Course Outline
Module 1: SIEM Fundamentals, Architecture, and Ecosystem Overview
Provides a comprehensive foundation in Security Information and Event Management (SIEM) principles, the IBM QRadar platform architecture, ecosystem integration capabilities, and the broader security analytics landscape, including Extended Detection and Response (XDR), Security Orchestration, Automation, and Response (SOAR), and Threat Intelligence Platforms.
1.1 Security Analytics and SIEM Fundamentals
- The evolution of SIEM from log management to advanced security analytics
- Differentiating SIEM, SOAR, and XDR: understanding the convergence of security tools for government
- Core SIEM components: log collection, normalization, correlation, and alerting mechanisms
- SOC analyst workflows: detection, triage, investigation, and response protocols
- Overview of the MITRE ATT&CK framework and its application in SIEM rule mapping
1.2 IBM QRadar Platform Architecture
- QRadar on-premises architecture: Event Processor, Log Manager, Console, and Flow Processor roles
- QRadar on Cloud: multi-tenant architecture, ingestion models, and scalability features
- QRadar Hybrid Cloud deployment strategies: integrating on-premises and cloud capabilities
- Deployment options: Virtual Appliances, Hardware Appliances, and SaaS offerings
- High Availability (HA) configurations: Active-Passive versus Active-Active setups
1.3 QRadar Components and Console Navigation
- IBM QRadar Console interface overview: workspaces, dashboards, and navigation structures
- Complementing Apps, the QRadar App Framework, and IBM App Exchange resources
- Utilizing Context Explorer, Risk Analyzer, and threat intelligence integration tools
- Data model fundamentals: Hosts, Devices, Protocols, and Categories within QRadar
1.4 The QRadar Ecosystem
- IBM QRadar SOAR: integrating security orchestration and automated response
- IBM QRadar EDR: implementing endpoint detection and response capabilities
- Threat Intelligence integration: leveraging VT feeds and custom threat data sources
- Integration with external SIEM tools, including Splunk, Elastic SIEM, and IBM QRadar for log source management
1.5 Integration with IBM Security Suite
- IBM QRadar SOAR integration for automation and playbook orchestration workflows
- IBM QRadar EDR integration for comprehensive endpoint telemetry
- IBM QRadar VTI (Vulnerability and Threat Intelligence) integration capabilities
- Utilizing IBM QRadar App Exchange applications and add-ons
- Integration with the IBM QRadar Network Integration Platform (NFI)
Market-Aligned Competencies: SIEM Fundamentals, Security Information and Event Management, IBM QRadar Platform Architecture, On-Premises Deployment, Cloud Architecture, Hybrid Cloud Security, SOC Operations, Security Analytics, XDR Integration, SOAR Platform Integration, Threat Intelligence Platform (TIP), MITRE ATT&CK Framework Mapping, Security Tool Convergence, Enterprise Security Architecture, Log Management and Analytics, SIEM Scalability and Capacity Planning, High-Availability (HA) Configuration, Console Navigation and Configuration
Module 2: Log Source Management, Data Ingestion, and Normalization
Examines log source configuration, data collection strategies, log normalization techniques, and critical protocols necessary for establishing enterprise-wide security visibility across on-premises, cloud, and hybrid environments.
