When you enroll in this course, you'll also be enrolled in this Specialization.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate
There are 4 modules in this course
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how threat-centric SOC must prepare for analyzing new and emerging threats by implementing robust security investigation procedures • By the end of the course, you will be able to: • Understand cyber-threat hunting concepts • Describe the five hunting maturity levels (HM0–HM4) • Describe the hunting cycle four-stage loop• Describe the use of the Common Vulnerability Scoring System (CVSS) and list the CVSS v3.0 base metrics• Describe the CVSS v3.0 scoring components (base, temporal, and environmental) • Provide an example of CVSS v3.0 scoring • Describe the use of a hot threat dashboard within a SOC • Provide examples of publicly available threat awareness resources • Provide examples of publicly available external threat intelligence sources and feeds• Describe the use of security intelligence feed • Describe threat analytics systems • Describe online security research tools • Simulate malicious actions to populate the event data on the Security Onion tools for later analysis • Identify resources for hunting cyber threats. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how threat-centric SOC must prepare for analyzing new and emerging threats by implementing robust security investigation procedures • By the end of the course, you will be able to: • Understand cyber-threat hunting concepts • Describe the five hunting maturity levels (HM0–HM4) • Describe the hunting cycle four-stage loop• Describe the use of the Common Vulnerability Scoring System (CVSS) and list the CVSS v3.0 base metrics• Describe the CVSS v3.0 scoring components (base, temporal, and environmental) • Provide an example of CVSS v3.0 scoring • Describe the use of a hot threat dashboard within a SOC • Provide examples of publicly available threat awareness resources • Provide examples of publicly available external threat intelligence sources and feeds• Describe the use of security intelligence feed • Describe threat analytics systems • Describe online security research tools • Simulate malicious actions to populate the event data on the Security Onion tools for later analysis • Identify resources for hunting cyber threats. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
Introduction to Identifying Resources for Hunting Cyber Threats•1 minute
Cyber Threat Hunting Concepts•3 minutes
Hunting Maturity Model•4 minutes
Cyber Threat Hunting Cycle•3 minutes
Common Vulnerability Scoring System•5 minutes
CVSS v3.0 Scoring•3 minutes
CVSS v3.0 Example•3 minutes
Hot Threat Dashboard•4 minutes
Publicly Available Threat Awareness Resources•3 minutes
Security Intelligence•3 minutes
Threat Analytic Systems•4 minutes
Security Tools Reference•5 minutes
Wrap-Up•1 minute
22 readings•Total 137 minutes
Introduction to Identifying Resources for Hunting Cyber Threats•1 minute
Cyber-Threat Hunting Concepts•2 minutes
Hunting Maturity Model•7 minutes
Cyber Threat Hunting Cycle•8 minutes
Common Vulnerability Scoring System•4 minutes
CVSS v3.0 Base Metrics•10 minutes
CVSS v3.0 Temporal Metrics•8 minutes
CVSS v3.0 Environmental Metrics•5 minutes
CVSS v3.0 Scoring•3 minutes
CVSS v3.0 Example•8 minutes
Hot Threat Dashboard•6 minutes
Hot Threat Process•8 minutes
Hot Threat Challenges•1 minute
Open Web Application Security Project•10 minutes
Spamhaus Project•5 minutes
Alexa•2 minutes
Publicly Available Threat Awareness Resources Practice Quiz •1 minute
Other External Threat Intelligence Sources and Feeds Reference•10 minutes
Security Intelligence•12 minutes
Threat Analytic Systems•10 minutes
Security Tools Reference•15 minutes
Wrap-Up•1 minute
10 assignments•Total 48 minutes
Identifying Resources for Hunting Cyber Threats Course Exam•20 minutes
Cyber-Threat Hunting Concepts Practice Quiz•3 minutes
Hunting Maturity Model Practice Quiz•2 minutes
Cyber Threat Hunting Cycle Practice Quiz •3 minutes
Common Vulnerability Scoring System Practice Quiz •5 minutes
Practice Quiz •3 minutes
CVSS v3.0 Scoring Practice Quiz •3 minutes
Hot Threat Dashboard Practice Quiz •3 minutes
Security Intelligence Practice Quiz •3 minutes
Threat Analytic Systems Practice Quiz •3 minutes
1 discussion prompt•Total 10 minutes
Learner Introduction•10 minutes
Understanding Event Correlation and Normalization
Module 2•2 hours to complete
Module details
