
Explore CrowdStrike for SOC analysts with an overview of the console. Learn to triage detections from start to finish using the next-gen SIM, log scale, and the CrowdStrike query language.
Configure your console with UTC time, auto sign-in, and a preferred theme. Bookmark Investigate Advanced Event Search for quick access, and manage subscriptions and modules from the left menu.
Learn to navigate the CrowdStrike console overview for SOC analysts, set UTC and preferences, review detections and crowd score, and leverage investigate, advanced event search, and the sandbox.
Focus your time in the CrowdStrike console as a SOC analyst by reviewing monitor data and incidents, monitoring quarantine actions, and using investigate, configure, and intel tools.
Navigate the CrowdStrike console to triage endpoint detections and incidents with filters and grouping, review quarantined files, and use investigate, hunt, sandbox, and Kql-powered raw logs for in-depth analysis.
Triage detections in CrowdStrike using the detection dashboard, filters, and group by views to gauge severity quickly. Examine endpoint logs and KQL to confirm true positives and decide containment actions.
Triages a detection on an endpoint, analyzing host details, the Sublime Text process, an eicar test file write, and incident workbench insights in CrowdStrike.
Explore open source intelligence tools for malware analysis, including VirusTotal, Any.run, Joe Sandbox, Hybrid Analysis, and Shodan, plus domain and whois lookups to support SOC root-cause investigations.
Explore CrowdStrike's next gen sim and kcl for advanced endpoint log searches, build repeatable base queries, group and visualize results, format timestamps to utc, and export data for investigations.
Explore how CrowdStrike's advanced event search uses the CrowdStrike query language to query and visualize endpoint logs, filter by time and host, build dashboards, and export results.
Demonstrates real-time response in CrowdStrike, triaging detections, evaluating true positives, and using live shell commands, file transfers, and script execution to analyze and contain threats like mimikatz.
Explore CrowdStrike's sandbox for malware analysis and submitting samples. Implement blocking actions via IOC management, host firewall rules, and regex-based blocks to enforce detections.
Detonate a sample executable in a CrowdStrike sandbox, analyze dynamic and static indicators, and implement blocking with IOC management, domain and hash controls, and custom EOA rule groups.
Learn to configure CrowdStrike exclusions by adding machine learning and IOA based whitelists, plus sensor visibility exclusions, to balance detections with reduced false positives while preserving visibility.
Compare IOA-based exclusions with machine learning based exclusions in CrowdStrike, and learn to create, test, and apply them using glob syntax.
Triaging a detection in module nine, this lecture uses an alert template and UTC reporting to identify mimikatz indicators on a Windows 11 workstation. It covers quarantining, blocking hashes, containment.
Identify practical next steps after this course by pursuing CrowdStrike EDR certification or threat hunter and analyst certs, exploring Splunk Core certs and SIEM exposure, and hands-on incident response tools.
Module 1: Console Overview Get acquainted with the CrowdStrike console, your command center for proactive threat detection and incident response. Explore its interface, functionalities, and navigation to ensure a solid foundation for the rest of the course.
Module 2: Where to Spend Your Time Learn to prioritize effectively in a dynamic threat landscape. Understand the critical areas of focus within the CrowdStrike console to optimize your time and as it pertains to SOC work.
Module 3: Triaging a Detection Master the art of rapid detection triage. Develop skills to assess the severity of a detection, determine its scope, and decide on appropriate immediate actions.
Module 4: Useful Open Source Tools to Use Discover a curated toolkit of open-source resources that complement the CrowdStrike platform. Explore how to leverage these tools to enhance your threat intelligence and investigative capabilities.
Module 5: Event Search / CQL Delve into advanced event search techniques and learn how to craft powerful queries in CQL. Learn how to conduct host analysis and leveraging endpoint logs to your advantage.
Module 6: Real-Time Response Features Equip yourself with CrowdStrike's real-time response arsenal. Dive into containment strategies, remote actions, scripting, and other instant response capabilities.
Module 7: Sandbox & Blocking Actions Explore the CrowdStrike sandbox environment and understand its role in threat analysis. Learn to implement blocking actions effectively to halt threats in their tracks.
Module 8: Whitelisting / Exclusions Navigate the nuances of whitelisting and exclusions. Gain insights into striking the right balance between security and operational efficiency.
Module 9: Putting It All Together Immerse yourself in realistic scenarios where you'll apply your newfound knowledge. Walk through end-to-end incident response processes, from detection to resolution.
Module 10: Where to Go Next Chart your future course in the realm of cybersecurity. Discover avenues for continued learning, specialization, and skill refinement to stay ahead in the ever-evolving threat landscape.