Перейти к содержимому
← Все курсы

Средний · Уроки: 4

Defensive operations: how the blue team works

What a Security Operations Center does, how logs and a SIEM turn events into alerts, the six phases of incident response, and how to preserve digital evidence.

Начать курс

  1. 1 The Security Operations Center: who watches, and how

    What a Security Operations Center (SOC) does all day, how its analysts are organised in tiers, and which habits make a small team effective.

    8 мин
  2. 2 Logs and SIEM: turning millions of events into a few good alerts

    Why logs are the raw material of every investigation, what a SIEM does with them, and how to decide what is worth collecting.

    8 мин
  3. 3 Incident response: the six phases, from preparation to lessons learned

    How organisations handle a security incident step by step, why preparation decides the outcome, and how the six-phase model maps to NIST’s guidance.

    9 мин
  4. 4 Digital forensics basics: preserving evidence you can trust

    How investigators collect digital evidence without destroying it, why the order of collection matters, and what chain of custody means.

    8 мин

Бесплатно, без аккаунта, без отслеживания. Прогресс хранится только в этом браузере.