Overview
This one-day course teaches you how to use the VMware Carbon Black® EDR™ product and leverage the capabilities to configure and maintain the system according to your organization’s security posture and policies.
This course provides an in-depth, technical understanding of the Carbon Black EDR product through comprehensive coursework and hands-on scenario-based labs.
Prerequisites
There are no prerequisites for this course.
Who Should Attend?
System administrators and security operations personnel, including analysts and managers
Course Outline
- Introductions and course logistics
- Course objectives
- Hardware and software requirements
- Architecture
- Data flows
- Server installation review
- Installing sensors
- Configuration and settings
- Carbon Black EDR users and groups
- Filtering options
- Creating searches
- Process analysis and events
- Filtering options
- Creating searches
- Hash banning
- Search operators
- Advanced queries
- Enabling alliance feeds
- Threat reports details
- Use and functionality
- Creating watchlists
- Use and functionality
- Using the HUD
- Alerts workflow
- Using network isolation
- Using live response