← All courses
Security

Defensive Security & SOC

Detect, investigate and shut down attacks in progress.

Defensive Security — Advance

SIEM engineering, threat hunting, forensics and incident response.

68 study hours 470 pages 11 modules PDF ebook

What is inside

01 SIEM deployment: Wazuh, Elastic Security, Splunk
02 Detection engineering and rule tuning
03 Reducing false positives without missing real attacks
04 Threat intelligence and IOC management
05 Proactive threat hunting methodology
06 EDR and XDR in practice
07 Digital forensics: disk, memory and network
08 Malware analysis fundamentals
09 Incident response lifecycle and playbooks
10 Containment, eradication and recovery
11 Post-incident review that changes something

By the end you can

  • Deploy and tune a SIEM that catches real attacks
  • Hunt for threats no alert has flagged
  • Lead a technical incident response