Detaillierte Informationen zum Seminar
Inhalte:
As a learner, you will begin by exploring event search and reporting features using Recon™s default content to get familiar with the interface and its core functionalities. As the course progresses, you will engage in hands-on exercises to build more advanced event searches, reports, and dashboards from the ground up.\n\nYou will also analyze security events tied to specific use cases, such as detecting threats from former employees, investigating the Log4j vulnerability, and uncovering insider threats related to data exfiltration. By applying your knowledge of Recon, you will examine these scenarios to identify targets, indicators of compromise (IoCs), and potential attackers.\n\nHighlights:\n\n\n- Create search queries using ArcSight schema fields, keywords, field sets, search operators, and hashtags.\n- Use default content reports and dashboards to analyze events of interest, including MITRE ATT&CK content.\n- Create reports and dashboards using data worksheets from scratch.\n- Analyze event data using Recon tools in sample scenarios, such as uncovering ex-employee threats and detecting Log4j vulnerability.\n- Use Recon tools to analyze historical events and identify undetected threats in a sample unstructured threat-hunting scenario.\n- Build and score the outlier model and explain outlier™s analytics charts.
Teilnahmevoraussetzungen:
To be successful in this course, you should have the following prerequisites or knowledge:\n\n\n- Familiar with Boolean logic operators and ArcSight Schema groups and fields.\n- Basic understanding of Command Shell in Windows and Linux, and familiarity with SIEM concepts
Zielgruppe:
This course is ideal for security analysts who want to enhance their threat detection and investigation capabilities by leveraging ArcSight Recon™s event search, reporting, and dashboarding features to identify anomalies, uncover threats, and support proactive security operations.