What You’ll Learn
  • You will be fully proficient in Cyber Security Incident Response processes.
  • You will learn to develop advanced rules in SIEM
  • EDR
  • and NIDS tools.
  • During an incident
  • you will be able to quickly develop analysis and detection rules
  • allowing for immediate intervention.
  • You will be able to learn and test the attack and defense commands of almost all the tactics and techniques of MITRE ATT&CK.

Requirements

  • Having completed my first course
  • the Blue Team Incident Handler training
  • will be quite beneficial.

Description

EN:

  • In the first part of our Cyber Security Blue Team: Incident Responder series, we will become fully proficient in Incident Response processes. We will explain and review each stage with examples. Then, we will write in-depth queries and rules at these stages. Specifically, we will learn to develop rules in Suricata, Sysmon, and Splunk for each technique in the MITRE ATT&CK Tactics and Techniques and will write many rules. Thanks to the training we received, you will be able to develop your own NIDS, SYSMON, and SIEM rules. On the other hand, we will understand all of the MITRE ATT&CK Tactics and Techniques and apply them in our Incident Response processes. We will examine the attack commands used in the MITRE ATT&CK Tactics and Techniques and develop our rules to detect these commands.

TR:

  • Cyber Security Blue Team : Incident Responder serimizin ilk bölümünde Incident Response süreçlerine tamamen hakim olacağız. Her bir aşamayı örneklerle açıklayıp inceleyeceğiz. Ardından bu aşamalarda derinlemesine sorgular ve kurallar yazacağız. Özellikle Suricata, Sysmon ve Splunk'da her bir teknik konularda olan MITRE ATT&CK Taktik ve Tekniğinde kurallar geliştirmeyi öğreneceğiz ve birçok kural yazacağız. Aldığımız eğitim sayesinde kendi NIDS, SYSMON ve SIEM kurallarını geliştirebileceksiniz. Bir yandan da MITRE ATT&CK Taktik ve Tekniklerin hepsini anlayacak ve Incident Response süreçlerimizde uygulayacağız. MITRE ATT&CK Taktik ve Tekniklerinde kullanılan saldırı komutlarını inceleyecek ve bu komutları tespit etmek için kurallarımızı geliştireceğiz.

ES:

  • En la primera parte de nuestra serie Cyber Security Blue Team: Incident Responder, nos volveremos completamente proficientes en los procesos de Respuesta a Incidentes. Explicaremos y revisaremos cada etapa con ejemplos. Luego, escribiremos consultas y reglas en profundidad en estas etapas. Específicamente, aprenderemos a desarrollar reglas en Suricata, Sysmon y Splunk para cada técnica en las Tácticas y Técnicas de MITRE ATT&CK y escribiremos muchas reglas. Gracias a la formación que recibimos, podrás desarrollar tus propias reglas NIDS, SYSMON y SIEM. Por otro lado, comprenderemos todas las Tácticas y Técnicas de MITRE ATT&CK y las aplicaremos en nuestros procesos de Respuesta a Incidentes. Examinaremos los comandos de ataque utilizados en las Tácticas y Técnicas de MITRE ATT&CK y desarrollaremos nuestras reglas para detectar estos comandos.

PT:

  • Na primeira parte da nossa série Cyber Security Blue Team: Incident Responder, nos tornaremos totalmente proficientes nos processos de Resposta a Incidentes. Explicaremos e revisaremos cada etapa com exemplos. Em seguida, escreveremos consultas e regras detalhadas nessas etapas. Especificamente, aprenderemos a desenvolver regras no Suricata, Sysmon e Splunk para cada técnica nas Táticas e Técnicas do MITRE ATT&CK e escreveremos muitas regras. Graças ao treinamento que recebemos, você poderá desenvolver suas próprias regras NIDS, SYSMON e SIEM. Por outro lado, compreenderemos todas as Táticas e Técnicas do MITRE ATT&CK e as aplicaremos em nossos processos de Resposta a Incidentes. Examinaremos os comandos de ataque usados nas Táticas e Técnicas do MITRE ATT&CK e desenvolveremos nossas regras para detectar esses comandos.

