Introduction
Course overview
()
1. Monitoring and Intake for Tier 1 Analysts
Module overview
()
Monitoring security events
()
Automated detection methods
()
Internal detection methods
()
External detection methods
()
Incident intake
()
Alert triage
()
The alert triage process
()
Alert triage at Cymbal Federal
()
Alert triage best practices
()
Data collection
()
Data categorization
()
Impact assessment
()
Tier 1 remediation actions
()
A phishing attack at Cymbal Federal is fully resolved in Tier 1
()
A phishing attack at Cymbal Federal is escalated to Tier 2
()
Support processes
()
ServiceNow tickets
()
Collaborating with other Tier 1 analysts
()
Support processes at Cymbal Federal
()
Module review
()
2. Incident Response for Tier 2 Analysts
Module overview
()
Incident response for Tier 2
()
Reception of an escalated incident ticket
()
Review of an escalated ticket
()
Ticket management with ServiceNow
()
An escalated ticket at Cymbal Federal
()
Incident investigation
()
Data correlation during investigation
()
Key sources for data correlation
()
Data correlation at Cymbal Federal
()
Incident analysis during investigation
()
System analysis strategies
()
System analysis at Cymbal Federal
()
Malware analysis strategies
()
Malware analysis at Cymbal Federal
()
Network traffic analysis strategies
()
Network traffic analysis at Cymbal Federal
()
Key points about incident investigation
()
Remediation of an incident
()
Containing a malware outbreak at Cymbal Federal
()
Containing a malware outbreak at Cymbal Federal
()
Remediation of a DDoS attack at Cymbal Federal
()
Key points on containment and remediation
()
The recovery process
()
Recovery from a DDoS attack at Cymbal Federal
()
Report on an incident
()
Postmortem for a malware attack at Cymbal Federal
()
Postmortem for a malware attack at Cymbal Federal
()
Support processes for escalation and collaboration
()
Common questions on support processes
()
Module review
()
3. Runbooks in Action: Predefined Incident Response Processes for Tier 1 and Tier 2 Analysts
Module overview
()
Introduction to coded guidelines
()
Incident response plans, playbooks, and runbooks
()
Determining ownership assignment
()
Determining impact severity
()
Runbooks in SecOps
()
Runbooks for Tier 2 incident response
()
Runbooks for containment, remediation, and recovery
()
Runbooks for post-incident actions
()
Common runbooks for GDC
()
Runbooks at Cymbal Federal
()
Module review
()
Ex_Files_SecOps_on_Google.zip
(112 KB)