Curso SOC Analyst Fundamentals

  • Redes & Infraestrutura de TI

Curso SOC Analyst Fundamentals

24h
Visão Geral

Este curso apresenta os fundamentos da atuação de um SOC Analyst, incluindo monitoramento, análise de alertas, investigação de eventos, triagem, threat intelligence, SIEM e resposta inicial a incidentes.

Objetivo

Após realizar este curso, você será capaz de:

  • Analisar alertas de segurança
  • Investigar eventos e logs
  • Realizar triagem de incidentes
  • Utilizar conceitos básicos de SIEM
Publico Alvo
  • Analistas de SOC
  • Profissionais de Cybersecurity
  • Analistas de infraestrutura
  • Iniciantes em Blue Team
Pre-Requisitos
  • Conhecimentos básicos de redes
  • Familiaridade com Windows e Linux
  • Noções de segurança da informação
  • Conhecimentos básicos de logs
  • Noções de TCP/IP
Conteúdo Programatico

Module 1: SOC Fundamentals

  1. Security Operations Center concepts
  2. SOC architecture
  3. SOC roles and responsibilities
  4. Security monitoring
  5. Alert management
  6. Incident lifecycle
  7. Security operations processes
  8. SOC metrics
  9. Escalation procedures
  10. SOC best practices

Module 2: Security Monitoring

  1. Network monitoring
  2. Endpoint monitoring
  3. Identity monitoring
  4. Application monitoring
  5. Cloud monitoring
  6. Security telemetry
  7. Log sources
  8. Event collection
  9. Monitoring coverage
  10. Monitoring architecture

Module 3: SIEM Fundamentals

  1. SIEM concepts
  2. Log ingestion
  3. Event normalization
  4. Event correlation
  5. Detection rules
  6. Alert generation
  7. Dashboards
  8. Search and investigation
  9. SIEM use cases
  10. SIEM operational workflow

Module 4: Alert Triage

  1. Alert classification
  2. False positives
  3. Alert prioritization
  4. Severity assessment
  5. Indicator validation
  6. Context enrichment
  7. Incident escalation
  8. Investigation notes
  9. Case management
  10. Triage workflow

Module 5: Threat Detection

  1. Indicators of compromise
  2. Indicators of attack
  3. Authentication anomalies
  4. Malware indicators
  5. Network anomalies
  6. Credential attacks
  7. Lateral Movement
  8. Persistence indicators
  9. MITRE ATT&CK
  10. Detection engineering fundamentals

Module 6: Incident Investigation

  1. Initial investigation
  2. Timeline construction
  3. Log correlation
  4. Endpoint investigation
  5. Network investigation
  6. Identity investigation
  7. Evidence collection
  8. Attack reconstruction
  9. Incident classification
  10. Investigation documentation

Module 7: Threat Intelligence

  1. Threat intelligence concepts
  2. Indicators
  3. Threat actors
  4. Campaigns
  5. Malware intelligence
  6. Intelligence enrichment
  7. IOC validation
  8. Intelligence-driven detection
  9. Threat intelligence platforms
  10. Intelligence reporting

Module 8: Practical SOC Operations

  1. Alert triage exercise
  2. Authentication investigation
  3. Malware alert investigation
  4. Network anomaly investigation
  5. Credential attack investigation
  6. SIEM investigation
  7. Incident escalation
  8. Evidence documentation
  9. SOC reporting
  10. Practical SOC case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas