Курс от CourseraRun incident response with speed and rigor. You will classify events per policy, execute playbooks for containment/eradication/recovery, triage SIEM/EDR/IDS alerts, and document evidence and timelines using tools like VirusTotal, Suricata, Splunk, Chronicle, and EDR consoles. This course blends Google and IBM perspectives. You will progress from IR fundamentals and playbook execution to procedure design and automation, then to alert correlation across network and endpoint telemetry. Ideal for SOC and IR professionals. You’ll produce consistent classifications, repeatable response actions, stakeholder‑ready reports, and documented decisions that accelerate containment and lessons learned.
8 модулей · 129 учебных материалов

Преподаватель курса