Перейти к содержимому

Security Operations Center

MSP-MIU

0:00 / 0:00

Security Operations Center

5 просмотров · 9 дней назад
MSP-MIU
16 подписчиков
5 просмотров · 9 дней назад
🔐 *Session 07 — Security Operations Center (SOC)* In this session, we explore how a Security Operations Center (SOC) works and how security teams monitor, detect, investigate, and respond to threats. Topics covered: • What is a SOC? • SOC tiers and responsibilities • Incident response lifecycle • SIEM and how it works • Common log sources • IOCs vs IOAs • From logs to security alerts • Practical Splunk lab • Finding suspicious login activity 🧪 *Practical:* We use Splunk to search logs, analyze failed logins, filter by IP and username, and identify suspicious activity. *Learn → Try → Observe → Ask* Good luck ❤️