Course Outline
Module 1: SIEM Fundamentals, Architecture, and Ecosystem Overview
This module builds a solid foundation in SIEM (Security Information and Event Management) principles, the architecture of the IBM QRadar platform, its ecosystem integrations, and the broader security analytics context, including XDR, SOAR, and threat intelligence platforms.
1.1 Security Analytics and SIEM Fundamentals
- The evolution of the SIEM landscape: from simple log management to advanced security analytics
- Distinguishing between SIEM, SOAR, and XDR: understanding the convergence of security tools
- Core components of SIEM: log collection, normalization, correlation, and alerting mechanisms
- The SOC analyst workflow: covering detection, triage, investigation, and response phases
- An overview of the MITRE ATT&CK framework and its application in SIEM mapping
1.2 IBM QRadar Platform Architecture
- On-premises QRadar architecture: components including Event Processor, Log Manager, Console, and Flow Processor
- QRadar on Cloud: multi-tenant architecture, data ingestion models, and scalability features
- Hybrid Cloud deployment with QRadar: merging on-premise and cloud capabilities
- Deployment options: Virtual Appliances, Hardware Appliances, and SaaS models
- High Availability (HA) configurations: comparing Active-Passive and Active-Active setups
1.3 QRadar Components and Console Navigation
- IBM QRadar Console: interface overview, workspaces, dashboards, and navigation tools
- Complementary Apps, the QRadar App Framework, and the IBM App Exchange
- Utilizing Context Explorer, Risk Analyzer, and threat intelligence integrations
- The QRadar data model: Hosts, Devices, Protocols, and Categories
1.4 The QRadar Ecosystem
- IBM QRadar SOAR: integrating security orchestration and automated response
- IBM QRadar EDR: endpoint detection and response integration
- Threat Intelligence integration (including VTI feeds and custom threat feeds)
- Integration with other SIEM tools: Splunk, Elastic SIEM, and IBM QRadar log source management
1.5 Integration with IBM Security Suite
- IBM QRadar SOAR integration for automation and playbook orchestration
- IBM QRadar EDR integration for endpoint telemetry collection
- IBM QRadar VTI (Vulnerability and Threat Intelligence) integration
- Accessing apps and add-ons via the IBM QRadar App Exchange
- IBM QRadar Network Integration Platform (NFI) integration
Market-Aligned Competencies: SIEM Fundamentals, Security Information and Event Management, IBM QRadar Platform Architecture, QRadar On-Premise Deployment, QRadar Cloud Architecture, Hybrid Cloud Security, SOC Operations and SIEM, Security Analytics, XDR Integration, SOAR Platform Integration, Threat Intelligence Platform (TIP), MITRE ATT&CK Framework Mapping, Security Tool Convergence, Enterprise Security Architecture, Log Management and Analytics, SIEM Scalability and Capacity Planning, High-Availability (HA) Configuration, QRadar Console Navigation and Configuration
Module 2: Log Source Management, Data Ingestion, and Normalization
This module provides an in-depth look at log source configuration, data collection strategies, log normalization, and the protocols required to establish enterprise-wide security visibility across on-premise, cloud, and hybrid environments.
2.1 Log Source Configuration and Protocols
- Log collection methods: Syslog (RSYSLOG), Network Connections (CEF), Common Event Format (CEF), and QRadar CEF
- CEF protocol details: headers, extension names, custom extensions, and CEF-to-CEF mapping
- Network-based log collection: NetFlow v5/v9, IPFIX (sFlow)
- Agent-based collection using the IBM QRadar Agent for enhanced endpoint visibility
- Configuring log sources for Active Directory, DNS, DHCP, HTTP, SMTP, and databases
- Best practices for log source deployment: handling high-throughput sources, compression, and encryption
2.2 Data Ingestion and Capacity Planning
- Understanding daily log file volume (GLP) and daily event data ingestion capacity
- Managing data retention policies and compliance-driven retention strategies
- Prioritizing log sources and filtering events to manage costs effectively
- Capacity planning for large-scale enterprise SIEM deployments
- Calculations for sizing and performance optimization in large environments
2.3 Log Normalization and Classification
- The QRadar Normalization Engine: mapping native log formats to QRadar protocols
- Using the Log Source Property Manager for protocol mapping
- Creating custom log sources for proprietary log types
- Mapping events, flows, and log sources
- Applying normalization rules and troubleshooting parsing issues
Market-Aligned Competencies: Log Source Management, Syslog Configuration, CEF Protocol, Network Connections (CEF), QRadar Agent Deployment, Active Directory Log Collection, DNS and DHCP Log Collection, HTTP/S and SMTP Log Collection, Database Log Collection (CEF) Integration, NetFlow and IPFIX Collection, Agentless SIEM Deployment, Enterprise Log Collection Strategy, Log Normalization, Protocol Mapping, Custom Log Source Configuration, Event Parsing and Classification, Daily Log Volume (DLV) Estimation, SIEM Capacity Planning, Performance Tuning for Large-Scale SIEM, Compliance-Driven Data Retention
Module 3: Detection, Correlation, and Rule Development
This module focuses on the core of SIEM operations: developing, testing, and managing detection rules, ranging from simple event rules to complex compound correlation rules that identify attacks, anomalies, and policy violations.
