Get in Touch

Course Outline

Module 1: SIEM Fundamentals, Architecture, and Ecosystem Overview

This module establishes a thorough understanding of SIEM (Security Information and Event Management) fundamentals, the IBM QRadar platform architecture, its integration within the broader ecosystem, and the wider security analytics landscape, including XDR, SOAR, and threat intelligence platforms.

1.1 Security Analytics and SIEM Foundations

  • The evolution of the SIEM landscape: from basic log management to advanced security analytics
  • Distinguishing SIEM, SOAR, and XDR: understanding the convergence of security tools
  • Core SIEM components: log collection, normalization, correlation, and alerting mechanisms
  • The SOC analyst workflow: covering detection, triage, investigation, and response
  • An overview of the MITRE ATT&CK framework and its application in SIEM mapping

1.2 IBM QRadar Platform Architecture

  • QRadar on-premises architecture: encompassing the Event Processor, Log Manager, Console, and Flow Processor
  • QRadar in the Cloud: multi-tenant architecture, ingestion models, and scalability features
  • QRadar Hybrid Cloud deployment: leveraging combined on-prem and cloud capabilities
  • Deployment options: Virtual Appliances, Hardware Appliances, and SaaS models
  • High Availability (HA) configurations: comparing Active-Passive vs. Active-Active setups

1.3 QRadar Components and Console Navigation

  • IBM QRadar Console: interface overview, workspaces, dashboards, and navigation structures
  • Complementary applications, the QRadar App Framework, and the IBM App Exchange
  • Context Explorer, Risk Analyzer, and threat intelligence integration features
  • The QRadar data model: defining Hosts, Devices, Protocols, and Categories

1.4 The QRadar Ecosystem

  • IBM QRadar SOAR: integrating security orchestration and automated response
  • IBM QRadar EDR: integrating endpoint detection and response capabilities
  • Threat Intelligence integration: utilizing VTI feeds and custom threat feeds
  • Interoperability with other SIEM tools: Splunk, Elastic SIEM, and IBM QRadar log source management

1.5 Integration with the IBM Security Suite

  • IBM QRadar SOAR integration for automation and playbook orchestration
  • IBM QRadar EDR integration for enhanced endpoint telemetry
  • Integration with IBM QRadar VTI (Vulnerability and Threat Intelligence)
  • Utilizing IBM QRadar App Exchange apps and add-ons
  • Integration with the IBM QRadar Network Integration Platform (NFI)

Market-Aligned Competencies: SIEM Fundamentals, Security Information and Event Management, IBM QRadar Platform Architecture, QRadar On-Prem Deployment, QRadar Cloud Architecture, Hybrid Cloud Security, SOC Operations and SIEM, Security Analytics, XDR Integration, SOAR Platform Integration, Threat Intelligence Platform (TIP), MITRE ATT&CK Framework Mapping, Security Tool Convergence, Enterprise Security Architecture, Log Management and Analytics, SIEM Scalability and Capacity Planning, High-Availability (HA) Configuration, QRadar Console Navigation and Configuration

Module 2: Log Source Management, Data Ingestion, and Normalization

This module provides an in-depth exploration of log source configuration, data collection strategies, log normalization, and essential protocols for establishing comprehensive enterprise security visibility across on-prem, cloud, and hybrid environments.

2.1 Log Source Configuration and Protocols

  • Log collection methods: Syslog (RSYSLOG), Network Connections (CEF), Common Event Format (CEF), and QRadar CEF
  • CEF protocol details: header structure, extension names, custom extensions, and CEF-to-CEF mapping
  • Network-based log collection: supporting NetFlow v5/v9 and IPFIX (sFlow)
  • Agent-based collection using the IBM QRadar Agent for enhanced endpoint visibility
  • Configuration for Active Directory, DNS, DHCP, HTTP, SMTP, and database log sources
  • Best practices for log source deployment: managing high-throughput sources, compression, and encryption

2.2 Data Ingestion and Capacity Planning

  • Understanding daily log file volume (GLP) and daily event data ingestion capacity
  • Implementing data retention policies and managing compliance-driven retention
  • Prioritizing log sources and filtering events to manage costs effectively
  • Capacity planning strategies for enterprise-scale SIEM deployments
  • Performing sizing calculations and optimizing performance in large-scale environments

