Course Details
Course Outline
1 - Course Introduction
Introductions and course logisticsCourse objectives
2 - VMware Carbon Black EDR & Incident Response
Framework identification and process
3 - Preparation
Implement the Carbon Black EDR instance according to organizational requirements
4 - Identification
Use initial detection mechanismsProcess alertsProactive threat huntingIncident determination
5 - Containment
Incident scopingArtifact collectionInvestigation
6 - Eradication
Hash banningRemoving artifactsContinuous monitoring
7 - Recovery
Rebuilding endpointsGetting to a more secure state
8 - Lessons Learned
Tuning Carbon Black EDRIncident close out
Actual course outline may vary depending on offering center. Contact your sales representative for more information.
Who is it For?
Target Audience
Security operations personnel, including analysts and incident responders
Prerequisites