К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Security Incident Detection and Response · LearnSpace
Назад в каталог
courseraIT и технологии

Security Incident Detection and Response

Курс от Coursera
Уровень не указан≈ 16.3 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

Run incident response with speed and rigor. You will classify events per policy, execute playbooks for containment/eradication/recovery, triage SIEM/EDR/IDS alerts, and document evidence and timelines using tools like VirusTotal, Suricata, Splunk, Chronicle, and EDR consoles. This course blends Google and IBM perspectives. You will progress from IR fundamentals and playbook execution to procedure design and automation, then to alert correlation across network and endpoint telemetry. Ideal for SOC and IR professionals. You’ll produce consistent classifications, repeatable response actions, stakeholder‑ready reports, and documented decisions that accelerate containment and lessons learned.

Навыки, которые вы освоите

SplunkComputer Security Incident ManagementGenerative AIAnomaly DetectionThreat DetectionTechnical DocumentationIntrusion Detection and PreventionAI SecurityIT AutomationDigital ForensicsEvent MonitoringSecurity Information and Event Management (SIEM)Technical CommunicationEndpoint Detection and ResponseNetwork AnalysisIncident ResponseIncident Management

Программа курса

8 модулей · 129 учебных материалов

01Start Here: Get Oriented and Check Your Skills2 материалов
Start Here: How This Skill-Based Course WorksЧтениеSkill Diagnostic: Find Your Recommended Starting PointЗадание
02Incident Investigation and Response30 материалов

Incident detection and verification

Welcome to moduleВидео

Учитесь у экспертов

Professionals from the Industry

Преподаватель курса

Security Incident Detection and Response
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 16.3 ч

8 модулей

Язык: Английский

Субтитры: Арабский, Французский, Украинский, Бразильский португальский, Вьетнамский, Корейский, Немецкий, Индонезийский, Турецкий, Испанский, Японский

Часть программы вашего университета
The detection and analysis phase of the lifecycle Видео
Cybersecurity incident detection methodsЧтение
Ongoing Monitoring of CI/CDЧтение
MK: Changes in the cybersecurity industryВидео
Indicators of compromiseЧтение
Identify: Indicators of compromisePLUGIN
Analyze indicators of compromise with investigative toolsЧтение
Activity: Investigate a suspicious file hashЗадание
Activity Exemplar: Investigate a suspicious file hashЧтение
Test your knowledge: Incident detection and verificationЗадание

Create and use documentation

The benefits of documentation ВидеоDocument evidence with chain of custody forms ВидеоBest practices for effective documentation ЧтениеThe value of cybersecurity playbooks ВидеоActivity: Use a playbook to respond to a phishing incidentЗаданиеActivity Exemplar: Use a playbook to respond to a phishing incidentЧтение

Response and recovery

The role of triage in incident response ВидеоRobin: Foster cross-team collaborationВидеоThe triage process ЧтениеThe containment, eradication, and recovery phase of the lifecycleВидеоBusiness continuity considerationsЧтениеTest your knowledge: Response and recoveryЗадание

Post-incident actions

The post-incident activity phase of the lifecycle ВидеоPost-incident review ЧтениеActivity: Review a final reportЗаданиеIdentify: Explore an incident event timelinePLUGINTest your knowledge: Post-incident actions Задание

Review: Incident investigation and response

Wrap-up ВидеоGlossary terms from moduleЧтение
03Skill Assessment 13 материалов
Practice for SOC Triage and EscalationЗаданиеLearner Expectations for AssessmentЧтениеCheckpoint 1 of 3: SOC Triage and EscalationЗадание
04Incident Response Management and Attack Mitigation27 материалов

Evidence preservation in investigations

Welcome to module 3ВидеоThe importance of evidence preservationВидеоDigital evidence preservation: Techniques and best practicesЧтениеHow security teams preserve evidenceВидеоTest your knowledge: Evidence preservationЗадание

Incident management

Incident response in Google CloudВидеоIncident response best practices with Chronicle SOARЧтениеIncident identificationВидеоCoordination for incident responseВидеоGuide to log queries, exports, and analysisЧтениеTest your knowledge: Incident managementЗадание

Documentation

Documentation fundamentalsВидеоElements of successful documentationВидеоDocumentation in practiceЧтениеActivity: Document a timeline of eventsЧтениеActivity Quiz: Document a timeline of eventsЗаданиеActivity Exemplar: Document a timeline of eventsЧтение

Response in action using automation

Actionable alert identificationВидеоIncident response partnersЧтениеSecurity orchestration with playbooksВидеоIncident response orchestration versus automationЧтениеPlaybooks' role in incident responseЧтениеFatima: A day in the life of a detection and response team managerВидео

Review: Incident response management and attack mitigation

Wrap-upВидеоGlossary terms from moduleЧтение
05SIEM and SOC Tasks Using Generative AI 29 материалов

