SIEM Admin - Incident Handing Training - SOC Team

所在平台: Udemy

课程主页: https://www.udemy.com/course/siem-administration-training-arcsight-splunk-qradar-nitro-rsa/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:SIEM 管理员 - 事件处理培训 -SOC 团队** **课程概述:** 本课程是 Udemy 上备受瞩目的 SIEM 在线培训的第二阶段。课程旨在帮助学员熟悉并掌握多种 SIEM 工具的组件、架构、事件生命周期和管理。重点将放在 Splunk 的日志源集成、规则创建、报告配置、仪表板创建、精细调优以及安全运营中心 (SOC) 团队遵循的事件处理步骤。 课程设计适合初学者及有经验的专业人士,深入讲解以下 SIEM 工具的事件流程、架构、设计及差异: * HP ArcSight * IBM QRadar * RSA Security Analytics * Splunk * McAfee Nitro **课程学习内容:** 完成本课程后,您将能够: * 理解什么是 SIEM * 了解 SIEM 的业务需求 * 掌握 HP Arcsight、IBM QRadar、Splunk、RSA SA 和 McAfee Nitro 的 SIEM 架构 * 了解 SIEM 解决方案中事件的生命周期 * 认识 HP ArcSight、IBM QRadar、Splunk、RSA SA 和 McAfee Nitro 中不同 SIEM 组件的角色 * 掌握数据源的集成配置(以 Splunk 为例) * 理解网络攻击的“杀伤链”模型 (Cyber Kill Chain) * 学习如何在 SIEM 中开发有效的用例 * 学会如何评估 SIEM 工具 * 构建行业相关的用例(以 Splunk 为例) * 学习在 Splunk 中创建警报 * 学习在 Splunk 中进行事件监控 * 掌握为攻击分析创建仪表板 * 了解报告配置 * 学习警报的精细调优 * 进行真实的事件响应调查(以 Splunk 为例) **教学理念:** 快乐学习!

课程评论(0条)

课程详情

THE MOST DEMANDING SIEM Online Training IS NOW ON UDEMY!PHASE 2 - This course will make you familiar and teach you about various SIEM tools component, architecture, event life cycle and administration part for Splunk for log source integration, rule creation, report configuration, dashboard creation, fine tuning and Incident Handing steps followed by Security Operation Center Team. This course is designed is such a way, that any beginner or any working professional can learn the below SIEM tools event flow, architecture, design & difference.1) HP ArcSight2) IBM QRadar3) RSA Security Analytics4) Splunk5) McAfee NitroWhat you will learn after completing this course:What is the SIEMSIEM Business RequirementSIEM Architecture of HP Arcsight, IBM QRadar, Splunk, RSA SA & McAfee NitroEvent Life Cycle in SIEM Solution HP Arcsight, IBM QRadar, Splunk, RSA SA & McAfee NitroRoles of Different SIEM Component of HP Arcsight, IBM QRadar, Splunk, RSA SA & McAfee NitroIntegration Configuration of Data sources [Splunk]What is Cyber Kill ChainHow to develop effective USECASE in SIEMHow to Evaluate a SIEM toolBuilding Industry Based Use Cases [Splunk]Alert Creation in [Splunk] Event Monitoring [Splunk]Creating Dashboards for Attack Analysis [Splunk]Report Configuration [Splunk]Fine Tuning Of Alerts[Splunk]Real World Incident Response Investigation [Splunk]Happy Learning!

课程标签

0人关注该课程

主题相关的课程