2.1 Log Source Configuration and Protocols
- Log collection methods: Syslog (RSYSLOG), Network Connections (CEF), Common Event Format (CEF), and QRadar-specific CEF implementations
- CEF protocol structure: header formats, extension names, custom extensions, and CEF-to-CEF mapping
- Network-based log collection: NetFlow v5/v9 and IPFIX (sFlow)
- Agent-based collection via the IBM QRadar Agent for enhanced endpoint visibility
- Configuration of Active Directory, DNS, DHCP, HTTP, SMTP, and database log sources
- Deployment best practices for high-throughput sources, including compression and encryption standards
2.2 Data Ingestion and Capacity Planning
- Evaluating daily log file volume (GLP) and daily event data ingestion capacity requirements
- Data retention policies aligned with compliance-driven retention management strategies
- Log source prioritization and event filtering to optimize operational costs for government
- Capacity planning methodologies for enterprise-scale SIEM deployments
- Sizing calculations and performance optimization techniques for large-scale environments
2.3 Log Normalization and Classification
- The QRadar Normalization Engine: mapping native log formats to standard QRadar protocols
- Utilizing the Log Source Property Manager for protocol mapping
- Creating custom log sources for proprietary data formats
- Mapping events, flows, and log sources within the system
- Applying normalization rules and troubleshooting parsing issues
Market-Aligned Competencies: Log Source Management, Syslog Configuration, CEF Protocol, Network Connections (CEF), QRadar Agent Deployment, Active Directory Log Collection, DNS and DHCP Log Collection, HTTP/S and SMTP Log Collection, Database Log Collection Integration, NetFlow and IPFIX Collection, Agentless SIEM Deployment, Enterprise Log Collection Strategy, Log Normalization, Protocol Mapping, Custom Log Source Configuration, Event Parsing and Classification, Daily Log Volume (DLV) Estimation, SIEM Capacity Planning, Performance Tuning for Large-Scale SIEM, Compliance-Driven Data Retention
Module 3: Detection, Correlation, and Rule Development
Focusing on the core operational aspects of SIEM: constructing, testing, and managing detection rules ranging from simple event filters to complex compound correlation rules that identify attacks, anomalies, and policy violations.
Focusing on the core operational aspects of SIEM: constructing, testing, and managing detection rules ranging from simple event filters to complex compound correlation rules that identify attacks, anomalies, and policy violations.
3.1 Event Rules and Aggregation Rules
- Event Rules: filtering raw events, extracting fields, and creating custom attributes
- Aggregation Rules: counting and grouping events by parameters such as IP, protocol, and user
- Aggregation rule actions: configuring notifications, counter thresholds, and custom properties
- Rule activation logic, ordering priorities, and execution sequences
3.2 Compound Correlation Rules
- Constructing compound correlation rules by joining data from multiple sources
- Rule types: Event, Aggregation, and Compound Correlation definitions
- Compound rule components: triggers, aggregations, correlations, and actions
- Correlation logic: temporal, threshold-based, and contextual correlation methods
- Prediction and correlation rule properties: managing confidence levels, severity, and escalation paths
- Writing effective correlation rules to mitigate alert fatigue and ensure signal quality
3.3 Detection Rules for MITRE ATT&CK Techniques
- Rules mapped to MITRE ATT&CK techniques: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control (C2), and Exfiltration
- Custom detections for specific attack categories:
- Detection rules for Brute Force, Port Scanning, Malware Communication, Insider Threat, Lateral Movement, Privilege Escalation, Data Exfiltration, and Command-and-Control (C2)
- Detection rules for Brute-Force Authentication Failures, Port Scanning, SQL Injection, DNS Tunneling, Privilege Escalation, and Pass-the-Hash Lateral Movement
3.4 Threat Hunting with QRadar Rules
- Methodologies for proactive threat hunting using QRadar
- Developing rules for the detection of unknown or zero-day threats
- Establishing behavior analysis and baseline deviation detection rules
Market-Aligned Competencies: Event Rule Development, Aggregation Rule Creation, Compound Correlation Rule Development, Custom Correlation Rule Design, MITRE ATT&CK Mapping, Threat Detection Engineering, Attack Technique Mapping (Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration), Malware Communication Detection, SQL Injection Detection, DNS Tunneling Detection, Privilege Escalation Rule, Brute Force Detection, Lateral Movement Detection, Insider Threat Detection, Data Exfiltration Detection, Command-and-Control (C2) Detection, Alert Fatigue Management, Rule Tuning and Optimization, SOC Detection Rule Engineering, Proactive Threat Hunting
Module 4: QRadar Offense Engine and Incident Investigation
Detailed coverage of the QRadar offense engine, including offense creation, investigation workflows, context analysis, false positive management, triage procedures, and incident handling protocols.
