04 · Digital Forensics

SIEM & Security Operations

Building a SOC: log collection, correlation rules, alert triage and incident response with ELK and Splunk.

  • ELK & Splunk
  • Correlation rules
  • SOC playbooks

Programme outline

  1. SIEM fundamentals and architecture
  2. Log collection, parsing and normalisation
  3. Correlation rules and detection use cases
  4. Alert triage and SOC playbooks
  5. Hands-on with the ELK stack and Splunk
  6. Integrating SIEM with incident response