Intrinsic Security
VM-VCBEDRAAN-On Demand
VMware Carbon Black EDR Advanced Analyst
Target Audience
Security operations personnel, including analysts and incident responders
Prerequisites
This course requires completion of the following course:
• VMware Carbon Black EDR Administrator
|
Course Objectives
By the end of the course, you should be able to meet the following objectives:
| ||
Course Outline
1 Course Introduction • Introductions and course logistics • Course objectives 2 VMware Carbon Black EDR & Incident Response • Framework identification and process 3 Preparation • Implement the Carbon Black EDR instance according to organizational requirements 4 Identification • Use initial detection mechanisms • Process alerts • Proactive threat hunting • Incident determination 5 Containment • Incident scoping • Artifact collection • Investigation 6 Eradication • Hash banning • Removing artifacts • Continuous monitoring 7 Recovery • Rebuilding endpoints • Getting to a more secure state 8 Lessons Learned • Tuning Carbon Black EDR • Incident close out |
If you would like to know more about this course please contact us