Skip to content

Details

Detection without response is just watching things burn. Tonight, we run both halves of the story back to back: first, we find it in the logs with live Splunk queries against real attack traffic from Cover6 infrastructure, then we work the full incident response lifecycle on what we just found — containment decisions, the communication chain, and the report that separates a good incident response from a career-ending one.
šŸŽÆ Part 1 — SIEM & Log Analysis

  • SPL (Search Processing Language) fundamentals – the queries you actually need
  • Building correlation searches
  • Dashboards for SOC analysts – what to monitor at a glance
  • Triage workflow – from alert to investigation to escalation

šŸŽÆ Part 2 — Incident Handling & Response

  • NIST IR lifecycle – Preparation → Detection → Containment → Eradication → Recovery → Lessons Learned
  • Containment decisions – isolate the host vs. preserve the evidence
  • Timeline reconstruction – building the attack story from logs
  • Incident communication – what to tell leadership and when
  • Lessons learned and post-incident report structure

šŸ”— Stay connected:
- Cover6 Solutions: [https://www.cover6solutions.com ](https://www.cover6solutions.com )
- YouTube (live streams + replays): https://www.youtube.com/@Cover6Solutions
- Courses and certification prep: https://cover6solutions.com/courses/

šŸŽ¤ Submit a talk/demo: https://www.papercall.io/cover6community

Rep the community → https://www.cover6solutions.com/product/cover6-shield-unisex-t-shirt/ Grab a Cover6 Shield tee and show up repping the community that helped get you here.

Related topics

Career Coaching
Cybersecurity
Information Security
Professional Networking

Sponsors

Cover6 Solutions

Cover6 Solutions

Group Organization

You may also like