1
1

00:00:00,270  -->  00:00:01,470
<v ->In this section of the course,</v>
2

2

00:00:01,470  -->  00:00:04,170
we're going to dive further into our coverage of SIEMs,
3

3

00:00:04,170  -->  00:00:06,510
which, as you know, are the security information
4

4

00:00:06,510  -->  00:00:08,400
and event management systems.
5

5

00:00:08,400  -->  00:00:09,720
Now, our focus in this section
6

6

00:00:09,720  -->  00:00:12,330
of the course is going to continue to be on domain one,
7

7

00:00:12,330  -->  00:00:16,170
security operations, as we discuss objective 1.3 along
8

8

00:00:16,170  -->  00:00:17,640
with moving into domain 4,
9

9

00:00:17,640  -->  00:00:21,000
reporting and communication with objective 4.1.
10

10

00:00:21,000  -->  00:00:23,880
Now objective 1.3 states that given a scenario,
11

11

00:00:23,880  -->  00:00:25,740
you must be able to use appropriate tools,
12

12

00:00:25,740  -->  00:00:28,500
or techniques to determine malicious activity.
13

13

00:00:28,500  -->  00:00:31,110
Our specific focus in this section is going to be
14

14

00:00:31,110  -->  00:00:33,330
on the security monitoring activities associated
15

15

00:00:33,330  -->  00:00:36,120
with SIEMs, of course, inside of this section.
16

16

00:00:36,120  -->  00:00:38,940
Objective 4.1 states that you must be able to explain
17

17

00:00:38,940  -->  00:00:40,950
the importance of vulnerability management reporting
18

18

00:00:40,950  -->  00:00:44,010
and communication, specifically focusing on the use
19

19

00:00:44,010  -->  00:00:47,220
of SIEM dashboards as one method of reporting inside
20

20

00:00:47,220  -->  00:00:49,920
of our larger vulnerability management program.
21

21

00:00:49,920  -->  00:00:51,630
Now, as we move through this section,
22

22

00:00:51,630  -->  00:00:54,090
we're going to start out by looking at a SIEM dashboard,
23

23

00:00:54,090  -->  00:00:56,610
and how we can use them to monitor our networks.
24

24

00:00:56,610  -->  00:00:58,110
Then we're going to be taking a look
25

25

00:00:58,110  -->  00:00:59,670
at how you can use a scene to detect
26

26

00:00:59,670  -->  00:01:01,140
and analyze various events,
27

27

00:01:01,140  -->  00:01:03,180
as well as how to conduct trend analysis
28

28

00:01:03,180  -->  00:01:06,090
by detecting issues over time within your networks.
29

29

00:01:06,090  -->  00:01:07,680
Next, we're going to look at how rules
30

30

00:01:07,680  -->  00:01:09,630
and queries can be written for your SIEMs,
31

31

00:01:09,630  -->  00:01:11,100
and even how you can describe
32

32

00:01:11,100  -->  00:01:12,990
how to perform various string searches
33

33

00:01:12,990  -->  00:01:14,340
using regular expressions,
34

34

00:01:14,340  -->  00:01:16,740
while piping data through various command line tools
35

35

00:01:16,740  -->  00:01:19,920
on your system through the find that data even quicker.
36

36

00:01:19,920  -->  00:01:22,530
Then we're going to be covering the basics of scripting,
37

37

00:01:22,530  -->  00:01:24,990
including how to use Bash, WMIC,
38

38

00:01:24,990  -->  00:01:28,200
and Powershell to find exactly what you're looking for.
39

39

00:01:28,200  -->  00:01:30,450
After that, we're going to analyze, filter,
40

40

00:01:30,450  -->  00:01:32,340
and search various event logs to find
41

41

00:01:32,340  -->  00:01:34,500
that figurative needle in a haystack,
42

42

00:01:34,500  -->  00:01:36,540
while we're trying to identify malicious data
43

43

00:01:36,540  -->  00:01:38,430
within our busy networks.
44

44

00:01:38,430  -->  00:01:40,200
Finally, we're going to take a short quiz
45

45

00:01:40,200  -->  00:01:42,300
to see what you learned during this section of the course
46

46

00:01:42,300  -->  00:01:44,130
and review each of those questions fully
47

47

00:01:44,130  -->  00:01:45,060
to ensure you can explain
48

48

00:01:45,060  -->  00:01:46,890
why the right answers were correct.
49

49

00:01:46,890  -->  00:01:48,870
So, let's continue to look at SIEMs,
50

50

00:01:48,870  -->  00:01:50,490
and how to use them for our analysis
51

51

00:01:50,490  -->  00:01:52,190
during this section of the course.