2.3 Log Normalization and Classification

  • The QRadar Normalization Engine: mapping native log formats to QRadar protocols
  • Using the Log Source Property Manager for protocol mapping
  • Creating custom log sources for proprietary log formats
  • Mapping events, flows, and log sources
  • Applying normalization rules and troubleshooting parsing issues

Market-Aligned Competencies: Log Source Management, Syslog Configuration, CEF Protocol, Network Connections (CEF), QRadar Agent Deployment, Active Directory Log Collection, DNS and DHCP Log Collection, HTTP/S and SMTP Log Collection, Database Log Collection (CEF) Integration, NetFlow and IPFIX Collection, Agentless SIEM Deployment, Enterprise Log Collection Strategy, Log Normalization, Protocol Mapping, Custom Log Source Configuration, Event Parsing and Classification, Daily Log Volume (DLV) Estimation, SIEM Capacity Planning, Performance Tuning for Large-Scale SIEM, Compliance-Driven Data Retention

Module 3: Detection, Correlation, and Rule Development

Central to SIEM operations, this module focuses on the construction, testing, and management of detection rules, ranging from simple event rules to complex compound correlation rules that identify attacks, anomalies, and policy violations.

Central to SIEM operations, this module focuses on the construction, testing, and management of detection rules, ranging from simple event rules to complex compound correlation rules that identify attacks, anomalies, and policy violations.

3.1 Event Rules and Aggregation Rules

  • Event Rules: filtering data, extracting fields, and creating custom attributes from raw events
  • Aggregation Rules: counting and grouping events by IP, protocol, user, and other criteria
  • Aggregation rule actions: managing notifications, counter thresholds, and custom properties
  • Managing rule activation, ordering, and execution logic

3.2 Compound Correlation Rules

    • Constructing compound correlation rules: joining data from multiple sources
      • Rule types: Event, Aggregation, and Compound Correlation
      • Compound rule components: defining triggers, aggregations, correlations, and actions
      • Correlation logic: implementing temporal, threshold, and contextual correlation
      • Prediction and correlation rule properties: setting confidence levels, severity, and escalation paths
      • Writing effective correlation rules: minimizing alert fatigue while ensuring signal quality

3.3 Detection Rules for MITRE ATT&CK Techniques

      • Rules mapped to MITRE ATT&CK techniques: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control (C2), Exfiltration
      • Developing custom detections for specific attack categories:
      • Rules for: Brute Force, Port Scanning, Malware Communication, Insider Threat, Lateral Movement, Privilege Escalation, Data Exfiltration, Command-and-Control (C2)
      • Rules for: Brute-Force Authentication Failures, Port Scanning, SQL Injection, DNS Tunneling, Privilege Escalation, Lateral Movement via Pass-the-Hash

3.4 Threat Hunting with QRadar Rules

      • Applying proactive threat hunting methodologies using QRadar
      • Creating rules for detecting unknown or zero-day threats
      • Implementing behavior analysis and baseline deviation detection rules

Market-Aligned Competencies: Event Rule Development, Aggregation Rule Creation, Compound Correlation Rule Development, Custom Correlation Rule Design, MITRE ATT&CK Mapping, Threat Detection Engineering, Attack Technique Mapping (Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration), Malware Communication Detection, SQL Injection Detection, DNS Tunneling Detection, Privilege Escalation Rule, Brute Force Detection, Lateral Movement Detection, Insider Threat Detection, Data Exfiltration Detection, Command-and-Control (C2) Detection, Alert Fatigue Management, Rule Tuning and Optimization, SOC Detection Rule Engineering, Proactive Threat Hunting

Module 4: QRadar Offense Engine and Incident Investigation

This module provides a detailed examination of the QRadar offense engine, covering offense creation, investigation workflows, context analysis, false positive management, triage, and comprehensive incident handling.

4.1 The Offense Engine

  • Managing offense creation, aggregation, and lifecycle
  • Configuring offense properties: severity, confidence, status, and attribution
  • Offense aggregation logic: grouping related events into meaningful incidents
  • Managing offense escalation, assignment, and workflows

4.2 Incident Investigation and Context Analysis

  • Using the Context Explorer for deep event analysis and timeline reconstruction
  • Performing event timeline analysis: chronological reconstruction of security incidents
  • Conducting IP address analysis and reputation enrichment via Threat Intel
  • Analyzing user and asset context: user activity, host inventory, and asset risk assessment
  • Reviewing correlation events within offense and event detail views
  • Executing event correlation, grouping, and evidence gathering