4.1 The Offense Engine
- Offense creation, aggregation logic, and lifecycle management
- Offense properties: severity, confidence, status, and attribution fields
- Aggregation logic for grouping related events into coherent incidents
- Offense escalation, assignment procedures, and workflow management
4.2 Incident Investigation and Context Analysis
- Utilizing Context Explorer for deep event analysis and timeline reconstruction
- Analyzing event timelines to chronologically reconstruct security incidents
- IP address analysis and reputation enrichment using Threat Intelligence
- User and asset context: analyzing user activity, host inventory, and risk profiles
- Correlating events within offense and event detail views
- Gathering evidence through event correlation and grouping
4.3 Threat Intelligence Integration
- Integrating Vulnerability and Threat Intelligence (VTI) feeds
- Automated threat intelligence enrichment via IBM QRadar VTI
- Managing custom threat feed uploads and threat actor profiles
- Applying threat intelligence context to offenses and risk analysis
4.4 False Positive Management and Rule Tuning
- Identifying and classifying false positives within the Offense Engine
- Implementing false positive suppression rules and workflows
- Tuning rules to reduce noise while maintaining detection sensitivity
- Documenting false positive incidents for continuous process improvement
Market-Aligned Competencies: QRadar Offense Engine Management, Incident Investigation and Analysis, Threat Investigation, Context Explorer Usage, Event Timeline Analysis, IP Reputation Analysis, Asset Risk Analysis, Threat Intelligence Enrichment, VTI Feed Integration, False Positive Management, Alert Tuning and Noise Reduction, SOC Incident Response Workflow, Security Incident Life Cycle, Compromise Indicator Analysis, Cyber Threat Attribution
Module 5: QRadar Vulnerability Management (QVM) and Risk Manager (QRM)
Comprehensive examination of IBM QVM, including vulnerability scanning integration, risk-based prioritization, configuration strategies for risk management, and risk-driven security posture assessments.
5.1 IBM QRadar Vulnerability Manager (QVM)
- QVM architecture: integration with Nessus, Qualys, and Rapid7 scanners
- Workflow management for vulnerability scanning and scheduling
- Parsing vulnerability assessment results and integrating them into QRadar
- Correlating CVSS scores with vulnerability severity classifications
- Analyzing vulnerability trends and prioritizing remediation efforts
5.2 IBM QRadar Risk Manager (QRM)
- QRM architecture: risk calculation engine and scoring methodology
- Risk rule configuration: defining asset criticality, exploitation likelihood, and risk profiles
- Calculating risk scores by combining vulnerability data, threat intelligence, offense data, and asset value
- Ranking assets based on risk and configuring risk dashboards
- Prioritizing remediation efforts using risk-driven methodologies
Market-Aligned Competencies: Vulnerability Assessment and Management, IBM QRadar Vulnerability Manager (QVM), CVE Score Correlation, Vulnerability Scanning Integration, Qualys/Nessus Integration, Risk-Based Vulnerability Prioritization, IBM QRadar Risk Manager (QRM), Risk Score Calculation, Asset Criticality Assessment, Risk-Driven Remediation, Risk Dashboard Configuration, Vulnerability Trend Analysis, Enterprise Vulnerability Management, Enterprise Risk Assessment and Management
Module 6: QRadar SOAR, Automation, and Incident Response
Covers IBM QRadar SOAR (Security Orchestration, Automation, and Response), focusing on playbook orchestration, runbook automation, and incident response automation critical for modern SOC operations.
6.1 IBM QRadar SOAR Overview
- Defining security orchestration and automated response and their operational value
- QRadar SOAR architecture and components: playbooks, incidents, automation actions, and data actions
- SOAR integration: connecting SIEM, EDR, threat intelligence, and ticketing systems (ServiceNow, Jira)
- Distinguishing SOAR from traditional automation through playbook-driven workflow orchestration
6.2 Playbook Design and Execution
- Creating playbooks to build automated investigation and response workflows
- Configuring playbook triggers: offense creation, rule triggers, and manual activation
- Defining playbook actions: IP enrichment, IP blocking, ticket creation, and threat feed queries
- Implementing playbook conditions and branching logic
6.3 Incident Response Automation
- Automated incident response workflows enabling containment within minutes
- Automated threat hunting utilizing playbook-driven investigations
- Automated containment actions: IP blocking, endpoint isolation, and account suspension
- Workflows for ransomware, phishing, brute-force attacks, and insider threats
6.4 Integration with External Systems
- SOAR integrations with ServiceNow, Jira, Slack, email, and webhook-based systems
- Custom API integration with Threat Intelligence platforms for government agencies
- EDR integration for executing automated endpoint actions
- Payload analysis automation for files, URLs, and domains
Market-Aligned Competencies: Security Orchestration, AI Automation and Response (SOAR), IBM QRadar SOAR, Playbook Automation, Runbook Design, Automated Incident Response Workflow Orchestration, API-Driven Security Automation, Threat Intelligence Integration, Incident Containment Automation, Automated Threat Analysis, ServiceNow Integration for Security, Ticketing System Automation, Endpoint Response Automation, Automated IP Blacklisting, Phishing Response Automation, Ransomware Response Automation
Module 7: QRadar Forensics, Network Forensics, and Data Analysis
Covers QRadar Incident Forensics (QRIF) and forensic investigation capabilities, network forensics via NFI for packet capture analysis, and forensic analysis techniques applied during incident investigations.
