December 2017
Beginner
330 pages
9h 1m
English
Being able to collect an incredible amount of log data from your organization's information systems is ultimately not the goal of the SOC. The goal is to take this information and, in a repeatable fashion, effectively analyze available information to detect whether an information security threat exists on the enterprise network.
This is where indicators of compromise are used to inform your information security tools (via correlation rules) and personnel to look for threats on the enterprise network. Indicators of compromise can be found within:
Read now
Unlock full access