4.3 Threat Intelligence Integration

  • Integrating Vulnerability and Threat Intelligence (VTI) feeds
  • Implementing automated threat intelligence enrichment with IBM QRadar VTI
  • Uploading custom threat feeds and defining threat actor profiles
  • Incorporating threat intelligence context into offenses and risk analysis

4.4 False Positive Management and Rule Tuning

  • Identifying and classifying false positives within the Offense Engine
  • Implementing false positive suppression rules and workflows
  • Tuning rules: reducing noise while maintaining detection sensitivity
  • Documenting false positive incidents to drive continuous improvement

Market-Aligned Competencies: QRadar Offense Engine Management, Incident Investigation and Analysis, Threat Investigation, Context Explorer Usage, Event Timeline Analysis, IP Reputation Analysis, Asset Risk Analysis, Threat Intelligence Enrichment, VTI Feed Integration, False Positive Management, Alert Tuning and Noise Reduction, SOC Incident Response Workflow, Security Incident Life Cycle, Compromise Indicator Analysis, Cyber Threat Attribution

Module 5: QRadar Vulnerability Management (QVM) and Risk Manager (QRM)

This module offers a deep dive into IBM QVM, covering vulnerability scanning integration, risk-based vulnerability prioritization, risk management configurations, and risk-driven security posture assessment.

5.1 IBM QRadar Vulnerability Manager (QVM)

  • QVM architecture: integrating with Nessus, Qualys, and Rapid7 scanners
  • Managing vulnerability scanning workflows and scan scheduling
  • Parsing vulnerability assessment results and integrating them with QRadar
  • Correlating CVSS scores and classifying vulnerability severity
  • Conducting vulnerability trend analysis and prioritizing remediation

5.2 IBM QRadar Risk Manager (QRM)

  • QRM architecture: understanding the risk calculation engine and scoring methodology
  • Configuring risk rules: assessing asset criticality, vulnerability exploitation likelihood, and asset risk profiles
  • Calculating risk scores: combining vulnerability data, threat intel, offense data, and asset value
  • Ranking assets by risk and configuring risk dashboards
  • Prioritizing assets and remediation efforts based on risk

Market-Aligned Competencies: Vulnerability Assessment and Management, IBM QRadar Vulnerability Manager (QVM), CVE Score Correlation, Vulnerability Scanning Integration, Qualys/Nessus Integration, Risk-Based Vulnerability Prioritization, IBM QRadar Risk Manager (QRM), Risk Score Calculation, Asset Criticality Assessment, Risk-Driven Remediation, Risk Dashboard Configuration, Vulnerability Trend Analysis, Enterprise Vulnerability Management, Enterprise Risk Assessment and Management

Module 6: QRadar SOAR, Automation, and Incident Response

This module covers IBM QRadar SOAR (Security Orchestration, Automation, and Response), focusing on playbook orchestration, runbook automation, and incident response automation critical for modern SOC operations.

6.1 IBM QRadar SOAR Overview

  • Defining and valuing security orchestration and automated response
  • Examining QRadar SOAR architecture and components: playbooks, incidents, automation actions, and data actions
  • Integrating QRadar SOAR: connecting SIEM, EDR, threat intelligence, and ticketing systems (ServiceNow, Jira)
  • Comparing SOAR to traditional automation: focusing on playbook-driven workflow orchestration

6.2 Playbook Design and Execution

  • Creating playbooks: building automated investigation and response workflows
  • Setting playbook triggers: offense creation, rule triggers, and manual activation
  • Defining playbook actions: enriching IP addresses, blocking IPs, creating tickets, and querying threat feeds
  • Implementing playbook conditions and branching logic

6.3 Incident Response Automation

  • Automating incident response: moving from alert to containment in minutes
  • Executing automated threat hunting: playbook-driven threat investigation
  • Automating incident containment: IP blocking, endpoint isolation, and account suspension
  • Developing automated response workflows for ransomware, phishing, brute-force attacks, and insider threats

6.4 Integration with External Systems

  • Integrating QRadar SOAR with ServiceNow, Jira, Slack, email, and webhook-based systems
  • Establishing custom API integrations with Threat Intelligence platforms
  • Integrating EDR for automated endpoint actions
  • Automating payload analysis (files, URLs, domains)

Market-Aligned Competencies: Security Orchestration, AI Automation and Response (SOAR), IBM QRadar SOAR, Playbook Automation, Runbook Design, Automated Incident Response Workflow Orchestration, API-Driven Security Automation, Threat Intelligence Integration, Incident Containment Automation, Automated Threat Analysis, ServiceNow Integration for Security, Ticketing System Automation, Endpoint Response Automation, Automated IP Blacklisting, Phishing Response Automation, Ransomware Response Automation

Module 7: QRadar Forensics, Network Forensics, and Data Analysis

This module addresses QRadar Incident Forensics (QRIF) and forensic investigation capabilities, network forensics (NFI) for packet capture analysis, and forensic analysis techniques applied in incident investigation.

