This VMware Carbon Black EDR Advanced Analyst training course teaches to use the VMware Carbon Black EDR product for incident response. Using the SANS PICERL framework, you will configure the server and perform an investigation on a possible incident. This course provides guidance on using Carbon Black EDR capabilities throughout an incident with an in-depth, hands-on, scenario-based lab.
By attending VMware Carbon Black EDR Advanced Analyst workshop, delegates will learn to:
- Utilize Carbon Black EDR throughout an incident
- Implement a baseline configuration for Carbon Black EDR
- Determine if an alert is a true or false positive
- Fully scope out an attack from moment of compromise
- Describe Carbon Black EDR capabilities available to respond to an incident
- Create addition detection controls to increase security
- VMware Carbon Black EDR Administrator
The VMware Carbon Black EDR Advanced Analyst class is ideal for:
- Security operations personnel, including analysts and incident responders