Get in Touch

Course Outline

Introduction to Blue Team Operations

  • An overview of the Blue Team and its critical role in cybersecurity
  • Assessing attack surfaces and understanding the evolving threat landscape
  • An introduction to key security frameworks, including MITRE ATT&CK, NIST, and CIS

Security Information and Event Management (SIEM)

  • Fundamentals of SIEM and log management
  • Installation and configuration of SIEM tools
  • Analyzing security logs to identify and detect anomalies

Network Traffic Analysis

  • Interpreting network traffic and performing packet analysis
  • Utilizing Wireshark for detailed packet inspection
  • Identifying network intrusions and suspicious activities

Threat Intelligence and Indicators of Compromise (IoCs)

  • Foundations of threat intelligence
  • Methods for identifying and analyzing IoCs
  • Advanced threat hunting techniques and industry best practices

Incident Detection and Response

  • The incident response lifecycle and relevant frameworks
  • Strategies for analyzing security incidents and containing threats
  • Basics of forensic investigation and malware analysis

Security Operations Center (SOC) and Best Practices

  • Exploring SOC structures and operational workflows
  • Automation of security tasks through scripts and playbooks
  • Fostering collaboration between Blue Team, Red Team, and Purple Team exercises

Summary and Next Steps

Requirements

  • A solid grasp of fundamental cybersecurity concepts
  • Proficiency in networking basics, including TCP/IP, firewalls, and IDS/IPS
  • Practical experience with both Linux and Windows operating systems

Target Audience

  • Security analysts
  • IT administrators
  • Cybersecurity professionals
  • Network defense specialists
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories