Reading Assignment Read Splunk documentation on alerts and explain how alerts support SOC operations. Research Assignment Research how organizations use SIEM tools to detect: Brute force attacks Suspicious PowerShell activity Abnormal login behavior Hands-On Practice Task Using the BOTSv3 dataset and the provided dataset: Detect multiple failed logins Identify suspicious IP activity Detect abnormal login […]
Assignment 2
Reading Assignment Read Microsoft documentation on KQL and explain how KQL helps analysts investigate security events. Research Assignment Research how organizations use Microsoft Sentinel to detect: Brute force attacks Impossible travel activity Suspicious cloud logins Hands-On Practice Task Using Microsoft Sentinel and the provided Dataset: Search SigninLogs Detect failed login attempts Identify suspicious IP activity […]
Assignment 2
Reading Assignment Read Splunk documentation on alerts and explain how alerts support SOC operations. Research Assignment Research how organizations use SIEM tools to detect: Brute force attacks Suspicious PowerShell activity Abnormal login behavior Hands-On Practice Task Using the BOTSv3 dataset and the provided dataset: Detect multiple failed logins Identify suspicious IP activity Detect abnormal login […]
Class Activity 2
Students will use the BOTSv3 dataset inside Splunk to: Filter events Detect suspicious patterns Investigate authentication activity Identify suspicious IPs Detect abnormal behavior Using the provided Dataset, Students must detect: Multiple failed logins Suspicious IP activity Abnormal activity Students should provide: SPL queries used Evidence found Investigation conclusions
Class Activity 2
Students will use Microsoft Sentinel to: Search SigninLogs Create KQL queries Detect suspicious login attempts Investigate impossible travel activity Analyze login timing and IP addresses Using the provided Dataset, Students should provide: KQL queries used Evidence found Investigation conclusions
Class Activity 2
Students will use the BOTSv3 dataset inside Splunk to: Filter events Detect suspicious patterns Investigate authentication activity Identify suspicious IPs Detect abnormal behavior Using the provided Dataset, Students must detect: Multiple failed logins Suspicious IP activity Abnormal activity Students should provide: SPL queries used Evidence found Investigation conclusions
Assignment 1
Reading Assignment:Read Splunk basic search documentation and explain what SPL is and why it is important in cybersecurity. Research Assignment:Research how SIEM tools help detect attacks and list three real-world use cases of SIEM in a SOC environment. Hands-On Practice Task:Use the provided log dataset and perform keyword searches and time filtering to identify suspicious […]
Assignment 1
Reading Assignment Read Microsoft documentation on Microsoft Sentinel and explain how cloud-native SIEM platforms differ from traditional SIEM tools. Research Assignment Research how organizations use Microsoft Sentinel to: Detect cloud threats Monitor Microsoft 365 activity Investigate suspicious logins Hands-On Practice Task Using Microsoft Sentinel and the provided dataset: View available data sources Search SigninLogs Detect […]
Assignment 1
Reading Assignment:Read Splunk basic search documentation and explain what SPL is and why it is important in cybersecurity. Research Assignment:Research how SIEM tools help detect attacks and list three real-world use cases of SIEM in a SOC environment. Hands-On Practice Task:Use the provided log dataset and perform keyword searches and time filtering to identify suspicious […]
Class Activity 1
Class Activity Students will use Splunk (or a simulated interface) to: Search logs using keywords Apply time filters Identify: Failed login attempts RDP activity Suspicious patterns Using the provided dataset, Students must explain: What they searched What they found Why it is suspicious
