Course summary
This course is built for analysts who utilize the Elastic Security for Endpoint solution. Elastic Security for Endpoint walks you through the components behind the Elastic Stack, Fleet, and Elastic Agent. You will then be familiarized with Elastic Security and using visualizations, dashboards, and other components of the Security App to triage alerts and investigate events in Timeline. Afterwards, you will learn about Elastic Defend and other security integrations. Finally, you will conduct a threat hunting capstone based on concepts covered during the course to reinforce the lessons learned.
- Topics
- Audience
- Duration
- Pre-reqs
- Requirements
Topics
- Elastic Stack overview
- Security application
- Elastic Defend
- Elastic security enrichments
- Threat hunting
Topics
- Elastic Stack overview
- Security application
- Elastic Defend
- Elastic security enrichments
- Threat hunting
Audience
Security analysts who are responsible for monitoring and investigating host based alerts sourced from Elastic Endpoint protection capabilities.
Duration
24 hours
Pre-Reqs
Operating Systems
- Windows and Linux
- File systems and permissions
- Command line navigation
- Windows registry
Networking
- Common ports and protocols
- Common Networking devices
Vulnerabilities and Exploit Methodology
- Reconnaissance
- Command and control
- Persistence techniques
Requirements
- Stable internet connection
- Mac, Linux, or Windows
- Latest version of Chrome or Firefox (other browsers not supported)
- Disable any ad blockers and restart your browser before class
Course Details
Virtual
10:00 am - 5:00 pm
10:00 am - 5:00 pm
10:00 am - 5:00 pm
10:00 am - 5:00 pm
(Europe - Amsterdam Time Zone)
Have a Question?
Please see our Training FAQ with any additional questions you may have. Have a question not answered in the FAQ? Contact us.