Blue Team
SOC & Blue Team Operations
Bangun dan operasikan Security Operations Center profesional
Selamat Datang di SOC & Blue Team Operations
Kursus ini terdiri dari 30 pelajaran dalam 6 modul. Pilih salah satu pelajaran dari daftar di samping untuk mulai belajar.
6
Modul
30
Pelajaran
16 jam
Durasi
Intermediate
Level
Tujuan Pembelajaran
- Mampu merancang arsitektur SOC yang efektif
- Menguasai SIEM management dan use case development
- Memahami incident response lifecycle dan execution
- Mampu melakukan threat hunting secara proaktif
- Mengelola tim dan operasional SOC sehari-hari
Modul Pembelajaran
Modul 1 5 pelajaran
SOC Fundamentals & Architecture
- SOC Models dan Tingkat Kematangan
- SOC Team Structure dan Roles
- Tool Stack: SIEM, EDR, NDR, SOAR, TI Platform
- +2 pelajaran lainnya
Modul 2 5 pelajaran
SIEM Management & Use Case Development
- SIEM Architecture: Splunk, Elastic, Wazuh
- Log Parsing, Normalization, dan Enrichment
- Detection Use Case Development Lifecycle
- +2 pelajaran lainnya
Modul 3 5 pelajaran
Threat Detection & Analysis
- Network Threat Detection - IDS/IPS Signatures
- Endpoint Detection dan EDR Analysis
- Email Security Analysis
- +2 pelajaran lainnya
Modul 4 5 pelajaran
Incident Response
- Incident Response Lifecycle (NIST 800-61)
- Triage, Containment, Eradication, Recovery
- Digital Forensics untuk Incident Responder
- +2 pelajaran lainnya
Modul 5 5 pelajaran
Threat Intelligence & Hunting
- Threat Intelligence Feeds dan TAXII/STIX
- MISP Platform untuk Threat Intel Sharing
- Threat Hunting Methodology
- +2 pelajaran lainnya
Modul 6 5 pelajaran
SOAR & Automation
- SOAR Platform Fundamentals (TheHive, Shuffle)
- Playbook Development dan Automation
- Case Management dan Ticketing Integration
- +2 pelajaran lainnya