
Want to learn more? Check out my full Detection Engineering course here:
Part 1: https://www.udemy.com/course/detection-engineering-masterclass-part-1/?referralCode=FE6EF7B50369EABD9D7D
Part 2: https://www.udemy.com/course/detection-engineering-masterclass-part-2/?referralCode=FAA917F067D365EDDAF0
This video will provide a high level summary of what to expect from this course.
This video covers the concepts behind SIEM technology.
Install the ossim sensor on a Debian-based VM with a 15 GB disk. Configure host-only networking with promiscuous mode to mirror traffic and verify connectivity to the server.
Configure the OSSIM server and sensor, set hostnames, and add data source plugins to parse logs. Connect sensors to the central server using IPs and enable a promiscuous interface.
Install Kali Linux by importing a preconfigured appliance, adjust resources, update packages, configure network settings, and prepare a host-only lab environment for a security analyst SIEM home lab.
By the end of this free course, you'll have a functioning home security lab, complete with a:
Security Incident Event Managements System
Intrusion Detection System
Hacking Machine
Target Machine
You will also know how to setup AlienVault's OSSIM (Open Source Security Information and Event Management) from the ground up!
This lab environment is great for a resume or portfolio site, understanding SIEM technology, and developing skill to be a stand out analyst. Whether you're just trying to learn or already have a job in a Security Operations Center, a home lab is the best way to get hands on skills.
For any questions or course requests, feel free to reach out to me directly via my profile page.
Thanks for checking out my AlienVault course! This course is getting a bit outdated. You will get a lot more out of my new course here: https://www.udemy[.]com/course/detection-engineering-masterclass-part-1/?referralCode=FE6EF7B50369EABD9D7D
Excerpt from that course description: "This course will first teach the theory behind security operations and detection engineering. We’ll then start building out our home lab using VirtualBox and Elastic’s security offering. Then we’ll run through three different attack scenarios, each more complex than the one prior. We’ll make detections off of our attacks, and learn how to document our detections. Next we’ll dive more into coding and Python by writing validation scripts and learning out to interact with Elastic through their API. Wrapping everything up, we’ll host all our detections on GitHub and sync with Elastic through our own GitHub Action automations. As a cherry on top, we’ll have a final section on how to write scripts to gather important metrics and visualizations."