Detection and Response with XDR: Integrated Security Solutions to Combat Emerging Threats

Detection and Response with XDR: Integrated Security Solutions to Combat Emerging Threats

3h 50mIntermediate2025-01-30

Authors

Pearson

Pearson

Katherine McNamara

Katherine McNamara

Steven McNutt

Steven McNutt

Matt Vander Horst

Matt Vander Horst

Course details

Modern security operations face a rapidly evolving threat landscape, making it difficult to gain complete visibility across an array of disparate security tools. Extended detection and response, also known as XDR, can help to bridge that gap by centralizing telemetry, intelligence, and response capabilities from a variety of sources into a single security platform. In this course, join instructors Matt Vander Horst, Steven McNutt, and Katherine McNamara as they explore why XDR is such a game-changer for reducing your detection and response times and optimizing your overall security operations. Along the way, discover practical strategies for implementing XDR within your organization. An ideal fit for cybersecurity professionals, regardless of your technical background or level of experience, this course is designed to equip you with the skills you need to successfully design, implement, and automate threat responses using cutting-edge XDR technology.

Learning objectives
Identify modern cybersecurity threats and vulnerabilities.
Understand how XDR enhances visibility across products and technologies.
Utilize XDR's investigation features to detect and manage breaches.
Leverage automation to isolate and remediate threats swiftly.

Skills covered

Governance, Risk, and ComplianceIncident ResponseCybersecurityOne-Off

Concepts

Introduction

  • Detection and response with XDR - Introduction

The Modern Security Operations Center

  • Module 1 - Security operations and tooling introduction
  • Learning objectives
  • Describe the goals of the SOC
  • Describe SOC organization
  • Describe SOC roles and responsibilities
  • Describe SOC process flow

Security Operations Concepts and Tooling

  • Learning objectives
  • Describe the basics of the NIST Cybersecurity Framework (CSF)
  • Describe major categories of threats
  • Describe major categories of controls
  • Identify some popular open-source tools and their functions

Computer Security Incident Response Teams (CSIRT)

  • Learning objectives
  • Describe the goals of a CSIRT
  • Appreciate the differences between a SOC and a CSIRT

Trends and Challenges

  • Module 2 - Extended detection and response (XDR) introduction
  • Learning objectives
  • Describe the limitations of existing solutions
  • Identify some of the top roadblocks with existing tools
  • Describe the limitations with SIEMs
  • Describe the limitations with SOARs

Introducing XDR

  • Learning objectives
  • Describe the basics of XDR
  • Describe the goals of XDR
  • Describe Cisco's secure approach to XDR
  • Identify the components of XDR
  • Appreciate XDR's differences from a SIEM and SOAR
  • Describe XDR's real-world outcomes

XDR's Integrated Security Stack

  • Learning objectives
  • Identify the goals of an integrated security stack
  • Appreciate XDR's native and third-party compatibility
  • Describe XDR's REST APIs
  • Describe XDR's detection analytics
  • Describe XDR's remediation capabilities
  • Describe XDR's orchestration and automation capabilities
  • Describe an effective XDR solution

Threat Hunting

  • Module 3 - XDR with Cisco introduction
  • Learning objectives
  • Describe the PICERL model
  • Describe the MITRE Framework
  • Describe adversary tactics, techniques, and procedures (TTPs)
  • Identify the tools and techniques for threat hunting

Investigating an Incident

  • Learning objectives
  • Describe an incident in XDR
  • Describe incident priority and MITRE tactics
  • Identify the components of an incident
  • Interact with Cisco XDR's attack graph
  • Identify correlating data using XDR

Responding to an Incident

  • Learning objectives
  • Appreciate the value of Cisco XDR integrations for response
  • Describe how XDR can respond to an incident
  • Understand incident response playbooks

What Is Security Automation

  • Module 4 - Security automation introduction
  • Learning objectives
  • Describe the advantages of security automation
  • Describe the roles of AI and machine learning

How Does Automation Fit into XDR

  • Learning objectives
  • Understand threat hunting and alert investigation
  • Describe response actions

Cisco XDR Automation

  • Learning objectives
  • Describe XDR automation and its usage
  • Explain automation components
  • Explore the workflow editor
  • Explain a workflow run and troubleshooting

Conclusion

  • Detection and response with XDR - Summary
80,000 Toman