC。完成本课程后,您将对ICS环境中使用的网络安全技术有良好的理解,并能够进行各种测试和模拟该环境,您还可以安装自己组织的应用程序进行类似测试。 欢迎通过LinkedIn与我联系,或访问cyberotsecure{dot}com网站获取优惠。

课程评论(0条)

课程详情

*MAKE YOUR OWN ICS SIEM/SOC LAB SETUP WITHOUT HARDWARE*Welcome to our comprehensive course on ICS Cybersecurity from end-to-end deployment. This course covers key concepts essential to safeguarding Industrial Automation and Control Systems cybersecurity.We will delve into critical cybersecurity components such as Security Information and Event Management (SIEM), with a focus on Elasticsearch-Logstash-Kibana (ELK Stack), SIEM Dashboarding/ Query: Kibana, and NOC- Network Monitoring/ Operations Dashboarding: Grafana.You will also learn about EDR/HIDS - Endpoint Detection and Response/ Host Intrusion Detection: Wazuh, Log Management: Beats/Sysmon (Log collector for Windows Event logs and more), Asset Management: OSQuery - FleetDM, Endpoint Visibility: Sysmon, Malware Detection: Strelka, Firewall: pfsense (Firewall), and IPS-Intrusion Prevention System: Snort Based.We will also explore Nmap for network-based queries, Vulnerability Management: Using Nessus, Active Directory- Windows Server, WSUS-Windows Server Update Services, Modbus Communication, DNP3 communication, and OPC Server-Client Communication.By the end of this course, you will have a comprehensive understanding of ICS Cybersecurity from end-to-end deployment, including key concepts and tools essential to safeguarding your systems. Enroll now to gain valuable knowledge and expertise in this critical field.This course is totally practical, in all chapters we are installing, configuring, or deploying something on machines located in azure infrastructure, and it's simple, I promise.We will cover some key concepts of ICS Cybersecurity from end-to-end deployment which are as follows:Security information and event management (SIEM): Elasticsearch-Logstash-Kibana (ELK Stack)SIEM Dashboarding/ Query: KibanaNOC- Network Monitoring/ Operations Dashboarding: GrafanaEDR/HIDS - Endpoint Detection and Response/ Host Intrusion Detection: WazuhLog Management: Beats/Sysmon (Log collector for Windows Event logs and more)Asset Management: OSQuery - FleetDMEndpoint Visibility: Sysmon Malware Detection: Strelka Firewall: pfsense (Firewall)IPS-Intrusion Prevention System: Snort Based Nmap for network-based queriesVulnerability Management: Using NessusActive Directory- Windows ServerWSUS-Windows Server Update ServicesModbus CommunicationDNP3 communicationOPC Server-Client CommunicationAnd this is a dynamic list, and with time keeps on updating and increasing to increase coverage.* Connect to me on Linkedin/ or visit cyberotsecure{dot}com website to get discounts.*The environment is deployed on Azure with the cheapest region and minimum resource requirements. All the steps are guided and well explained so that you can follow and create your own ICS SOC easily. after doing this course you will have a good understanding of cybersecurity technologies that are in use in the ICS landscape as well as in the overall industrial control system environment. You can run all types of tests and simulate this environment, you can also install applications from your organization to test in a similar mode.

课程标签

0人关注该课程

主题相关的课程