RSA Netwitness Logs & Network Analysis
What you'll learn
- Use the features and functions of RSA NetWitness Platform to to respond to and investigate incidents.
Requirements
- Fmiliarity with the basic processes of cybersecurity forensic analysis
- Knowledge of network architecture
- Knowledge of TCP/IP Stack
- Knowledge of integrating log & network traffic to perform analysis on network-based security events
Description
This course helps the students to use the features and functions of RSA NetWitness Platform to to respond to and investigate incidents. This course is for Level 1 and Level 2 analysts relatively new to RSA NetWitness Platform, who wish to increase their familiarity with the tool’s features and functions within the context of incident response and analysis. Students should have familiarity with the basic processes of cybersecurity forensic analysis, including some knowledge of network architecture, the TCP/IP stack, networking protocols, and integrating log & network traffic to perform analysis on network-based security events. Students should have taken the Foundation course prior to this course.
Upon successful completion of this course, participants should be able to:
Describe SOC roles and models
Describe the Investigative Methodology
Identify types of incidents
Describe the Incident Response process
Use analysis tools and techniques to investigate an incident
Document the incident
Use the incident response process and tools to investigate an incident using packets
Use the incident response process and tools to investigate an incident using logs
Use the incident response process and tools to investigate an incident using packets and endpoint
Use the incident response process and tools to investigate an incident using logs, packets and endpoint
Who this course is for:
- Level 1 and Level 2 analysts relatively new to RSA NetWitness Platform
- SOC Analysts
- Security Architects
- Security Consultants
- Security Engineers
Course content
- Preview14:36
- 05:052
- 01:303
- 06:404
- 04:275
Instructor
We are a group of professionals with over 15 years in IT GRC Training and consulting. Governance, Risk, and Compliance (GRC) is a company's strategy for managing corporate governance, enterprise risk management, and demonstrating corporate compliance. By using the GRC applications (Policy and Compliance, Risk, Audit, and Vendor Risk) GRC professionals create a scalable compliance program based on their organization's needs to meet internal and regulatory requirements.