Opleiding: Investigating Incidents with Splunk SOAR (IISS)

This 3.5 hour course prepares security practitioners to use SOAR to respond to security incidents, investigate vulnerabilities, and take action to mitigate and prevent security problems.

- SOAR concepts
- Investigations
- Running actions and playbooks
- Case management & workflows

Topic 1 – Starting Investigations


- SOAR investigation concepts
- ROI view
- Using the Analyst Queue
- Using indicators
- Using search
Topic 2 – Working on Events


- Use the Investigation page to work on events
- Use the heads-up display
- Set event status and other fields
- Use notes and comments
- How SLA affects event workflow
- Using artifacts and files
- Exporting events
- Executing actions and playbooks
- Managing approvals
Topic 3 – Cases: Complex Events


- Use case management for...

Meer...
€0
ex. BTW
Aangeboden door
Fast Lane
Onderwerp
Splunk
Niveau
Duur
1 dag
Looptijd
8 dagen
Type product
seminar
Lesvorm
Klassikaal
Tijdstip
Overdag
Keurmerken aanbieder
Lean IT
UWV scholingsvoucher
AWS Partner Network (APN)
BTW-vrijstelling
Cedeo
Cedeo Maatwerk
Cedeo Open
Cisco Authorized Learning Partners
CRKBO en BTW-vrijstelling
CRKBO zonder BTW vrijstelling