Course curriculum
-
-
Read before you start
-
-
-
Prerequisites
-
EDR agent installation - Windows
-
Video - Installing the EDR agent
-
EDR agent troubleshooting - Windows
-
Video - Troubleshooting the EDR
-
V14 - Updating the EDR agents from V1 to V2
-
Video - Updating the EDR agents from V1 to V2
-
Quiz - Installing the EDR agent
-
-
-
Configuration workflow
-
Configuring in detect mode
-
Video - Adding a new detection configuration
-
Whitelisting benign alerts (true positives without impact)
-
Video - Implementing a whitelist on a benign alert
-
Configuring in remediation mode
-
Video - Enabling automated remediations
-
[OPTIONAL] Understanding child configurations priorities
-
Quiz - Configuring the EDR
-
-
-
How fast should you be able to spot alarms?
-
From the XDR to SOC notification: Automating alarm notifications
-
Video - Creating a SOAR rule for notification upon remediation
-
Quiz - SOAR
-
-
-
From notification to SOC level 1: Triage focusing on remediations
-
Video - Triage using the remediation dashboard
-
Quiz - Triage
-
-
-
Machine, Binary, User: the three main pivots you can rely on
-
Machine investigation functionalities on the XDR
-
Binary investigation functionalities on the XDR
-
User investigation functionalities on the XDR
-
Video - Qualification on the XDR
-
Quiz - Qualification
-
About this course
- Free
- 32 lessons
- 0.5 hours of video content