Workshop XDR-Essentials
Master XDR fundamentals to enhance your cybersecurity skills and develop a proactive security posture for your organization.
Basic concepts
Why do we need a minimum cybersecurity level
Threats, vulnerabilities and risks
Cybersecurity management
NIST SP 800-39 / Managing information security risk
Risk assessment framework
Incident response (IR) - basics
Attack vectors
Incident prevention strategies and controls
MITRE framework
MITRE attack coverage mapping
IOCs, whitelist and blacklist
Best practices for event logging
Reputation analysis
Heuristic analysis
Anomaly detection
Signature detection
Pair matching game
Network perimeter security
Host-based intrusion detection and prevention systems (HIDS/HIPS)
Endpoint detection and response (EDR)
Extended detection and response (XDR)
Security information and event management (SIEM)
Security orchestration, automation and response (SOAR)
Cyber threat intelligence (CTI)
Attention to buzzwords
EDR insight
EDR modules cheatsheet
Labs EDR/SIEM/EPP
Performance monitoring
False positives
Analytics tips
Labs data science
Labs SOAR