7.1 IBM QRadar Forensics (QRIF)

  • QRIF: collecting and storing forensic data for investigations
  • Identifying forensic data sources: packet captures, event logs, and endpoint forensics
  • Performing forensic analysis: timeline reconstruction, file analysis, and network forensic analysis
  • Preserving forensic evidence and maintaining chain-of-custody
  • Utilizing forensic analysis tools and techniques within QRIF

7.2 Network Forensics and Inspection (NFI)

  • Network forensics: analyzing packet captures and inspecting network traffic
  • Analyzing flow data: utilizing NetFlow, sFlow, and IPFIX in QRadar Network Forensics
  • Protocol analysis: inspecting HTTP, DNS, SMTP, SSH, FTP, and custom protocols
  • Detecting threats via network forensics: identifying C2 beaconing, data exfiltration, and lateral movement
  • Identifying suspicious traffic patterns

7.3 User and Entity Behavior Analytics (UEBA)

  • UEBA: understanding user behavior baselines and detecting anomalies
  • UEBA data sources: Active Directory, proxy logs, endpoint logs, DLP logs, authentication logs, and cloud logs
  • UEBA scoring: calculating user risk scores and entity risk scores
  • UEBA-driven threat detection: identifying compromised accounts, insider threats, and data exfiltration

Market-Aligned Competencies: QRadar Incident Forensics (QRIF), Forensic Data Collection, Forensic Investigation and Analysis, Network Forensics, Packet Capture Analysis, Flow Data Analysis, Threat Detection Through Network Forensics, User and Entity Behavior Analytics (UEBA), User Anomaly Detection, Insider Threat Detection, Compromised Account Detection, Data Exfiltration via User Behavior, C2 Beaconing Detection, Lateral Movement via Network Forensics, Digital Forensics and Incident Response (DFIR), Evidence Preservation and Chain of Custody, Protocol Analysis, Security Log Forensics, Threat Hunting via Network Analytics

Module 8: Cloud SIEM, SIEM-as-Code, Compliance, and SIEM Operations

This module evaluates IBM QRadar operations, scaling, compliance reporting, cloud SIEM integration, detection-as-code practices, and SOC governance essential for enterprise-scale SIEM deployment.

8.1 QRadar Operations and Administration

  • Administering QRadar: managing user roles, permissions, and security policies
  • Auditing QRadar configurations and access logs
  • Designing scheduled reports and custom reports for management and compliance
  • Scheduling tasks: backup/restore, database cleanup, and maintenance
  • Configuring Syslog servers for SIEM log forwarding
  • Managing software updates and patching for QRadar appliances

8.2 Compliance Reporting and Regulatory Mapping

  • Meeting PCI DSS SIEM requirements and generating QRadar compliance reports
  • Mapping HIPAA, GDPR, SOX, NIST CSF, and ISO 27001 compliance using QRadar reports
  • Producing regulatory audit reports: custom report templates for PCI DSS and HIPAA auditors
  • Implementing real-time compliance monitoring and continuous compliance dashboards

8.3 SIEM-as-Code and Infrastructure as Code

  • Managing version-controlled SIEM rules: Git-based rule deployment
  • Using Terraform and Ansible for QRadar appliance provisioning and configuration
  • Implementing CI/CD pipelines for SIEM rules and playbooks
  • Leveraging QRadar API-driven automation for rule deployment and management

8.4 Cloud SIEM and Hybrid Cloud Security

  • Integrating cloud log sources: AWS CloudTrail, Microsoft Sentinel, GCP Audit Logs, and Azure Monitor
  • Adopting cloud-native SIEM strategies: SIEM for SaaS environments (AWS, Azure, GCP, Office 365, AWS)
  • Integrating with Microsoft Sentinel, Azure Sentinel, AWS CloudWatch Logs, and Google Cloud Logging
  • Monitoring cloud identity and access: IAM, Active Directory, and Entra ID
  • Implementing cloud workload protection and SIEM integration