This module focuses on the core of SIEM operations: developing, testing, and managing detection rules, ranging from simple event rules to complex compound correlation rules that identify attacks, anomalies, and policy violations.
3.1 Event Rules and Aggregation Rules
- Event Rules: filtering data, extracting fields, and creating custom attributes from raw events
- Aggregation Rules: counting and grouping events based on IP, protocol, user, and other criteria
- Actions for Aggregation Rules: sending notifications, setting counter thresholds, and defining custom properties
- Managing rule activation, ordering, and execution logic
3.2 Compound Correlation Rules
- Constructing compound correlation rules: joining data from multiple sources
- Rule types: Event, Aggregation, and Compound Correlation
- Components of Compound Rules: triggers, aggregations, correlations, and actions
- Correlation logic: temporal, threshold, and contextual correlation methods
- Prediction and correlation rule properties: confidence levels, severity, and escalation paths
- Writing effective correlation rules: minimizing alert fatigue while ensuring signal quality
3.3 Detection Rules for MITRE ATT&CK Techniques
- Rules aligned with MITRE ATT&CK techniques: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control (C2), and Exfiltration
- Developing custom detections for specific attack categories:
- Rules for: Brute Force, Port Scanning, Malware Communication, Insider Threat, Lateral Movement, Privilege Escalation, Data Exfiltration, and Command-and-Control (C2)
- Rules for: Brute-Force Authentication Failures, Port Scanning, SQL Injection, DNS Tunneling, Privilege Escalation, and Lateral Movement via Pass-the-Hash
3.4 Threat Hunting with QRadar Rules
- Applying a proactive threat hunting methodology using QRadar
- Building rules to detect unknown or zero-day threats
- Implementing behavior analysis and baseline deviation detection rules
Market-Aligned Competencies: Event Rule Development, Aggregation Rule Creation, Compound Correlation Rule Development, Custom Correlation Rule Design, MITRE ATT&CK Mapping, Threat Detection Engineering, Attack Technique Mapping (Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration), Malware Communication Detection, SQL Injection Detection, DNS Tunneling Detection, Privilege Escalation Rule, Brute Force Detection, Lateral Movement Detection, Insider Threat Detection, Data Exfiltration Detection, Command-and-Control (C2) Detection, Alert Fatigue Management, Rule Tuning and Optimization, SOC Detection Rule Engineering, Proactive Threat Hunting
Module 4: QRadar Offense Engine and Incident Investigation
This module explores the QRadar offense engine in detail, covering offense creation, investigation workflows, context analysis, managing false positives, triage, and incident handling.