Using Generative AI for incident response

Triage Potential Incidents, Analyze Logs, and Assist InvestigationsВидеоReading: Incident Response Using Generative AIPLUGINHands-on Lab: Incident Response and Alerts Generation Using Generative AIВнешний инструментEnhancing Vulnerability Management with Generative AI ВидеоExpert Viewpoints: AI Systems for Incident ResponseВидеоDemo: Augmenting Threat Hunting and Security Analysis ВидеоDemo: Streamlining Vulnerability ManagementВидеоLesson 1 Summary: Using Generative AI for Incident ResponseЧтениеLesson 1 Practice Quiz: Using Generative AI for Incident ResponseЗадание

Integrating Generative AI Models with Security Systems

Advanced Threat Detection Using Generative AI in SIEM ВидеоWays to Integrate Generative AI into SIEM ВидеоReading: ChatGPT with QRadar/any SIEM toolPLUGINReading: Optimizing Cybersecurity with Generative AI Integration in SIEMPLUGINHands-on Lab: Training Generative AI with Incident Data for Better Pattern RecognitionPLUGINDecoding UBEA Using Generative AI Видео

Ethics, Issues, Considerations for using Generative AI for Cybersecurity

Issues, Concerns, and Considerations Using Generative AI in CybersecurityВидеоEthical Concerns of AI in CybersecurityВидеоTips for Cybersecurity ProfessionalsВидеоReading: Generative AI and Cybersecurity: Balancing Benefits and Ethical ConcernsPLUGINExpert Viewpoints: Responsible Use of Generative AI in CybersecurityВидеоLesson 3 Summary: Ethics, Issues, Considerations for Using Generative AI for CybersecurityЧтение
06Skill Assessment 23 материалов

Lesson

Practice for Advanced Incident Response OperationsЗаданиеLearner Expectations for AssessmentЧтениеCheckpoint 2 of 3: Advanced Incident Response OperationsЗадание
07Network Traffic and Logs using IDS and SIEM Tools32 материалов

Overview of logs

Welcome to moduleВидеоThe importance of logs ВидеоBest practices for log collection and managementЧтениеTest your knowledge: Overview of logsЗаданиеRebecca: Learn new tools and technologiesВидеоVariations of logs ВидеоOverview of log file formatsЧтениеIdentify: Match log files to their file formatPLUGINTest your knowledge: Log components and formatsЗадание

Overview of intrusion detection systems (IDS)

Security monitoring with detection tools Видео Detection tools and techniquesЧтениеGrace: Security mindset in detection and responseВидеоComponents of a detection signature ВидеоExamine signatures with SuricataВидеоExamine Suricata logsВидео

Overview of security information event management (SIEM) tools

Reexamine SIEM toolsВидеоLog sources and log ingestionЧтениеQuery for events with SplunkВидеоQuery for events with Google SecOpsВидеоSearch methods with SIEM toolsЧтениеFollow-along guide for Wazuh setupЧтение

Review: Network traffic and logs using IDS and SIEM tools

Coach dialogue: Explore network security technologiesDIALOGUEWrap-up ВидеоGlossary: Network traffic and logs using IDs and SIEM ToolsЧтениеPortfolio Activity Exemplar: Finalize your incident handler's journalЧтение
08Skill Assessment 33 материалов

Lesson

Practice for Alert Triage and ContainmentЗаданиеLearner Expectations for AssessmentЧтениеCheckpoint 3 of 3: Alert Triage and ContainmentЗадание
Test your knowledge: DocumentationЗадание
Test your knowledge: Response in action using automationЗадание
Reading: SOAR in Cybersecurity: Enhancing Security Operations with Generative AIPLUGIN
Reading: Securing the Future with Generative AI: Building Proactive and Cost-effective Cybersecurity SolutionsPLUGIN
Demo: Real-Time Assistance Using Generative AI Видео
Hands-on Lab: Using Generative AI for Threat Intelligence PLUGIN
Expert Viewpoints: AI and Threat PredictionВидео
Lesson 2 Summary: Integrating Generative AI Models with Security SystemsЧтение
Lesson 2 Practice Quiz: Integrating Generative AI Models with Security SystemsЗадание
Lesson 3 Practice Quiz: Ethics, Issues, Considerations for Using Generative AI for CybersecurityЗадание
Overview of SuricataЧтение
Activity: Explore signatures and logs with SuricataВнешний инструмент
Optional Exemplar: Explore signatures and logs with SuricataВнешний инструмент
Exemplar: Explore signatures with SuricataЧтение
Test your knowledge: Overview of intrusion detection systems (IDS) Задание
Activity: Perform a query with WazuhЗадание
Test your knowledge: Overview of SIEM toolsЗадание