8.5 Identity Threat Detection

  • Recognizing identity as the new threat boundary: detecting account compromises
  • Detecting Active Directory threats: Kerberoasting, AS-REP roasting, and Golden/Sid ticket attacks
  • Detecting Multi-factor authentication (MFA) bypass attempts
  • Monitoring Privileged Identity Management (PIM)

8.6 Zero Trust Monitoring

  • Monitoring Zero Trust architecture: covering identity, device, and network controls
  • Validating Microsegmentation monitoring and policy enforcement
  • Generating Zero Trust compliance reports via SIEM integration

8.7 SOC Operations and SIEM Governance

  • Tracking SOC metrics and KPIs: MTTR (Mean Time to Respond) and MTTD for SIEM monitoring
  • Assessing SOC maturity and driving SIEM-based SOC improvements
  • Governing the SIEM: managing rules, tracking false positives, and ensuring continuous improvement
  • Adopting SIEM operational best practices: monitoring, alerting, and escalation procedures

Market-Aligned Competencies: QRadar Administration, SIEM Operations and Management, SIEM Compliance Management, PCI D SIEM Compliance Reporting, HIPAA and GDPR SIEM Compliance, SOX and ISO 27001 SIEM Compliance, NIST CSF SIEM Mapping, Continuous Compliance Monitoring, Custom Compliance Reporting, SIEM-as-Code and Infrastructure as Code, Terraform for SIEM, Ansible for SIEM Deployment, CI/CD for SIEM Rules, QRadar API Automation, Cloud SIEM Integration, AWS CloudTrail SIEM, Microsoft Sentinel Integration, GCP Cloud Logging SIEM, Azure Monitor SIEM, Office 365 SIEM Integration, Cloud-Native SIEM, Zero Trust Monitoring, IAM Threat Detection, Identity Threat Detection, Active Directory Threat Detection, Kerberos Attack Detection, Privileged Identity Monitoring, Multi-Factor Authentication (MFA) Security, SOC KPI and Metric Management, SOC Maturity Assessment, SIEM Operational Best Practices, Incident Response Governance, SIEM Rule Lifecycle Management, Enterprise SIEM Governance

Module 9: Capstone Project and Real-World Threat Scenarios

This comprehensive hands-on capstone simulates enterprise security scenarios, including threat detection, investigation, and incident response using IBM QRadar.

9.1 Capstone Project: Enterprise Security Scenario

  • Setting up a simulated enterprise environment with realistic log sources and attack scenarios
  • Deploying log sources and configuring log collection policies
  • Building detection rules mapped to the MITRE ATT&CK framework
  • Investigating real-world offense data in QRadar and performing forensic analysis
  • Designing and deploying SOAR playbooks for automated response
  • Generating compliance reports for PCI DSS, HIPAA, and GDPR
  • Performing capacity planning and scaling the SIEM deployment

9.2 Real-World Threat Scenarios

  • Simulating attacks: ransomware deployment, insider threats, lateral movement, brute-force attacks, supply chain attacks, and phishing
  • Detecting ransomware: identifying lateral movement, data staging, and propagation
    • Addressing insider threats: detecting data exfiltration attempts and anomalies
    • Detecting supply chain attacks: identifying compromised vendor access
    • Responding to phishing: implementing automated URL blocking and email investigation workflows
  • Hunting zero-day threats: detecting unknown threats using rule-less hunting techniques
  • Detecting Advanced Persistent Threats (APTs) using UEBA and forensic analysis

Market-Aligned Competencies: Capstone Security Project Delivery, Enterprise SIEM Simulation, Real-World Threat Scenario Design, MITRE ATT&CK Detection Rule Deployment, SOC Incident Investigation, QRadar SOAR Playbook Design, Ransomware Response Simulation, Insider Threat Detection, Phishing Response Automation, Supply Chain Attack Detection, Zero-Day Threat Hunting, Advanced Persistent Threat (APT) Detection, SIEM Capacity Planning and Scaling, Multi-Compliance Reporting (PCI DSS, HIPAA, GDPR), Enterprise Threat Response, Forensic Threat Investigation, Threat Intelligence Enrichment, Automated Incident Containment, SOC Operations Simulation, Full-Scale SIEM Engineering Practice

Requirements

  • A foundational understanding of IT security principles

Target Audience

  • Security Engineers
 14 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories