
Learn to monitor cyber security with Splunk SIEM, ingest logs from endpoints and network devices, build dashboards with SPL, and enable real-time alerts and incident response.
Explore Splunk siem deployment scenarios from single to distributed setups, using forwarders, indexers, and search heads across Linux, Windows, or Mac, with network devices and logs for security monitoring.
Explore the Splunk SIEM interface and core components, including dashboards, data inputs, indexers, forwarders, SPL, data models, and reports.
Learn to ingest data into Splunk SIEM by uploading logs from Windows, Linux, networks, cloud, and databases using forwarders and scripted inputs.
Explore spl processing language to ingest data, extract fields, and search with pipes, boolean filters, and charts to create real-time dashboards and insightful reports.
Create reports and dashboards in Splunk SIEM to present data effectively. Use search commands, event types, tags, and real-time visualizations to monitor data and configure security alerts for the SoC.
Discover how Splunk handles data ingestion from diverse source types, including Windows and Linux logs, firewall and Suricata alerts, and network activity to enable investigation.
Explore ransomware analysis with Splunk SIEM, focusing on alerts, endpoint investigations, IOC concepts, PowerShell activity, C2 servers, and incident response using Windows and Linux logs.
Analyze a compromised website scenario using Splunk SIEM to investigate defacement, identify attacker tactics, IOCs, and data exfiltration, and plan immediate response and recovery.
Explore a splunk siem ctf challenge titled boss of the soc v2, using datasets sv2 and try hack me, to analyze attack scenarios, emails, http and smtp events, espionage.
Analyze AWS investigation workflows with CloudTrail and CloudWatch logs, inspect IAM users and service activity, assess S3 bucket public access and PutBucketACL events, and MFA authentication in a TryHackMe lab.
مقدمة إلى الدورة:
في هذه الدورة المتكاملة أقدم لك شرح شامل عن استخدام السبلنك (SPLUNK SIEM) وأقسامه ومكوناته بالإضافة إلى شرح عملية إضافة البيانات ولغة البحث والمعالجة وإنشاء التقارير والتحليلات بالإضافة الى تطبيقات عملية في مجال الأمن السيبراني.
يمكن الانضمام الى هذه الدورة من دون أية معرفة مسبقة بالسبلنك. معرفة أساسية ببروتوكولات الشبكات (TCP,UDP,HTTP,DNS,DHCP,HTTPS,SMB) ستسهل عملية الفهم أكثر.
تتضمن الدورة ملفات ملحقة لتساعدك أكثر على فهم المبادئ المطروحة لضمان سهولة الاستيعاب.
ماذا ستتعلم بنهاية هذه الدورة؟
في نهاية هذه الدورة, ستكون قد أصبحت قادرا على استخدام السبلنك لتنفيذ مهام في مجال الأمن السيبراني أو مجال تحليل البيانات.
عدد ساعات الدورة:
مايقارب الست ساعات
محتويات الدورة:
- مقدمة الى سبلنك (Splunk SIEM)
- شرح الواجهة والأقسام (Splunk GUI)
- شرح سيناريوهات التنصيب ضمن الشبكة (Deployment Scenarios)
- شرح عملية إدخال البيانات الى السبلنك (Data Infegestion)
- شرح لغة المعالجة المستخدمة في عمليات البحث ومعالجة البيانات في السبلنك (Splunk Search Processing Language)
- شرح إنشاء التقارير واللوحات التحليلة لغرض عرض البيانات
- فهم أنواع مصادر البيانات التي يمكن معالجتها في السبلنك (Source Types)
- سيناريوهات عملية في استخدام السبلنك في مجال الأمن السيبراني:
- السيناريو الأول: تحليل برنامج الفدية
-السيناريو الثاني: تحليل موقع مخترق
- السيناريو الثالث والرابع: حل تحدي Boss of the SOC V2 & V3