
Explain why cybersecurity matters and how networks—from switches and DNS to domain controllers—work securely, with firewalls, proxies, antivirus, and log-based monitoring to detect and respond to incidents.
Discover how Siem architecture uses receiver, manager, and logger to collect logs, normalize data to a common format, and apply correlation rules for real-time threat detection, dashboards, and regulatory reporting.
Explore siem architecture by detailing the receiver that collects and normalizes logs before sending to the manager, across ArcSight, QRadar, Splunk, and McAfee iOS eic receivers.
Explore the siem architecture from the receiver to the manager, the rules engine, and correlation alerts, with enterprise security manager, event stream analysis, and splunk indexing.
Explore how loggers store and archive raw logs across event and system storage, applying retention and compression, with architectures from ArcSight, Splunk, McAfee, RSA Security Analytics, and IBM.
Explore ArcSight architecture from log ingestion through smart and flex connectors to ESM evaluation, core engine rule matching, and alert generation; access via command center, outside console, or web interface.
Explore RSA SA architecture for incident handling: decode network and log data, aggregate via concentrators and brokers, and generate alerts with RSA rules through advanced correlation.
Explore IBM architecture, a three-layer system: collect logs from collectors, process them with processors, and present a user interface console for searching, analyzing, and reporting.
Collect logs and forward them to Splunk, where data is indexed for searching, analyzing, reporting, and alerting on cyberattack, with the search head's graphical user interface for querying the index.
Explore how McAfee EIC extracts events and forwards them to ESM, where a correlation engine triggers alerts and stores data in E limb; learn vendor architectures and data sources integration.
Understand why integrating data sources with a siem system is essential. Learn how agents and syslog forwarders collect and index logs from firewalls, email servers, and endpoints using Splunk.
Explore types of siem installation and practical lab setup of Splunk Enterprise, Splunk Light, and Splunk Cloud, including Universal Forwarder deployment on Windows and Linux.
Install splunk enterprise on a windows machine by downloading the 64-bit installer, accepting the license, and completing the default setup to launch the web UI at localhost:8000.
Discover siem features in Splunk Enterprise, install on Windows, use the search and reporting app to query logs, manage data sources, and forward logs.
Install the Splunk universal forwarder on a 64-bit Windows machine, accept the agreement, and configure it to forward logs to the indexer using the IP address and port 9997.
Integrate and configure a Windows agent to forward system, application, and security logs to a Splunk instance, adjust inputs.conf, enable forwarding and receiving, and verify the logs in Splunk.
Install the universal forwarder on a Linux Debian machine and configure it to send autopsy logs to the Splunk instance.
Configure syslog input in a siem by enabling udp inputs, defining input settings, assigning host values, and indexing data for cloud and Splunk platform analysis.
Integrate a network device with Splunk by configuring the device and settings to forward logs to a Splunk index via the agent, and validate log delivery in the cloud.
Configure the agent on a Linux machine, forward logs to Splunk, verify the logs, and monitor the incoming logs.
Learn to build effective use cases for identifying compromised machines and network activity, guided by the use case lifecycle and Splunk Universal Forwarder deployment.
Master the development lifecycle for security use cases, from requirements and data points to log validation, design, implement, documentation, onboarding, and tooling, ensuring effective incident handling across security devices.
Phase 1 defines the use case requirements by identifying the scenario and notification needs, using a brute force attack example to design an alert for detection.
Identify data points and sources for use cases by collecting authentication and authorization logs from entry points, including Active Directory, Linux, and third-party apps.
Validate logs from field data sources, ensuring user name, IP address, station name, and machine line are captured; verify local and VPN authentication for secure remote access.
Design and implement SIEM use cases by defining log sources, triggers, and aggregation rules; prioritize alerts for failed logins, brute force attempts, and admin vs normal user accounts.
Onboard the usecase by fine-tuning the load in a pre-production phase and monitoring its behavior. Identify and eliminate false positives by analyzing daily triggers before moving to production.
Phase 8 updates use cases by refining rules after development phases and updating conditions for accounts and ip addresses during investigations, including whether to ignore or whitelist all.
Compare business and system use cases; map traffic flow and device inventory to create platform-specific rules, reducing Windows and Linux monitoring gaps.
