SIEM/SOC Intermediate / NS107

FIVE   |   SIX   |   85%   |   40

                SCENARIOS               LABS                HANDS-ON           DURATION

Those responsible for the initial triage of an incident are the SOC analysts and incident responders; This course covers the necessary skills and practices to train such SOC personnel and successfully operate a modern-day SOC. The training starts from a broad understanding of the various functions in a SOC and a thorough workout on its technologies, up to a real-time hands-on practice in a virtual simulation environment.

LAB 01

Networking

LAB 02

Windows and Linux Firewalls

LAB 03

Monitoring

LAB 04

IDS and IPS Terminology

LAB 05

PfSense

LAB 06

Framework

Scenario: SCCA001

During the coronavirus, medical research university suffered a data breach. Criminal groups seek to exploit the crisis for financial gain. We need to track down their actions to understand what was stolen. Our tech engineer captured the network traffic during the attack; you have the task to solve the incident.

photo_2020-04-14_13-00-53.jpg

Scenario: SCCA002

Recently a large insurance company called VitaLife has suffered a severe breach. The SOC team who worked on that breach that day are still investigating the scene. You have been asked to filter through those logs to find the possible cause of the attack.

photo_2020-05-01_16-53-34.jpg

Scenario: SCCA003

Information about 60% of the US population was exposed to what is believed to be the largest ever known exposure. The IT department found an unsecured server, which is now under in-depth investigation by your team. The company using your services to investigate the server that held a large amount of that data to mitigate this issue.

photo_2020-05-21_17-40-52.jpg

Scenario: SCCA004

Financial company in Asia suffered from a Ransomware attack, which made them pay $1 million in bitcoin, to restore encrypted files. They hired you as a specialist to help them find any tracks. The SOC team was able to monitor some of that traffic that might contain valuable information related to the attack.

photo_2017-09-18_09-39-42.jpg

Scenario: SCCA005

A company suspects it has been attacked and needs your help to find and tracked down activities of a new group of financially-motivated hackers that are targeting several businesses and organizations in Germany.

photo_2020-03-29_22-17-38.jpg

© 2020 by ThinkCyber

THE 2020

CYBERIUM