FR:

    • Dans la première partie de notre série Cyber Security Blue Team: Incident Responder, nous deviendrons pleinement compétents dans les processus de réponse aux incidents. Nous expliquerons et passerons en revue chaque étape avec des exemples. Ensuite, nous écrirons des requêtes et des règles approfondies à ces étapes. Plus précisément, nous apprendrons à développer des règles dans Suricata, Sysmon, et Splunk pour chaque technique dans les Tactiques et Techniques du MITRE ATT&CK et nous écrirons de nombreuses règles. Grâce à la formation que nous avons reçue, vous serez en mesure de développer vos propres règles NIDS, SYSMON, et SIEM. D'autre part, nous comprendrons toutes les Tactiques et Techniques du MITRE ATT&CK et les appliquerons dans nos processus de réponse aux incidents. Nous examinerons les commandes d'attaque utilisées dans les Tactiques et Techniques du MITRE ATT&CK et développerons nos règles pour détecter ces commandes.

RU:

    • В первой части нашей серии Cyber Security Blue Team: Incident Responder мы станем полностью профессионалами в процессах реагирования на инциденты. Мы объясним и рассмотрим каждый этап на примерах. Затем мы напишем глубокие запросы и правила на этих этапах. В частности, мы научимся разрабатывать правила в Suricata, Sysmon и Splunk для каждой техники в тактике и методах MITRE ATT&CK и напишем много правил. Благодаря полученному нами обучению, вы сможете разработать свои собственные правила NIDS, SYSMON и SIEM. С другой стороны, мы поймем все тактики и методы MITRE ATT&CK и применим их в наших процессах реагирования на инциденты. Мы изучим команды атаки, используемые в тактике и методах MITRE ATT&CK, и разработаем наши правила для их обнаружения.

HE:

  • בחלק הראשון של הסדרה שלנו צוות האבטחה הכחול: מגיב התקרית, נהפוך למיומנים בתהליכי תגובה לתקריתים. נסביר ונבחן כל שלב עם דוגמאות. לאחר מכן, נכתוב שאילתות מעמיקות וכללים בשלבים אלה. בפרט, נלמד לפתח כללים ב-Suricata, Sysmon, ו-Splunk לכל טכניקה בטקטיקות וטכניקות MITRE ATT&CK ונכתוב הרבה כללים. הודות להכשרה שקיבלנו, תוכלו לפתח את הכללים שלכם ל-NIDS, SYSMON, ו-SIEM. מצד שני, נבין את כל טקטיקות וטכניקות MITRE ATT&CK וניישם אותם בתהליכי התגובה שלנו לתקריתים. נבחן את פקודות ההתקפה המשמשות בטקטיקות וטכניקות MITRE ATT&CK ונפתח את הכללים שלנו לזיהוי פקודות אלה.

HI:

  • हमारी साइबर सुरक्षा नीली टीम: घटना प्रतिक्रियाकारी श्रृंखला के पहले हिस्से में, हम घटना प्रतिसाद प्रक्रियाओं में पूरी तरह से निपुण हो जाएंगे। हम हर चरण को उदाहरणों के साथ समझाएंगे और समीक्षा करेंगे। फिर, हम इन चरणों पर गहरी तरह से पूछ-ताछ और नियम लिखेंगे। विशेष रूप से, हम Suricata, Sysmon, और Splunk में प्रत्येक तकनीक के लिए MITRE ATT&CK तकनीक और तकतिक में नियम विकसित करना सीखेंगे और बहुत सारे नियम लिखेंगे। हमें प्राप्त प्रशिक्षण के कारण, आप अपने NIDS, SYSMON, और SIEM नियम विकसित कर पाएंगे। दूसरी ओर, हम MITRE ATT&CK तकनीक और तकतिक को समझेंगे और इसे हमारी घटना प्रतिसाद प्रक्रियाओं में लागू करेंगे। हम MITRE ATT&CK तकनीक और तकतिक में प्रयुक्त हमला कमांड्स को देखेंगे और इन कमांड्स को पता लगाने के लिए हमारे नियम विकसित करेंगे।

DE:

  • In dem ersten Teil unserer Serie 'Cyber Security Blue Team: Incident Responder' werden wir uns vollständig in den Prozessen der Incident Response auskennen. Wir werden jeden Schritt mit Beispielen erklären und überprüfen. Dann werden wir detaillierte Abfragen und Regeln für diese Schritte schreiben. Insbesondere werden wir lernen, Regeln in Suricata, Sysmon und Splunk für jede Technik in den Taktiken und Techniken von MITRE ATT&CK zu entwickeln und werden viele Regeln schreiben. Dank der Schulung, die wir erhalten haben, werden Sie in der Lage sein, Ihre eigenen NIDS, SYSMON und SIEM Regeln zu entwickeln. Auf der anderen Seite werden wir alle Taktiken und Techniken von MITRE ATT&CK verstehen und sie in unseren Incident Response Prozessen anwenden. Wir werden die Angriffsbefehle untersuchen, die in den Taktiken und Techniken von MITRE ATT&CK verwendet werden, und unsere Regeln entwickeln, um diese Befehle zu erkennen.

