Visão Geral
Este curso apresenta os fundamentos da atuação de um SOC Analyst, incluindo monitoramento, análise de alertas, investigação de eventos, triagem, threat intelligence, SIEM e resposta inicial a incidentes.
Conteúdo Programatico
Module 1: SOC Fundamentals
- Security Operations Center concepts
- SOC architecture
- SOC roles and responsibilities
- Security monitoring
- Alert management
- Incident lifecycle
- Security operations processes
- SOC metrics
- Escalation procedures
- SOC best practices
Module 2: Security Monitoring
- Network monitoring
- Endpoint monitoring
- Identity monitoring
- Application monitoring
- Cloud monitoring
- Security telemetry
- Log sources
- Event collection
- Monitoring coverage
- Monitoring architecture
Module 3: SIEM Fundamentals
- SIEM concepts
- Log ingestion
- Event normalization
- Event correlation
- Detection rules
- Alert generation
- Dashboards
- Search and investigation
- SIEM use cases
- SIEM operational workflow
Module 4: Alert Triage
- Alert classification
- False positives
- Alert prioritization
- Severity assessment
- Indicator validation
- Context enrichment
- Incident escalation
- Investigation notes
- Case management
- Triage workflow
Module 5: Threat Detection
- Indicators of compromise
- Indicators of attack
- Authentication anomalies
- Malware indicators
- Network anomalies
- Credential attacks
- Lateral Movement
- Persistence indicators
- MITRE ATT&CK
- Detection engineering fundamentals
Module 6: Incident Investigation
- Initial investigation
- Timeline construction
- Log correlation
- Endpoint investigation
- Network investigation
- Identity investigation
- Evidence collection
- Attack reconstruction
- Incident classification
- Investigation documentation
Module 7: Threat Intelligence
- Threat intelligence concepts
- Indicators
- Threat actors
- Campaigns
- Malware intelligence
- Intelligence enrichment
- IOC validation
- Intelligence-driven detection
- Threat intelligence platforms
- Intelligence reporting
Module 8: Practical SOC Operations
- Alert triage exercise
- Authentication investigation
- Malware alert investigation
- Network anomaly investigation
- Credential attack investigation
- SIEM investigation
- Incident escalation
- Evidence documentation
- SOC reporting
- Practical SOC case studies