7.1 IBM QRadar Forensics (QRIF)
- QRIF capabilities for forensic data collection and storage during investigations
- Forensic data sources: packet captures, event logs, and endpoint forensics
- Forensic analysis methods: timeline reconstruction, file analysis, and network forensics
- Maintaining chain-of-custody for forensic evidence preservation
- Utilizing forensic analysis tools and techniques within QRIF
7.2 Network Forensics and Inspection (NFI)
- Network forensics principles: packet capture analysis and traffic inspection
- Analyzing flow data via NetFlow, sFlow, and IPFIX within QRadar
- Protocol analysis for HTTP, DNS, SMTP, SSH, FTP, and custom protocols
- Detecting threats through network forensics: C2 beaconing, data exfiltration, and lateral movement
- Identifying suspicious traffic patterns
7.3 User and Entity Behavior Analytics (UEBA)
- Understanding UEBA fundamentals: establishing user behavior baselines and anomaly detection
- UEBA data sources: Active Directory, proxy logs, endpoint logs, DLP logs, authentication logs, and cloud logs
- UEBA scoring methodologies for user and entity risk assessment
- Detecting threats via UEBA: compromised accounts, insider threats, and data exfiltration
Market-Aligned Competencies: QRadar Incident Forensics (QRIF), Forensic Data Collection, Forensic Investigation and Analysis, Network Forensics, Packet Capture Analysis, Flow Data Analysis, Threat Detection Through Network Forensics, User and Entity Behavior Analytics (UEBA), User Anomaly Detection, Insider Threat Detection, Compromised Account Detection, Data Exfiltration via User Behavior, C2 Beaconing Detection, Lateral Movement via Network Forensics, Digital Forensics and Incident Response (DFIR), Evidence Preservation and Chain of Custody, Protocol Analysis, Security Log Forensics, Threat Hunting via Network Analytics
Module 8: Cloud SIEM, SIEM-as-Code, Compliance, and SIEM Operations
Evaluates IBM QRadar operations, scaling capabilities, compliance reporting, cloud SIEM integration, detection-as-code practices, and SOC governance essential for enterprise-scale deployments.
8.1 QRadar Operations and Administration
- Administering QRadar: managing user roles, permissions, and security policies
- Auditing QRadar configurations and access logs
- Scheduled reporting and custom report design for management and compliance needs
- Managing scheduled tasks: backup/restore procedures, database cleanup, and maintenance
- Configuring the syslog server for SIEM log forwarding
- Managing software updates and patch cycles for QRadar appliances
8.2 Compliance Reporting and Regulatory Mapping
- PCI DSS SIEM requirements and QRadar compliance reporting mechanisms
- Mapping HIPAA, GDPR, SOX, NIST CSF, and ISO 27001 requirements with QRadar reports
- Regulatory audit reporting using custom templates for PCI DSS and HIPAA auditors
- Implementing real-time compliance monitoring via continuous dashboards
8.3 SIEM-as-Code and Infrastructure as Code
- Version-controlled SIEM rule management using Git-based deployment
- Utilizing Terraform and Ansible for QRadar appliance provisioning and configuration
- Establishing CI/CD pipelines for SIEM rules and playbooks
- Leveraging the QRadar API for automated rule deployment and management
8.4 Cloud SIEM and Hybrid Cloud Security
- Cloud log source integration: AWS CloudTrail, Microsoft Sentinel, GCP Audit Logs, and Azure Monitor
- Cloud-native SIEM strategies for SaaS environments (AWS, Azure, GCP, Office 365)
- SIM integrations with Microsoft Sentinel, Azure Sentinel, AWS CloudWatch Logs, and Google Cloud Logging
- Monitoring cloud identity and access: IAM, Active Directory, and Entra ID
- Integrating cloud workload protection solutions with SIEM
8.5 Identity Threat Detection
- Treating identity as the new threat boundary for account compromise detection
- Detecting Active Directory threats: Kerberoasting, AS-REP roasting, and Golden/Sid ticket attacks
- Detecting Multi-factor authentication (MFA) bypass attempts
