This 5-day course teaches you how to install, configure, and manage the VMware Carbon Black® Portfolio suite of products, which include:
You learn how to use the capabilities of the products according to the organization’s security posture and organizational policies. This course provides an in-depth, technical understanding of the Carbon Black Portfolio through comprehensive coursework, hands-on labs, and scenario-based exercises.
By the end of the course, you should be able to meet the following objectives:
System administrators and security operations personnel (including analysts and managers)
35 godzin (5 dni x 7 godzin), w tym wykłady i warsztaty praktyczne.
1. Course Introduction
• Introductions and course logistics
• Course objectives
2. VMware Carbon Black App Control Administrator
• Login Accounts and Groups
• Policies
• Computer Details
• Custom Rules
• Tools
• Events
• Baseline Drift
3. VMware Carbon Black EDR
• Planning and Architecture
• Server Installation & Administration
• Process Search and Analysis
• Binary Search and Banning Binaries
• Search best practices
• Threat Intelligence
• Watchlists
• Alerts / Investigations / Responses
4. VMware Carbon Black Cloud Endpoint Standard
• Data Flows and Communication
• Searching Data
• Policy Components
• Prevention Capabilities Using Rules
• Processing Alerts
• Response Capabilities
5. VMware Carbon Black Cloud Enterprise EDR
• Managing Watchlists
• Alert Processing
• Threat Hunting in Enterprise EDR
• Response Capabilities
6. VMware Carbon Black Cloud Audit and Remediation
• Query Basics
• Recommended Queries
• SQL Basics
• Filtering Results
• Basic SQL Queries
• Advanced Search Capabilities
• Response Capabilities