At the heart of a SOC, you must see, understand and react fast. This module trains you to operate a tier-1 security operations centre: collect logs, correlate, alert, triage and launch first responses.
• Design log collection and ingestion • Search and correlate within a SIEM • Detect via endpoint telemetry • Triage and respond to an alert per a playbook