Syllabus SOC-IR

09

SIEM מערכת

Learn SQL

  • Practice Exercises for Interviews with Solutions
  • GroupBy, Aggregate functions with practical example

Getting to know the SIEM

  • Introduction to Azure Sentinel SIEM interface, dashboard, logs, devices
  • Introduction to Qradar SIEM interface, dashboard, logs, devices
  • Introduction to WatchDog-Splunk SIEM interface, dashboard, logs, devices
  • Architecture Overview
  • Devices and Settings
  • Data Sources
  • Event Analysis
  • Aggregation
  • Watch Lists and Policy Editor
  • Query Filters
  • Rule Correlation
  • Alarms

Gaining Hands on experience

  • Working on the SIEM - queries, detection, analysis
  • Domain User activity, Anti-Virus, Perimeter Defense, firewall, Correlation Engine

Detecting & Analyzing Attack scenarios

  • SIEM scenarios and analysis

חזרה לדף קורס SOC-IR - לחצו כאן