Get in Touch

Course Outline

Foundations of Defensive Cyber Operations

  • Overview of defensive cybersecurity roles and responsibilities
  • Assessment of attack vectors and evolving threat environments
  • Familiarization with established security standards (MITRE ATT&CK, NIST, CIS)

Security Information and Event Management (SIEM)

  • Principles of SIEM architecture and centralized log management
  • Deployment and configuration of SIEM platforms
  • Log analysis techniques for anomaly detection

Network Traffic Analysis

  • Analysis of network traffic patterns and packet-level data
  • Utilization of Wireshark for deep packet inspection
  • Identification of unauthorized access and suspicious network behavior

Threat Intelligence and Indicators of Compromise (IoCs)

  • Introduction to strategic and tactical threat intelligence
  • Collection and evaluation of Indicators of Compromise
  • Proactive threat hunting methodologies for government entities

Incident Detection and Response

  • Structure and phases of the incident response lifecycle
  • Evaluation of security incidents and containment protocols
  • Fundamentals of digital forensics and malware analysis

Security Operations Center (SOC) and Operational Best Practices

  • Organizational structure and operational workflows of a SOC
  • Enhancing operational efficiency through automation and scripted playbooks
  • Interagency collaboration via Red Team and Purple Team exercises for government operations

Summary and Strategic Next Steps

Requirements

  • Foundational knowledge of cybersecurity principles
  • Competence in networking fundamentals (TCP/IP, firewalls, IDS/IPS)
  • Proficiency with Linux and Windows operating systems

Audience

  • Security analysts
  • IT administrators
  • Cybersecurity professionals
  • Network defenders
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories