Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Cisco Stealthwatch: Look Deep Into Networks
Rating: 3.3 out of 5(19 ratings)
101 students

Cisco Stealthwatch: Look Deep Into Networks

Scan and mitigate attacks
Created byMoiz Kareem
Last updated 8/2022
English
English [Auto],

What you'll learn

  • Scanning networking with Stealthwatch
  • Defending Organization with Stealthwatch
  • Mitigating cyberattacks with stealthwatch
  • Policies to get notified when breached

Course content

1 section • 15 lectures • 5h 53m total length
  • Introduction to Cisco Stealthwatch Technology42:53

    In this video you will learn about stealthwatch technology and overview of it.

  • Stealthwatch Installation1:00:18

    Install Stealthwatch management console, flow collector, and flow sensor by uploading ISO images to iSCSI and deploying on ESXi with Linux, meeting RAM and datastore requirements for a successful setup.

  • Stealthwatch GUI15:29
  • Configure Router For NetFlow Collector Part -119:24

    Configure routers and switches for NetFlow collection, create flow records with matching traffic, export to the NetFlow collector, and set up ingress monitoring and switch span for Stealthwatch.

  • Configure Router For NetFlow Collector Part -28:41

    Configure router for NetFlow collection by defining a flow record, exporter to the flow collector on port 2055, and monitor; apply input on inside interfaces and output on others.

  • Edit Config of SMC37:08

    Learn how to configure stealthwatch via centralized management, troubleshoot NetFlow collectors, and manage DNS, certificate trust, and SSH access, including the shift to centralized data storage.

  • Configure Policies on Stealthwatch40:30

    Master policy management in Stealthwatch by editing default baseline policies, creating custom events, and configuring alarms to detect relationship, core, and anomaly events across inside networks.

  • Install Applications in Stealthwatch4:54
  • AD integration with Stealthwatch Config4:57

    Learn to deploy and configure Active Directory integration with Stealthwatch using ldap, including setting host, port 389, base with DC values, and handling authentication events and potential configuration errors.

  • Configure SMC with Java Client29:17
  • Configuring Host Policy with Java Client12:27

    Configure a host policy with the Java client to detect ICMP ping, isolate the source for a set duration using a high concern index, then automatically resume traffic.

  • NetFlow Collector Packet Capture8:27

    Learn how to verify NetFlow collector traffic with packet capture, view appliance statistics, and troubleshoot by ensuring reachability and realistic traffic duration.

  • PxGrid Introduction21:00

    Pxgrid introduction explains how ISE enables cross-platform exchange with FMC and Stealthwatch by sharing security group tags and policy context, enabling adaptive network control and threat-centric NAC policies.

  • PxGrid Certificate Template3:44
  • PxGrid LAB44:25

    Learn how to configure pxgrid integration between Cisco ISE and Stealthwatch, including root certificate deployment, CSR generation, and pxgrid certificate provisioning, plus ANC policy governance with security group tags.

Requirements

  • CCNA

Description

Detect attacks across the dynamic network with high-fidelity alerts enriched with context such as user, device, location, timestamp, and application. Analyze encrypted traffic for threats and compliance, without decryption. Quickly detect unknown malware, insider threats like data exfiltration, policy violations, and other sophisticated attacks using advanced analytics. Store telemetry data for long periods for forensic analysis. Define smarter segmentation policies without disrupting the business. Create custom alerts to detect any unauthorized access and ensure compliance. Use Secure Network Analytics with Identity Services Engine (ISE) to enforce policies and contain threats.

Challenges:

Protecting a variety of sensitive member data and financial assets

Being able to prove audit requirements and ensure other internal business and security policies are being enforced

Monitor a distributed network spread across 22 branches and multiple ATM locations

Maintaining a first-class security strategy and infrastructure with a lean team

Solutions:

● Secure Network Analytics (Stealthwatch)

● Identity Services Engine (ISE)

● Secure Firewall (Firepower)

● Secure Endpoint (AMP for Endpoints)

● Umbrella

● Secure Email (Cloud Email Security)

● AnyConnect

● Secure Malware Analytics (Threat Grid)


Results

● Unprecedented threat visibility with actionable alerts infused with context

● Ability to easily prove audit requirements like cryptographic compliance, and to monitor for any business or security policy violations with custom alerts

● Achieved automated detection and response across the network, endpoints and web, and extended investments with an integrated security architecture

● Transitioned to a remote workforce without compromising on security and infrastructure uptime

Who this course is for:

  • security specialist, security auditors, cybersecurity specialist, network engieers, system engineers, security admins