Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to Blue Team Operations
- A comprehensive overview of the Blue Team and its strategic function in cybersecurity.
- Analyzing attack surfaces and understanding the evolving threat landscape.
- Exposure to key security frameworks, including MITRE ATT&CK, NIST, and CIS.
Security Information and Event Management (SIEM)
- Foundations of SIEM systems and effective log management.
- Practical steps for setting up and configuring SIEM tools.
- Techniques for analyzing security logs to identify anomalies.
Network Traffic Analysis
- Deep dive into network traffic dynamics and packet-level analysis.
- Applying Wireshark for detailed packet inspection.
- Strategies for detecting network intrusions and identifying suspicious behavior.
Threat Intelligence and Indicators of Compromise (IoCs)
- Principles and applications of threat intelligence.
- Methods for identifying and analyzing Indicators of Compromise.
- Advanced threat hunting techniques and operational best practices.
Incident Detection and Response
- Mapping the incident response lifecycle against established frameworks.
- Evaluating security incidents and deploying containment strategies.
- Basics of forensic investigation and malware analysis.
Security Operations Center (SOC) and Best Practices
- Navigating the structure and workflows of a SOC.
- Enhancing efficiency through automated security operations via scripts and playbooks.
- Fostering collaboration between Blue, Red, and Purple Teams through exercises.
Summary and Next Steps
Requirements
- A foundational understanding of core cybersecurity concepts.
- Proficiency in networking fundamentals, including TCP/IP, firewalls, and IDS/IPS systems.
- Working experience with both Linux and Windows operating systems.
Target Audience
- Security analysts.
- IT administrators.
- Cybersecurity professionals.
- Network defenders.
21 Hours
Testimonials (2)
Clarity and pace of explanations
Federica Galeazzi - Aethra Telecomunications SRL
Course - AI-Powered Cybersecurity: Advanced Threat Detection & Response
It did give me the insight what I needed :) I am starting teaching on a BTEC Level 3 qualification and wanted to widen my knowledge in this area.