Course summary
This course is built for analysts who utilize the Elastic Security for SIEM solution. Elastic Security for SIEM walks you through the architecture behind the Elastic Stack, Fleet, and Elastic Agent. You will then learn how to create visualizations and dashboards and how to use Lens before diving into the Security App. Finally, you will conduct a threat hunting capstone exercise to tie everything together.
- Topics
- Audience
- Duration
- Pre-reqs
- Requirements
Topics
- Stack overview
- Elastic Common Schema (ECS)
- Discover
- Visualizations
- Dashboards
- Security App
- Hunt Capstone
Topics
- Stack overview
- Elastic Common Schema (ECS)
- Discover
- Visualizations
- Dashboards
- Security App
- Hunt Capstone
Audience
Duration
24 hours
Pre-Reqs
A basic understanding of:
Networking
- TCP/IP
- Common ports and protocols
- Common Networking devices (routers, switches, firewalls)
Common Network Monitoring Tools
- IDS (Suricata)
- Zeek
- Packet Capture tool
Operating Systems
- Windows and Linux
- File systems and permissions
- Command line navigation
Vulnerabilities and Exploit Methodology
- Reconnaissance
- Command and Control (C2)
- Data exfiltration
Requirements
- Stable internet connection (virtual classroom)
- Mac, Linux, or Windows
- Latest version of Chrome or Firefox (other browsers not supported)
- Disable any ad blockers and restart your browser before class
Course Details
Virtual
10:00 am - 5:00 pm
10:00 am - 5:00 pm
10:00 am - 5:00 pm
10:00 am - 5:00 pm
(America - New York Time Zone)
Sorry, This class is currently sold out. Please try another class, or contact us
Have a Question?
Please see our Training FAQ with any additional questions you may have. Have a question not answered in the FAQ? Contact us.