Cortex XDR: Investigation and Response (EDU-262)

 

Course Overview

The first part of this instructor-led training enables you to investigate attacks from Cortex XDR management console pages, including the Incidents page and specialized artifact analysis views such as the IP View. In the first part, you will also learn how to run remote Python scripts on your endpoints.

The second part of the training enables you to work with Cortex XDR data processing capabilities to protect your environment against advanced threats such as fileless attacks. For example, in this part you will analyze alerts in the Causality View. Also, you will learn about Cortex XDR data collection capabilities, including Cortex XDR API for ingesting external alerts, and leverage the data to investigate threats. The training ends up with introductory modules to XDR Query Language XQL and two Pro features based-on Cortex XDR XQL engine.

Who should attend

Cybersecurity analysts and engineers, and security operations specialists

Prerequisites

Participants must have taken the course EDU-260 (Cortex XDR: Prevention and Deployment)

Course Objectives

Successful completion of this instructor-led course with hands-on lab activities should enable the students to:

  • Investigate attacks on the incidents page, and score, assign, and close them
  • Investigate artifacts using the specialized views such as IP View and Hash View
  • Work with Cortex XDR Pro actions: the remote script execution and EDL service
  • Describe the Cortex XDR causality and analytics concepts
  • Analyze alerts using the Causality and Timeline Views
  • Create and manage on-demand and scheduled search queries in the Query Center
  • Create and manage the Cortex XDR rules BIOC and IOC
  • Work with the Cortex XDR’s external data ingestion support
  • Write XQL queries to search datasets and visualize the result sets
  • Create simple Correlation Rules and Parsing Rules using XQL

Course Content

  • 1. Cortex XDR Incidents
  • 2. Investigation Views
  • 3. Advanced Response Actions
  • 4. Causality and Analytics Concepts
  • 5. Causality Analysis of Alerts
  • 6. Building Basic Search Queries
  • 7. Building Basic XDR Rules
  • 8. External Data Collection
  • 9. Introduction to XQL
  • 10. Correlation and Parsing Rules

Prijs & Delivery methods

Online training

Duur
2 dagen

Prijs
  • 1.895,– €
Klassikale training

Duur
2 dagen

Prijs
  • Nederland: 1.895,– €
  • België: 1.895,– €

Beschikbare data

Fast Lane will carry out all guaranteed training regardless of the number of attendees, exempt from force majeure or other unexpected events, like e.g. accidents or illness of the trainer, which prevent the course from being conducted.
Instructor-led Online Training:   Dit is een Instructor-Led Online (ILO) training: een online training verzorgd door een trainer.
Dit is een FLEX-training: een training die zowel klassikaal als online gevolgd kan worden. Je kiest zelf de gewenste leervorm.

Engels

Tijdzone: Midden-Europese Tijd (MET)   ±1 uur

Online training Tijdzone: Greenwich Mean Time (GMT)
Online training Tijdzone: British Summer Time (BST)
Online training Tijdzone: British Summer Time (BST)
Online training Tijdzone: Greenwich Mean Time (GMT)

6 uur tijdsverschil

Online training Tijdzone: Eastern Standard Time (EST)
Online training Tijdzone: Eastern Standard Time (EST)

7 uur tijdsverschil

Online training Tijdzone: Central Daylight Time (CDT)
Online training Tijdzone: Central Daylight Time (CDT)
Online training Tijdzone: Central Standard Time (CST)
Online training Tijdzone: Central Standard Time (CST)

9 uur tijdsverschil

Online training Tijdzone: Pacific Daylight Time (PDT)
Online training Tijdzone: Pacific Daylight Time (PDT)
Fast Lane will carry out all guaranteed training regardless of the number of attendees, exempt from force majeure or other unexpected events, like e.g. accidents or illness of the trainer, which prevent the course from being conducted.
Dit is een FLEX-training: een training die zowel klassikaal als online gevolgd kan worden. Je kiest zelf de gewenste leervorm.

Europa

Duitsland

Gegarandeerde doorgang Hamburg Dit is een FLEX-training.   Tijdzone: Midden-Europese Tijd (MET) boek direct:
de online FLEX-training
de klassikale FLEX-training
Berlijn Dit is een FLEX-training.   Tijdzone: Midden-Europese Tijd (MET) boek direct:
de online FLEX-training
de klassikale FLEX-training
Frankfurt Dit is een FLEX-training.   Tijdzone: Midden-Europese Zomertijd (MEZT) boek direct:
de online FLEX-training
de klassikale FLEX-training
München Dit is een FLEX-training.   Tijdzone: Midden-Europese Zomertijd (MEZT) boek direct:
de online FLEX-training
de klassikale FLEX-training
Hamburg Dit is een FLEX-training.   Tijdzone: Midden-Europese Zomertijd (MEZT) boek direct:
de online FLEX-training
de klassikale FLEX-training