Microsoft Security Operations Analyst (SOC enginner)

所在平台: Udemy

课程主页: https://www.udemy.com/course/microsoft-security-operations-analyst-soc-enginner/

课程评论:没有评论

第一个写评论        关注课程

课程简介

Coursera 上的 Microsoft 安全运营分析师(SOC 工程师)课程,旨在培养能够保护组织 IT 系统、减少风险的安全运营专业人才。 **课程核心内容包括:** * **Microsoft 365 威胁防护:** 学习如何使用 Microsoft 365 Defender 系列产品来识别、分析和应对各种安全威胁,包括利用 Microsoft 365 Defender for Office 365 修复风险,以及通过 Microsoft Defender for Identity 和 Microsoft Defender for Cloud Apps 保护身份和云环境。 * **Microsoft Defender for Endpoint:** 深入掌握 Defender for Endpoint 的部署、配置、安全增强、设备调查、威胁响应以及漏洞管理能力,以全面保护终端设备。 * **Microsoft Defender for Cloud:** 学习如何规划和实施云工作负载保护,连接 Azure 和非 Azure 资源,管理云安全态势,并利用 Defender for Cloud 响应安全警报。 * **Microsoft Sentinel:** 重点学习这款云原生 SIEM 和 SOAR 解决方案。课程将覆盖 Sentinel 的工作空间管理、日志查询(使用 KQL)、数据连接(包括 Microsoft 服务、M365 Defender、Windows 主机、CEF、Syslog 等)、威胁检测分析、自动化响应(Playbooks)、安全事件管理、行为分析、数据可视化以及威胁搜寻(包括使用 notebooks)。 * **Kusto 查询语言 (KQL):** 熟练掌握 KQL,用于在 Sentinel 和其他 Azure 服务中编写查询语句,分析日志数据,构建多表查询,从而进行深入的威胁调查。 * **安全运营基础:** 课程还将涵盖攻击向量、网络威胁、事件管理等基础知识,以及如何管理数据丢失防护 (DLP) 警报和内部风险。 **本课程适合具备以下基础的学员:** * 熟悉攻击向量和网络威胁。 * 了解事件管理流程。 * 掌握 Kusto 查询语言 (KQL)。 * 熟悉 Microsoft 365 和 Azure 服务。 通过本课程的学习,学员将能够胜任安全运营分析师的职责,有效地利用 Microsoft 安全技术栈来保护企业环境免受攻击。

课程评论(0条)

课程详情

The Microsoft security operations analyst collaborates with organizational stakeholders to secure information technology systems for the organization. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders.Responsibilities include threat management, monitoring, and response by using a variety of security solutions across their environment. The role primarily investigates, responds to, and hunts for threats using Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft 365 Defender, and third-party security products. Since the security operations analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.Candidates for this role should be familiar with attack vectors, cyberthreats, incident management, and Kusto Query Language (KQL). Candidates should also be familiar with Microsoft 365 and Azure services.What will be cover in this course: Introduction to Microsoft 365 threat protectionMitigate incidents using Microsoft 365 DefenderProtect your identities with Azure AD Identity ProtectionRemediate risks with Microsoft Defender for Office 365Safeguard your environment with Microsoft Defender for IdentitySecure your cloud apps and services with Microsoft Defender for Cloud AppsRespond to data loss prevention alerts using Microsoft 365Manage insider risk in Microsoft PurviewProtect against threats with Microsoft Defender for EndpointDeploy the Microsoft Defender for Endpoint environmentImplement Windows security enhancements with Microsoft Defender for EndpointPerform device investigations in Microsoft Defender for EndpointPerform actions on a device using Microsoft Defender for EndpointPerform evidence and entities investigations using Microsoft Defender for EndpointConfigure and manage automation using Microsoft Defender for EndpointConfigure for alerts and detections in Microsoft Defender for EndpointUtilize Vulnerability Management in Microsoft Defender for EndpointPlan for cloud workload protections using Microsoft Defender for CloudConnect Azure assets to Microsoft Defender for CloudConnect non-Azure resources to Microsoft Defender for CloudManage your cloud security posture managementExplain cloud workload protections in Microsoft Defender for CloudRemediate security alerts using Microsoft Defender for CloudConstruct KQL statements for Microsoft SentinelAnalyze query results using KQLBuild multi-table statements using KQLWork with data in Microsoft Sentinel using Kusto Query LanguageIntroduction to Microsoft SentinelCreate and manage Microsoft Sentinel workspacesQuery logs in Microsoft SentinelUse watchlists in Microsoft SentinelUtilize threat intelligence in Microsoft SentinelConnect data to Microsoft Sentinel using data connectorsConnect Microsoft services to Microsoft SentinelConnect Microsoft 365 Defender to Microsoft SentinelConnect Windows hosts to Microsoft SentinelConnect Common Event Format logs to Microsoft SentinelConnect syslog data sources to Microsoft SentinelConnect threat indicators to Microsoft Sentinel Threat detection with Microsoft Sentinel analyticsAutomation in Microsoft SentinelThreat response with Microsoft Sentinel playbooksSecurity incident management in Microsoft SentinelIdentify threats with Behavioral AnalyticsData normalization in Microsoft SentinelQuery, visualize, and monitor data in Microsoft SentinelManage content in Microsoft SentinelExplain threat hunting concepts in Microsoft SentinelThreat hunting with Microsoft SentinelUse Search jobs in Microsoft SentinelHunt for threats using notebooks in Microsoft SentinelAnd moreNice training!

课程标签

0人关注该课程

主题相关的课程