Курс от CourseraTurn detections and incident lessons into continuous improvement. You will analyze post‑incident findings, perform threat hunting with intelligence, validate IDS/IPS alerts, detonate files in sandboxes to extract IOCs, and verify endpoint protection health to strengthen coverage. This course draws on IBM and Google Cloud content. You will progress from incident reviews and forensics to intelligence‑led hunts and network analytics, then to sandbox‑assisted investigations and operational EPP checks. Great for detection engineers and SOC analysts. You’ll deliver new rules/use cases, refined signatures, IOC-driven hunts, and health reports that measurably improve detection fidelity and response speed.
10 модулей · 90 учебных материалов

Преподаватель курса