JA:

  • 私たちの「サイバーセキュリティブルーチーム:インシデントレスポンダーシリーズ」の最初の部分では、インシデントレスポンスのプロセスを完全に習得します。私たちは各ステージを例で説明し、レビューします。次に、これらのステージで詳細なクエリとルールを書きます。具体的には、MITRE ATT&CKのタクティクスとテクニックの各テクニックに対してSuricata、Sysmon、Splunkでルールを開発する方法を学び、多くのルールを書きます。私たちが受け取ったトレーニングのおかげで、自分自身のNIDS、SYSMON、およびSIEMのルールを開発することができます。一方、私たちはMITRE ATT&CKの全タクティクスとテクニックを理解し、インシデントレスポンスのプロセスでそれらを適用します。私たちは、MITRE ATT&CKのタクティクスとテクニックで使用される攻撃コマンドを調査し、これらのコマンドを検出するためのルールを開発します。


The topics and headings of our course.


  • Introduction

  • IR : Preparation and Analysis & Detection

    • Splunk SPL Language and Rule Development

    • MITRE ATT&CK Review

    • Defense-Oriented Review of MITRE ATT&CK

    • Suricata Rule Development

    • MITRE ATT&CK Reconnaissance - Splunk and Suricata Rule Development

    • MITRE ATT&CK Resource Development - Splunk and Suricata Rule Development

    • MITRE ATT&CK Initial Access - Splunk and Suricata Rule Development

    • MITRE ATT&CK Execution - Splunk and Suricata Rule Development

    • MITRE ATT&CK Persistence - Splunk and Suricata Rule Development

    • MITRE ATT&CK Privilege Escalation - Splunk and Suricata Rule Development

    • MITRE ATT&CK Defense Evasion - Splunk and Suricata Rule Development

    • MITRE ATT&CK Credential Access - Splunk and Suricata Rule Development

    • MITRE ATT&CK Lateral Movement - Splunk and Suricata Rule Development

    • MITRE ATT&CK Discovery - Splunk and Suricata Rule Development

    • MITRE ATT&CK Collection - Splunk and Suricata Rule Development

    • MITRE ATT&CK Exfiltration - Splunk and Suricata Rule Development

    • MITRE ATT&CK C&C (Command & Control) - Splunk and Suricata Rule Development

    • MITRE ATT&CK Impact - Splunk and Suricata Rule Development

    • SYSMON Review and Rule Development

  • IR : Containment, Eradication & Remediation and Lessons Learned

    • Containment

    • Eradication

    • Remediation

    • Lessons Learned


Who this course is for:

  • It is aimed at individuals who want to advance to a higher level in the Cyber Security Blue Team field.
Courses

Course Includes:

  • Price: FREE
  • Enrolled: 3572 students
  • Language: Turkish
  • Certificate: Yes

Recomended Courses

Wordpress (No Coding), Domain not Needed, within 3.5 hours
4.06
(196 Rating)
FREE

2024 - Learn The Complete Wordpress Within 3.5 Hours

Enrolled
The Best ChatGPT & AI Course: Make Money With AI
3.6578948
(222 Rating)
FREE

Learn ChatGPT and how to make passive income with free AI tools

Enrolled
Chatbot Creation with Generative AI: A Practical Guide
4.28
(87 Rating)
FREE

From Basics to Advanced: Mastering Chatbot Development with Generative AI Tools

Enrolled
AI Personal Branding: Secure High-Paying Jobs as a Student
4.4886365
(44 Rating)
FREE

Building Your Future with AI: From Classroom to Career

Enrolled
From Basics to Advanced: Data Analysis Using ChatGPT
4.5030866
(162 Rating)
FREE
Category
Marketing, Digital Marketing, Data Analysis
  • English
  • 5858 Students
From Basics to Advanced: Data Analysis Using ChatGPT
4.5030866
(162 Rating)
FREE

