Security Operations Center
MSP-MIU
0:00 / 0:00
Security Operations Center
5 просмотров · 9 дней назад
MSP-MIU
16 подписчиков
5 просмотров · 9 дней назад
🔐 *Session 07 — Security Operations Center (SOC)*
In this session, we explore how a Security Operations Center (SOC) works and how security teams monitor, detect, investigate, and respond to threats.
Topics covered:
• What is a SOC?
• SOC tiers and responsibilities
• Incident response lifecycle
• SIEM and how it works
• Common log sources
• IOCs vs IOAs
• From logs to security alerts
• Practical Splunk lab
• Finding suspicious login activity
🧪 *Practical:* We use Splunk to search logs, analyze failed logins, filter by IP and username, and identify suspicious activity.
*Learn → Try → Observe → Ask*
Good luck ❤️