SIEM with Tactical Analytics

Many organizations have logging capabilities but lack the people and processes to analyze them. In addition, logging systems collect vast amounts of data from a variety of data sources which require an understanding of the sources for proper analysis. This class is designed to provide training, methods, and processes for enhancing existing logging solutions. This class will also provide the understanding of the when, what, and why behind the logs. This is a lab-heavy course that utilizes SOF-ELK, a SANS-sponsored free SIEM solution, to train hands-on experience and provide the mindset for large-scale data analysis.

Course syllabus:

  1. SIEM Architecture

  2. Service Profiling with SIEM

  3. Advanced Endpoint Analytics

  4. Baselining and User Behavior Monitoring

  5. Tactical SIEM Detection and Post-Mortem Analysis

  6. Capstone: Design, Detect, Defend