Unlock the Power of Generative AI: Simplify, Analyze, and Visualize Data Like Never Before

Enrolled
Professional Diploma in Corporate Management
4.39
(531 Rating)
FREE
Category
Business, Management, Management Skills
  • English
  • 21606 Students
Professional Diploma in Corporate Management
4.39
(531 Rating)
FREE

Professional Diploma in Corporate Management by MTF Institute

Enrolled
CRISPR Cas9 Technology
4.36
(63 Rating)
FREE
Category
Teaching & Academics, Science, Genetics
  • English
  • 2514 Students
CRISPR Cas9 Technology
4.36
(63 Rating)
FREE

CRISPR Cas9 Technology

Enrolled
Numpy For Data Science - Real Time Experience
4.44
(265 Rating)
FREE
Category
Development, Programming Languages, NumPy
  • English
  • 31898 Students
Numpy For Data Science - Real Time Experience
4.44
(265 Rating)
FREE

First step towards Python's Numpy Library

Enrolled
GIS Software & Application Online Course
4.51
(70 Rating)
FREE
Category
Teaching & Academics, Online Education,
  • English
  • 7285 Students
GIS Software & Application Online Course
4.51
(70 Rating)
FREE

Unraveling the World of GIS Software & Applications

Enrolled

Previous Courses

Cyber Security Blue Team: Incident Handler
4.76
(207 Rating)
FREE
Category
BT ve Yazılım, Ağ ve Güvenlik, Siber Güvenlik
  • Turkish
  • 2972 Students
Cyber Security Blue Team: Incident Handler
4.76
(207 Rating)
FREE

Blue Team prensiplerini, metodolojileri ve tekniklerini öğrenip siber savunma bilgi ve becerilerinizi geliştireceksiniz.

Enrolled
HTML 5,Python,Flask Framework All In One Complete Course
4.422727
(998 Rating)
FREE
Category
IT & Software, IT Certifications, Python
  • English
  • 114722 Students
HTML 5,Python,Flask Framework All In One Complete Course
4.422727
(998 Rating)
FREE

This is the complete course of HTML 5 with Python programming language and python framework Flask

Enrolled
Professional Diploma in Office Administration Management
4.0855265
(1526 Rating)
FREE
Category
Business, Management, Office Administration
  • English
  • 44191 Students
Professional Diploma in Office Administration Management
4.0855265
(1526 Rating)
FREE

Principles of work of Office Administrator. Required hard and soft skills. Introduction to MS Office and banking area

Enrolled
The Higher Self Blueprint: 21 Days of Self-Discovery
5.0
(1 Rating)
FREE

Daily Practices to Discover, Understand, and Embody Your True Self

Enrolled
Professional Diploma in Digitalization of Retail Banking
3.98
(376 Rating)
FREE

Digital at sales, cross-sale, loyalty increase and costs, risks decrease. Practical cases and profitability assessment

Enrolled
C# for Beginners
4.22
(142 Rating)
FREE
Category
Development, Software Engineering, C# (programming language)
  • English
  • 21424 Students
C# for Beginners
4.22
(142 Rating)
FREE

Learn C# - an introduction for total beginners

Enrolled
Advanced Certificate in Financial Analysis and Management
5.0
(2 Rating)
FREE

Financial Analysis and Management with concentration in Finance Business Partnership in IT, Startups, SAAS, Products

Enrolled
Computer Vision with Python
4.24
(142 Rating)
FREE
Category
Development, Software Engineering, Python
  • English
  • 18332 Students
Computer Vision with Python
4.24
(142 Rating)
FREE

Introduction to Computer Vision, make vision apps

Enrolled
Network Security: Scan Networks with Zenmap
4.4565215
(23 Rating)
FREE
Category
IT & Software, Network & Security, Network Security
  • English
  • 3968 Students
Network Security: Scan Networks with Zenmap
4.4565215
(23 Rating)
FREE

Learn to Scan and Secure Networks Easily with Zenmap

Enrolled

Total Number of 100% Off coupon added

Till Date We have added Total 1021 Free Coupon. Total Live Coupon: 939

Confuse which course 100% Off coupon live? Click Here

For More Update Join Our Telegram Channel.