4.1 The Offense Engine
- Creating, aggregating, and managing the lifecycle of offenses
- Key offense properties: severity, confidence, status, and attribution
- Offense aggregation logic: grouping related events into coherent incidents
- Managing offense escalation, assignment, and workflow processes
4.2 Incident Investigation and Context Analysis
- Using Context Explorer for deep event analysis and timeline reconstruction
- Event timeline analysis: chronologically reconstructing security incidents
- Analyzing IP addresses and enriching data with reputation (Threat Intel) information
- User and asset context: examining user activity, host inventory, and asset risk analysis
- Reviewing correlation events within offense and event detail views
- Event correlation, grouping, and gathering evidence
4.3 Threat Intelligence Integration
- Integrating Vulnerability and Threat Intelligence (VTI) feeds
- Automating threat intelligence enrichment using IBM QRadar VTI
- Uploading custom threat feeds and defining threat actor profiles
- Incorporating threat intelligence context into offenses and risk analysis
4.4 False Positive Management and Rule Tuning
- Identifying and classifying false positives within the Offense Engine
- Configuring false positive suppression rules and workflows
- Tuning rules: reducing noise while preserving detection sensitivity
- Documenting false positive incidents to drive continuous improvement
Market-Aligned Competencies: QRadar Offense Engine Management, Incident Investigation and Analysis, Threat Investigation, Context Explorer Usage, Event Timeline Analysis, IP Reputation Analysis, Asset Risk Analysis, Threat Intelligence Enrichment, VTI Feed Integration, False Positive Management, Alert Tuning and Noise Reduction, SOC Incident Response Workflow, Security Incident Life Cycle, Compromise Indicator Analysis, Cyber Threat Attribution
Module 5: QRadar Vulnerability Management (QVM) and Risk Manager (QRM)
This module delves into IBM QVM, covering vulnerability scanning integration, risk-based prioritization, risk management configurations, and risk-driven security posture assessment.
5.1 IBM QRadar Vulnerability Manager (QVM)
- QVM architecture: integrating with Nessus, Qualys, and Rapid7 scanners
- Workflows for vulnerability scanning and scheduling
- Parsing vulnerability assessment results and integrating them with QRadar
- Correlating CVSS scores and classifying vulnerability severity
- Analyzing vulnerability trends and prioritizing remediation efforts
5.2 IBM QRadar Risk Manager (QRM)
- QRM architecture: the risk calculation engine and scoring methodology
- Configuring risk rules: asset criticality, vulnerability exploitation likelihood, and asset risk profiles
- Calculating risk scores: combining vulnerability data, threat intelligence, offense data, and asset value
- Ranking assets by risk and configuring risk dashboards
- Driving asset and remediation prioritization based on risk scores
Market-Aligned Competencies: Vulnerability Assessment and Management, IBM QRadar Vulnerability Manager (QVM), CVE Score Correlation, Vulnerability Scanning Integration, Qualys/Nessus Integration, Risk-Based Vulnerability Prioritization, IBM QRadar Risk Manager (QRM), Risk Score Calculation, Asset Criticality Assessment, Risk-Driven Remediation, Risk Dashboard Configuration, Vulnerability Trend Analysis, Enterprise Vulnerability Management, Enterprise Risk Assessment and Management
Module 6: QRadar SOAR, Automation, and Incident Response
This module covers IBM QRadar SOAR (Security Orchestration, Automation, and Response), focusing on playbook orchestration, runbook automation, and incident response automation essential for modern SOC operations.
6.1 IBM QRadar SOAR Overview
- Defining and valuing security orchestration and automated response
- QRadar SOAR architecture and components: playbooks, incidents, automation actions, and data actions
- QRadar SOAR integration: connecting SIEM, EDR, threat intelligence, and ticketing systems (ServiceNow, Jira)
- SOAR vs. traditional automation: orchestrating workflow via playbooks
6.2 Playbook Design and Execution
- Creating Playbooks: building automated investigation and response workflows
- Playbook triggers: offense creation, rule triggers, and manual activation
- Playbook actions: enriching IP addresses, blocking IPs, creating tickets, and querying threat feeds
- Implementing playbook conditions and branching logic
6.3 Incident Response Automation
- Automating incident response: achieving containment from alert in minutes
- Automated threat hunting: conducting playbook-driven threat investigations
- Automating incident containment: IP blocking, endpoint isolation, and account suspension
- Designing automated response workflows for ransomware, phishing, brute-force attacks, and insider threats
6.4 Integration with External Systems
- Integrating QRadar SOAR with ServiceNow, Jira, Slack, email, and webhook-based systems
- Custom API integration with Threat Intelligence platforms
- Integrating EDR for automated endpoint actions
- Automating payload analysis (files, URLs, domains)
Market-Aligned Competencies: Security Orchestration, AI Automation and Response (SOAR), IBM QRadar SOAR, Playbook Automation, Runbook Design, Automated Incident Response Workflow Orchestration, API-Driven Security Automation, Threat Intelligence Integration, Incident Containment Automation, Automated Threat Analysis, ServiceNow Integration for Security, Ticketing System Automation, Endpoint Response Automation, Automated IP Blacklisting, Phishing Response Automation, Ransomware Response Automation
Module 7: QRadar Forensics, Network Forensics, and Data Analysis
This module examines QRadar Incident Forensics (QRIF) and forensic investigation capabilities, Network Forensics (NFI) for packet capture analysis, and forensic techniques used in incident investigation.
