Instructor

VMware Carbon Black EDR Advanced Analyst Training Course

Curriculum

Master threat hunting & incident response with VMware Carbon Black EDR Advanced Analyst Training. Gain hands-on skills to detect & mitigate cyber threats.

Ratings

( 3.7 Ratings )

Live Online Classes starting on 01 January, 1970

VMware Carbon Black EDR Advanced Analyst

The VMware Carbon Black EDR Advanced Analyst course is a comprehensive program designed for security professionals who want to master the skills needed to effectively use VMware Carbon Black Endpoint Detection and Response (EDR) for Advanced threat hunting and incident response. Throughout the course, learners will be introduced to the framework and processes essential for identifying, responding to, and mitigating cyber threats.Starting with course logistics and objectives, participants will gain a foundational understanding before delving into the practical aspects of incident response using VMware Carbon Black EDR. The course covers preparation and implementation of the EDR solution, followed by identification techniques including Initial detection, Alert processing, and Proactive threat hunting.Learners will then explore containment strategies such as Incident scoping and Investigation, and move onto eradication methods including Hash banning and Artifact removal. The Recovery module teaches students how to rebuild compromised endpoints and enhance security postures. Finally, the course concludes with lessons on Tuning the EDR system and Incident closure, ensuring a holistic understanding of the incident response lifecycle. This course empowers security analysts with the advanced skills required for effective cyber defense and incident management.

 

Course Objectives

By the end of the course, you should be able to:

  • Utilize Carbon Black EDR throughout an incident.

  • Implement a baseline configuration for Carbon Black EDR.

  • Determine if an alert is a true or false positive.

  • Fully scope out an attack from the moment of compromise.

  • Describe Carbon Black EDR capabilities available to respond to an incident.

  • Create additional detection controls to increase security.

 

Who Can Benefit

  • Security operations personnel.

  • Analysts and incident responders.

 

Prerequisites

This course requires completion of the following:

  • VMware Carbon Black EDR Administrator.

 

Course Outline:

1. Course Introduction

  • Introductions and course logistics

  • Overview of course objectives

2. VMware Carbon Black EDR & Incident Response

  • Understanding the framework identification and incident response processes

3. Preparation

  • Implementing the Carbon Black EDR instance based on organizational requirements

4. Identification

  • Utilizing initial detection mechanisms

  • Processing alerts effectively

  • Engaging in proactive threat hunting

  • Determining incidents through analysis

5. Containment

  • Scoping incidents to understand their impact

  • Collecting relevant artifacts for investigation

  • Conducting thorough investigations to assess the situation

6. Eradication

  • Implementing hash banning to prevent further issues

  • Removing malicious artifacts from the environment

  • Establishing continuous monitoring practices

7. Recovery

  • Rebuilding endpoints to restore functionality

  • Transitioning systems to a more secure state post-incident

8. Lessons Learned

  • Tuning Carbon Black EDR for improved performance

  • Closing out incidents with comprehensive reports and analyses

(3.7 Ratings)

Download Course Contents

Still unsure?
We're just a click away


Course Outline PDF

SpireTec Unique Features

course-img
1-On-1 Training

Benefit from our 1-On-1 Training for personalized, focused, and effective learning experiences.

course-img
Customized Training

Experience our Customized Training service tailored to meet your specific learning needs and goals

course-img
4 - Hours / Weekend Session

Join our Class featuring 4 - Hours / Weekend Session for in-depth learning and expert training.

course-img
Free Demo Class

Join our Free Demo Class to experience top-notch training and expert guidance first hand!

Purchase This Course

Request More Information

CERTIFICATE

Get Ahead With SpireTec Solutions
Training Certificate

Earn your Certificate

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Differentiate yourself with Masters Certificate

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Share your achievement

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Need Customized Curriculum?

Our course is exhaustive and this certificate is proof that you have taken a big leap in mastering the domain.

Talk To Adviser
course-certificate

Top Certifications