Data Sources, Network Attacks & Detection Techniques
Compare attack surfaces, understand the vulnerability lifecycle, and SOC integration.
TOPIC 2.2The NSM data pyramid: Alert, Statistical, Transaction, Session, and Full Packet data.
CREATE 2.3Six blind spots: Encryption, Cloud/SaaS, DoH/DoT, IoT, BYOD, and East-West traffic.
CREATEPacket capture with tcpdump, flow analysis with NetFlow, when to use each.
TOPIC 2.5Reading firewall logs, identifying attack patterns, SOC response workflows.
TOPIC 2.6URL categories, proxy logs, web filtering policies and enforcement.
CREATE 2.7Layer 7 inspection, DPI, application identification and risk assessment.
CREATEDoS, MITM, spoofing attacks with SOC detection signatures and response.
TOPIC 2.9XSS, SQLi, CSRF, command injection with OWASP context and log detection.
TOPIC 2.10Phishing, pretexting, baiting, and human-focused attack vectors.
LINKEncoding, tunneling, LOLBins, and how attackers hide their activity.
CREATE 2.12X.509 structure, PKI, certificate validation and common issues.
LINKEssential PowerShell for security operations and automation.
Process monitoring, performance analysis, security triage.
Resource Monitor, Performance Monitor, PowerShell queries.
Text processing with grep, sed, awk for log analysis.
Essential Linux CLI navigation and command fundamentals.
Service management, port investigation, security hardening.
Linux log structure, journalctl, log analysis techniques.
File permissions, ownership, and security implications.
Complete all topics and labs, then take the Week 2 assessment to test your knowledge.
Begin Evaluation