7.1 IBM QRadar Forensics (QRIF)
- QRIF: collecting and storing forensic data for investigations
- Forensic data sources: packet captures, event logs, and endpoint forensics
- Forensic analysis: reconstructing timelines, analyzing files, and performing network forensic analysis
- Preserving forensic evidence and maintaining chain-of-custody
- Using forensic analysis tools and techniques within QRIF
7.2 Network Forensics and Inspection (NFI)
- Network forensics: analyzing packet captures and inspecting network traffic
- Flow data analysis: utilizing NetFlow, sFlow, and IPFIX in QRadar Network Forensics
- Protocol analysis: inspecting HTTP, DNS, SMTP, SSH, FTP, and custom protocols
- Detecting threats through network forensics: identifying C2 beaconing, data exfiltration, and lateral movement
- Identifying suspicious traffic patterns
7.3 User and Entity Behavior Analytics (UEBA)
- UEBA: understanding user behavior baselines and detecting anomalies
- UEBA data sources: Active Directory, proxy logs, endpoint logs, DLP logs, authentication logs, and cloud logs
- UEBA scoring: calculating user and entity risk scores
- Using UEBA for threat detection: identifying compromised accounts, insider threats, and data exfiltration
Market-Aligned Competencies: QRadar Incident Forensics (QRIF), Forensic Data Collection, Forensic Investigation and Analysis, Network Forensics, Packet Capture Analysis, Flow Data Analysis, Threat Detection Through Network Forensics, User and Entity Behavior Analytics (UEBA), User Anomaly Detection, Insider Threat Detection, Compromised Account Detection, Data Exfiltration via User Behavior, C2 Beaconing Detection, Lateral Movement via Network Forensics, Digital Forensics and Incident Response (DFIR), Evidence Preservation and Chain of Custody, Protocol Analysis, Security Log Forensics, Threat Hunting via Network Analytics
Module 8: Cloud SIEM, SIEM-as-Code, Compliance, and SIEM Operations
This module evaluates IBM QRadar operations, scaling strategies, compliance reporting, cloud SIEM integration, detection-as-code practices, and SOC governance essential for enterprise-scale SIEM deployment.
8.1 QRadar Operations and Administration
- Administering QRadar: managing user roles, permissions, and security policies
- Auditing QRadar configurations and access logs
- Designing scheduled reports and custom reports for management and compliance
- Setting up scheduled tasks: backup/restore, database cleanup, and maintenance
- Configuring Syslog servers for SIEM log forwarding
- Managing software updates and patches for QRadar appliances
8.2 Compliance Reporting and Regulatory Mapping
- Meeting PCI DSS SIEM requirements and generating QRadar compliance reports
- Mapping compliance for HIPAA, GDPR, SOX, NIST CSF, and ISO 27001 using QRadar reports
- Regulatory audit reporting: creating custom report templates for PCI DSS and HIPAA auditors
- Implementing real-time compliance monitoring and continuous compliance dashboards
8.3 SIEM-as-Code and Infrastructure as Code
- Version-controlled SIEM rule management: deploying rules via Git
- Using Terraform and Ansible for QRadar appliance provisioning and configuration
- Implementing CI/CD pipelines for SIEM rules and playbooks
- Automating rule deployment and management via the QRadar API
8.4 Cloud SIEM and Hybrid Cloud Security
- Integrating cloud log sources: AWS CloudTrail, Microsoft Sentinel, GCP Audit Logs, and Azure Monitor
- Cloud-native SIEM strategies: implementing SIEM for SaaS environments (AWS, Azure, GCP, Office 365, AWS)
- Integrating SIEM with Microsoft Sentinel, Azure Sentinel, AWS CloudWatch Logs, and Google Cloud Logging
- Monitoring cloud identity and access: IAM, Active Directory, and Entra ID
- Integrating cloud workload protection with SIEM
8.5 Identity Threat Detection
- Identity as the new threat boundary: detecting account compromises
- Active Directory threat detection: identifying Kerberoasting, AS-REP roasting, and Golden/Silver ticket attacks