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you describe event correlation and normalization. By the end of the course, you will be able to: • Describe network security monitoring event sources (IPS, Firewall, NetFlow, Proxy Server, IAM, AV, and application logs)• Describe direct evidence and circumstantial evidence • Describe chain of custody for all evidence and interacting with law enforcement • Describe an example of security data normalization • Provide an example of security events correlation • Explain the basic concepts of security data aggregation, summarization, and deduplication • Use the Security Onion Sguil and ELSA applications as the SIEM platform to monitor the network for peculiarities and start an investigation. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
What's included
8 videos18 readings6 assignments
Show info about module content
8 videos•Total 20 minutes
Introduction to Understanding Event Correlation and Normalization•1 minute
Event Sources•6 minutes
Evidence•3 minutes
Chain of Custody•1 minute
Security Data Normalization•3 minutes
Event Correlation•2 minutes
Other Security Data Manipulation •3 minutes
Wrap-Up•1 minute
18 readings•Total 62 minutes
Introduction to Understanding Event Correlation and Normalization•1 minute
Event Sources•5 minutes
Intrusion Prevention System•3 minutes
Firewalls•3 minutes
NetFlow•3 minutes
Proxy Servers•3 minutes
Identity and Access Management•3 minutes
Antivirus•1 minute
Application Logs•1 minute
Evidence•7 minutes
Chain of Custody•5 minutes
Security Data Normalization•7 minutes
Event Correlation•7 minutes
Other Security Data Manipulation•1 minute
Aggregation•2 minutes
Summarization•2 minutes
Deduplication•7 minutes
Wrap-Up•1 minute
6 assignments•Total 24 minutes
Understanding Event Correlation and Normalization Course Exam•12 minutes
Event Sources Practice Quiz•3 minutes
Evidence Practice Quiz•3 minutes
Chain of Custody Practice Quiz•2 minutes
Event Correlation Practice Quiz•3 minutes
Other Security Data Manipulation Practice Quiz•1 minute
Conducting Security Incident Investigations
Module 3•1 hour to complete
Module details
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will explain how to conduct security incident investigations. By the end of the course, you will be able to: • Explain the objective of security incident investigation: Discover the who, what, when, where, why, and how of the incident • Describe the China Chopper Remote Access Trojan • Identify network traffic that was created by an advanced persistent threat (APT). To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
What's included
4 videos11 readings3 assignments
Show info about module content
4 videos•Total 9 minutes
Introduction to Conducting Security Incident Investigations•1 minute
Security Incident Investigation Procedures Practice Quiz•5 minutes
Threat Investigation Example: China Chopper Remote Access Trojan Practice Quiz•3 minutes
Using a Playbook Model to Organize Security Monitoring
Module 4•2 hours to complete
Module details
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how to use a playbook model to organize security monitoring. By the end of the course, you will be able to: • Describe the security analytics process • Describe the use of a playbook in a SOC • Describe the components of a play in a typical SOC playbook • Describe the use of a playbook management system in the SOC • Explore SOC playbooks. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.
What's included
6 videos12 readings5 assignments
Show info about module content
6 videos•Total 11 minutes
Introduction to Using a Playbook Model to Organize Security Monitoring•1 minute
Security Analytics•1 minute
Playbook Definition•1 minute
What Is in a Play?•4 minutes
Playbook Management System•1 minute
Wrap-Up•1 minute
12 readings•Total 47 minutes
Introduction to Using a Playbook Model to Organize Security Monitoring•2 minutes
Security Analytics•10 minutes
Playbook Definition•10 minutes
What Is in a Play?•1 minute
Report Identification•5 minutes
Objective•1 minute
Data Query•2 minutes
Action•1 minute
Analysis•2 minutes
Reference•2 minutes
Playbook Management System•10 minutes
Wrap-Up•1 minute
5 assignments•Total 32 minutes
Course Exam•20 minutes
Security Analytics Practice Quiz•5 minutes
Playbook Definition Practice Quiz•2 minutes
What Is in a Play Practice Quiz•3 minutes
Playbook Management System Quiz•2 minutes
Earn a career certificate
Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.
Instructor
Instructor ratings
Instructor ratings
We asked all learners to give feedback on our instructors based on the quality of their teaching style.
The Cisco Learning and Certifications organization is a worldwide leader in training and education programs that foster the development of careers in networking and other technology areas. The organization caters to a global community of students, partners, customers, and employees who seek the most up-to-date training on Cisco technologies and certifications.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.