Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
SOC & DFIR: From Setup to Investigation - Arabic
Rating: 3.8 out of 5(6 ratings)
47 students

SOC & DFIR: From Setup to Investigation - Arabic

Learn how to to deploy your SOC, and detect the infected machines finally add your new rules with new IOCs.
Created byGeno Hamdan
Last updated 3/2025
Arabic
Arabic [Auto],

What you'll learn

  • 1. Introduction to SIEM Solutions & Full Lifecycle Process (Theoretical Overview) - Arabic
  • 2. Understanding Key Security Concepts: NOC, SOAR, DLP, XDR, TI, IR, DF, Honeypots and more - Arabic
  • 3. Deploying SIEM: Installing and configuring Elastic Stack (Elasticsearch, Logstash, Kibana) - Arabic
  • 4. Installing SIEM Agents on Windows - Arabic
  • 5. Installing SIEM Agents on Linux - Arabic
  • 6. Log Forwarding & Collection: IIS & Apache Web Server Logs Windows Defender & Antivirus Logs, Sysmon & Security Event Logs, Active Directory Logs - Arabic
  • 7. Building Dashboards in Elasticsearch (Kibana) for Log Visualization - Arabic
  • 8. Creating and Managing SIEM Rules: Static Detection Rules, Behavioral-based Detection & Anomaly Detection - Arabic
  • 9. Understanding Key SIEM Concepts: Log Aggregation Event Correlation & Normalization, Noise Reduction & Tuning False Positives - Arabic
  • 10. Hands-on: Writing and Optimizing Elasticsearch Queries - Arabic
  • 11. Incident Handling & Case Management: Building a strong Incident Response case, Analyzing attack patterns in SIEM, Writing investigation reports - Arabic
  • 12. Practical Labs: Real-world log analysis scenarios - Arabic
  • 13. Understanding the Full Lifecycle of Incident Response & Digital Forensics - Arabic
  • 14. Memory Forensics: Acquiring RAM dumps using various tools (WinPMEM, DumpIt) - Arabic
  • 15. Disk Forensics: Acquiring disk images with FTK Imager, dd, and other tools - Arabic
  • 16. Working with Sysinternals & Eric Zimmerman's Forensic Tools - Arabic
  • 17. RAM Analysis: Investigating memory dumps with Volatility and MemProcFS, Extracting malicious processes, injected code, and artifacts - Arabic
  • 18. Disk Image Analysis: Investigating acquired disk images with Autopsy & Sleuth Kit, Recovering deleted files and extracting forensic artifacts - Arabic
  • 19. Writing a Comprehensive DFIR Report: Proper documentation of forensic findings, Creating an evidence-based attack timeline - Arabic
  • 20. . Hands-on Labs: Disk Image Forensics: Extracting artifacts from compromised machines ,Memory Forensics: Investigating malware-infected RAM dumps - Arabic

Course content

6 sections25 lectures16h 4m total length
  • Introduction and talking about Syllabus7:52

Requirements

  • Well understanding of networks, Active Directory.
  • Basic knowledge of RED Team Attacks.
  • Basic knowledge with Linux and Windows commands

Description

في هذا الكورس، سننطلق في رحلة شيّقة لاستكشاف عالم محلل الأمن السيبراني والاستجابة للحوادث والبحث الجنائي الرقمي.

سنبدأ من الصفر، نتعرف على المصطلحات الأساسية، وننزل الأنظمة، ونبني اللابات الخاصة بنا، حتى نصمم سيناريوهات هجمات حقيقية ونحللها بطرق احترافية.

سنتعلم كيفية تحليل الـ SOC وفهم الهجمات من منظور محلل أمني، متابعة السجلات، استخراج الأنماط المشبوهة، والتحقيق في الحوادث السيبرانية بشكل استباقي. لن يكون الأمر نظريًا فقط، بل سنتعمق في الأدوات العملية التي يستخدمها المحترفون في هذا المجال مثل SIEM Solution with Elastic.

ومن ثم سنعمل على كيفية ارسال logs من الاجهزة المرتبطة بالشركة الى ال management elastic

وبناء الRULES الخاصة بنا

وبعد إتقان التحليل الأمني، سننتقل إلى التحليل الجنائي الرقمي. سنتعلم كيفية التعامل مع الأجهزة المصابة، استخراج الملفات الخبيثة، وتحليلها لاكتشاف طبيعة الهجوم. سنتعامل مع أدوات متقدمة مثل Volatility وWireshark وAutopsy لتحليل الذاكرة والملفات والنشاطات المشبوهة.

بالإضافة إلى ذلك، سنناقش كيفية توثيق نتائج التحقيقات، كتابة التقارير الاحترافية، وعرض النتائج بطريقة تسهل على الفرق الأمنية اتخاذ القرارات المناسبة. كما سنتعرف على أحدث التهديدات والهجمات وأساليب التحقيق الحديثة.

هذا الكورس عملي بنسبة كبيرة، حيث سنعمل على حالات حقيقية وسيناريوهات من الواقع، مما يجهزك لسوق العمل ويمكّنك من التصدي للهجمات السيبرانية وتحليلها باحترافية. سيكون التركيز على تطوير مهارات حقيقية تساعدك في بناء مستقبل قوي في مجال الأمن السيبراني والاستجابة للحوادث. ستكتسب خبرة عملية تجعلك مميزًا بين المتخصصين في هذا المجال.

Who this course is for:

  • Beginner to medium level for who wants to understand SOC and DFIR for Real world