- Detecting Multi-factor authentication (MFA) bypass attempts
- Monitoring Privileged Identity Management (PIM)
8.6 Zero Trust Monitoring
- Monitoring Zero Trust architecture: covering identity, device, and network controls
- Validating Microsegmentation monitoring and policy enforcement
- Generating Zero Trust compliance reports via SIEM integration
8.7 SOC Operations and SIEM Governance
- Tracking SOC metrics and KPIs: including MTTR (Mean Time to Respond) and MTTD for SIEM monitoring
- Conducting SOC maturity assessments and driving SIEM-led SOC improvements
- SIEM governance: managing rules, tracking false positives, and ensuring continuous improvement
- Adhering to SIEM operational best practices: monitoring, alerting, and escalation procedures
Market-Aligned Competencies: QRadar Administration, SIEM Operations and Management, SIEM Compliance Management, PCI DSS SIEM Compliance Reporting, HIPAA and GDPR SIEM Compliance, SOX and ISO 27001 SIEM Compliance, NIST CSF SIEM Mapping, Continuous Compliance Monitoring, Custom Compliance Reporting, SIEM-as-Code and Infrastructure as Code, Terraform for SIEM, Ansible for SIEM Deployment, CI/CD for SIEM Rules, QRadar API Automation, Cloud SIEM Integration, AWS CloudTrail SIEM, Microsoft Sentinel Integration, GCP Cloud Logging SIEM, Azure Monitor SIEM, Office 365 SIEM Integration, Cloud-Native SIEM, Zero Trust Monitoring, IAM Threat Detection, Identity Threat Detection, Active Directory Threat Detection, Kerberos Attack Detection, Privileged Identity Monitoring, Multi-Factor Authentication (MFA) Security, SOC KPI and Metric Management, SOC Maturity Assessment, SIEM Operational Best Practices, Incident Response Governance, SIEM Rule Lifecycle Management, Enterprise SIEM Governance
Module 9: Capstone Project and Real-World Threat Scenarios
This module presents a comprehensive hands-on capstone project that simulates enterprise security scenarios, covering threat detection, investigation, and incident response using IBM QRadar.
9.1 Capstone Project: Enterprise Security Scenario
- Setting up a simulated enterprise environment with realistic log sources and attack scenarios
- Deploying log sources and configuring log collection policies
- Building detection rules mapped to the MITRE ATT&CK framework
- Investigating real-world offense data in QRadar and performing forensic analysis
- Designing and deploying SOAR playbooks for automated response
- Generating compliance reports for PCI DSS, HIPAA, and GDPR
- Performing capacity planning and scaling the SIEM deployment
9.2 Real-World Threat Scenarios
- Simulating attacks: ransomware deployment, insider threats, lateral movement, brute-force attacks, supply chain attacks, and phishing
- Detecting ransomware: identifying lateral movement, data staging, and other malicious activities
- Insider threats: detecting data exfiltration attempts and anomalies
- Supply chain attack detection: identifying compromised vendor access
- Phishing response: implementing automated URL blocking and email investigation workflows
- Zero-day threat hunting: detecting unknown threats using rule-less hunting techniques
- Advanced Persistent Threat (APT) detection using UEBA and forensic analysis
Market-Aligned Competencies: Capstone Security Project Delivery, Enterprise SIEM Simulation, Real-World Threat Scenario Design, MITRE ATT&CK Detection Rule Deployment, SOC Incident Investigation, QRadar SOAR Playbook Design, Ransomware Response Simulation, Insider Threat Detection, Phishing Response Automation, Supply Chain Attack Detection, Zero-Day Threat Hunting, Advanced Persistent Threat (APT) Detection, SIEM Capacity Planning and Scaling, Multi-Compliance Reporting (PCI DSS, HIPAA, GDPR), Enterprise Threat Response, Forensic Threat Investigation, Threat Intelligence Enrichment, Automated Incident Containment, SOC Operations Simulation, Full-Scale SIEM Engineering Practice
Requirements
- Fundamental understanding of IT security concepts
Target Audience
- Security Engineers