Explore the seven stages of the cyber kill chain—reconnaissance through action on objective—and how defenders map attacker tools and techniques to detect intrusions, assess damage, and strengthen defenses.
Explore how reconnaissance targets by collecting information on IPs, domains, operating systems, applications, and company accounts, then weaponize with remote administration tools to infect and exploit vulnerabilities.
Delivery phase describes delivering a malicious email with an attachment and the subject important action exploitation, enabling remote code execution via Microsoft Office macros and backdoor installation for later access.
Explore command and control techniques and actions on objective, showing how compromised machines connect to attackers, receive commands, and enable data exfiltration, destruction, or encryption for further impact.
Define effective use cases to capture requirements and risk, and detect and prevent phishing and remote code execution, using real-time examples of email links, attachments, and Active Directory pivot risk.
Define an effective use case to alert on phishing by analyzing exchange logs and security device logs, including secure mail gateway events and indicators of compromise.
Map use cases to priority and impact based on privilege level, and align with kill chain stages to help analysts detect phishing, reconnaissance, and weaponization, and prepare defenses.
Define a practical use case with standard operating procedures for investigations, collect infection details and logs, and tune detection rules through continuous improvement and correlation adjustments.
Define an incident response plan (IRP) and an SLA to guide the six phases—preparation, identification, containment, medication, recovery—and lessons learned for SOC incident handling.
Auditing the incident handling process ensures analysts follow procedures, document findings, maintain logs and notes, and update case management to reduce business risk.
Evaluate siem capabilities with use cases to build a versatile sim that answers key questions about time, user identity, host and ip, event triggers, and log sources, and identify gaps.
Build real-world brute force detection use cases by defining business and system use cases, devices, and multi-condition rules across Windows, Linux, firewall, database, and email.
Learn to build real-world malware use cases that detect and isolate infections on single or multiple machines using antivirus data and logs across Windows and mobile devices.
Explore industry based use cases in Splunk fundamentals for incident handling by configuring universal forwarders, indexers, and searches to index logs and optimize searches across single or multiple indexes.
Learn to run Splunk searches across time ranges, select indexes, extract fields, identify authentication events, visualize results with tables, and build incident handling rules.
Explore Splunk alert manager for incident review and security posture analysis, configuring alerts from Windows security events in XML, and defining looks, roles, ownership, and real-time rules.
Learn to build a Splunk incident-handling use case by creating a port-scanning rule, ingesting firewall logs, parsing inputs, and configuring alerts with throttling.
Learn to monitor events with dashboards, fine-tune alerts by use case and severity, and guide incident response with a standard template and panel visibility.
THE MOST DEMANDING SIEM Online Training IS NOW ON UDEMY!
PHASE 2 - This course will make you familiar and teach you about various SIEM tools component, architecture, event life cycle and administration part for Splunk for log source integration, rule creation, report configuration, dashboard creation, fine tuning and Incident Handing steps followed by Security Operation Center Team.
This course is designed is such a way, that any beginner or any working professional can learn the below SIEM tools event flow, architecture, design & difference.
1) HP ArcSight
2) IBM QRadar
3) RSA Security Analytics
4) Splunk
5) McAfee Nitro
What you will learn after completing this course:
What is the SIEM
SIEM Business Requirement
SIEM Architecture of HP Arcsight, IBM QRadar, Splunk, RSA SA & McAfee Nitro
Event Life Cycle in SIEM Solution HP Arcsight, IBM QRadar, Splunk, RSA SA & McAfee Nitro
Roles of Different SIEM Component of HP Arcsight, IBM QRadar, Splunk, RSA SA & McAfee Nitro
Integration Configuration of Data sources [Splunk]
What is Cyber Kill Chain
How to develop effective USECASE in SIEM
How to Evaluate a SIEM tool
Building Industry Based Use Cases [Splunk]
Alert Creation in [Splunk]
Event Monitoring [Splunk]
Creating Dashboards for Attack Analysis [Splunk]
Report Configuration [Splunk]
Fine Tuning Of Alerts[Splunk]
Real World Incident Response Investigation [Splunk]
Happy Learning !