Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Incident Handling & Response: SOC 3.0 Operations & Analytics

via INE

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates

The focus of the Practical Incident Handling course is to educate you on the techniques, tactics, and procedures that modern adversaries use, as well as teach you how to detect them. Now, it is time to scale things up… The SOC 3.0 Operations & Analytics Section first introduces you to the world of SIEM so you can become comfortable with working with some of the most effective and open-source SIEM solutions. You will then witness how common protocol analytics can greatly increase your network visibility in an attempt to detect abnormal and probably malicious actions at scale. Endpoint analytics are up next, covering the most important logs/events, correlation strategies and SIEM queries that you can leverage to detect adversaries on your network and endpoints. As usual, modules will be accompanied by hands-on labs, where you will be tasked with detecting real-world attacks and malware. As this section progresses, you will also see how tactical threat intelligence and adversary simulation can help you upgrade your detection capabilities.

This course is part of the Incident Handling & Response Professional Learning path which prepares you for the eCIR exam and certification

Taught by

Dimitrios Bougioukas

Reviews

Start your review of Incident Handling & Response: SOC 3.0 Operations & Analytics

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.