L3 SOC Analyst: AWS Incident Investigation with Splunk

Master AWS incident investigation using Splunk: from data integration to automated response, elevate your SOC analyst skills.

Setting Up the Foundation: AWS Data Sources and Splunk Integration

Unit 1: AWS Data Sources for Security

Unit 2: Splunk Integration with AWS

Unit 3: Best Practices for AWS Data in Splunk

Threat Detection: Crafting Splunk Queries for AWS Security Monitoring

Unit 1: Splunk Query Fundamentals for AWS Security

Unit 2: Detecting Suspicious Activity in AWS

Unit 3: Creating Dashboards and Alerts

Incident Investigation: Analyzing and Responding to AWS Security Events

Unit 1: Investigating Unauthorized Access

Unit 2: Analyzing Data Breaches

Unit 3: Compromised EC2 Instances

Unit 4: Incident Response Procedures

Automation and Reporting: Enhancing Incident Response with SOAR and AWS Security Services

Unit 1: SOAR Integration with Splunk and AWS

Unit 2: AWS Security Services and Splunk

Unit 3: Incident Reporting and Lessons Learned