- Monitoring Privileged Identity Management (PIM)
8.6 Zero Trust Monitoring
- Monitoring Zero Trust architecture components: identity, device, and network controls
- Validating microsegmentation monitoring and policy enforcement
- Generating Zero Trust compliance reports via SIEM integration
8.7 SOC Operations and SIEM Governance
- SOC metrics and KPIs: MTTR (Mean Time to Respond) and MTTD for SIEM monitoring
- Conducting SOC maturity assessments and driving improvement via SIEM data
- SIEM governance: managing rules, tracking false positives, and ensuring continuous improvement
- Implementing operational best practices for monitoring, alerting, and escalation procedures
Market-Aligned Competencies: QRadar Administration, SIEM Operations and Management, SIEM Compliance Management, PCI DSS SIEM Compliance Reporting, HIPAA and GDPR SIEM Compliance, SOX and ISO 27001 SIEM Compliance, NIST CSF SIEM Mapping, Continuous Compliance Monitoring, Custom Compliance Reporting, SIEM-as-Code and Infrastructure as Code, Terraform for SIEM, Ansible for SIEM Deployment, CI/CD for SIEM Rules, QRadar API Automation, Cloud SIEM Integration, AWS CloudTrail SIEM, Microsoft Sentinel Integration, GCP Cloud Logging SIEM, Azure Monitor SIEM, Office 365 SIEM Integration, Cloud-Native SIEM, Zero Trust Monitoring, IAM Threat Detection, Identity Threat Detection, Active Directory Threat Detection, Kerberos Attack Detection, Privileged Identity Monitoring, Multi-Factor Authentication (MFA) Security, SOC KPI and Metric Management, SOC Maturity Assessment, SIEM Operational Best Practices, Incident Response Governance, SIEM Rule Lifecycle Management, Enterprise SIEM Governance
Module 9: Capstone Project and Real-World Threat Scenarios
A comprehensive hands-on capstone project simulating enterprise security scenarios, including threat detection, investigation, and incident response using IBM QRadar.
9.1 Capstone Project: Enterprise Security Scenario
- Setting up a simulated enterprise environment with realistic log sources and attack scenarios
- Deploying log sources and configuring log collection policies
- Building detection rules mapped to the MITRE ATT&CK framework
- Investigating real-world offense data in QRadar and performing forensic analysis
- Designing and deploying SOAR playbooks for automated response
- Generating compliance reports for PCI DSS, HIPAA, and GDPR
- Performing capacity planning and scaling the SIEM deployment
9.2 Real-World Threat Scenarios
- Simulated attacks: ransomware deployment, insider threats, lateral movement, brute-force attacks, supply chain attacks, and phishing
- Detecting ransomware activities: lateral movement, data staging, and exfiltration attempts
- Insider threat detection: identifying data exfiltration attempts and behavioral anomalies
- Supply chain attack detection: identifying compromised vendor access
- Phishing response: automated URL blocking and email investigation workflows
- Zero-day threat hunting: detecting unknown threats using rule-less hunting techniques
- Advanced Persistent Threat (APT) detection using UEBA and forensic analysis
Market-Aligned Competencies: Capstone Security Project Delivery, Enterprise SIEM Simulation, Real-World Threat Scenario Design, MITRE ATT&CK Detection Rule Deployment, SOC Incident Investigation, QRadar SOAR Playbook Design, Ransomware Response Simulation, Insider Threat Detection, Phishing Response Automation, Supply Chain Attack Detection, Zero-Day Threat Hunting, Advanced Persistent Threat (APT) Detection, SIEM Capacity Planning and Scaling, Multi-Compliance Reporting (PCI DSS, HIPAA, GDPR), Enterprise Threat Response, Forensic Threat Investigation, Threat Intelligence Enrichment, Automated Incident Containment, SOC Operations Simulation, Full-Scale SIEM Engineering Practice
Requirements
- Demonstrated proficiency in information technology security principles and practices
Target Audience
- Security Engineers responsible for safeguarding critical infrastructure and data systems for government operations