SIEM & Log Analysis + Incident Handling & Response (Combined Session)
Details
Detection without response is just watching things burn. Tonight, we run both halves of the story back to back: first, we find it in the logs with live Splunk queries against real attack traffic from Cover6 infrastructure, then we work the full incident response lifecycle on what we just found ā containment decisions, the communication chain, and the report that separates a good incident response from a career-ending one.
šÆ Part 1 ā SIEM & Log Analysis
- SPL (Search Processing Language) fundamentals ā the queries you actually need
- Building correlation searches
- Dashboards for SOC analysts ā what to monitor at a glance
- Triage workflow ā from alert to investigation to escalation
šÆ Part 2 ā Incident Handling & Response
- NIST IR lifecycle ā Preparation ā Detection ā Containment ā Eradication ā Recovery ā Lessons Learned
- Containment decisions ā isolate the host vs. preserve the evidence
- Timeline reconstruction ā building the attack story from logs
- Incident communication ā what to tell leadership and when
- Lessons learned and post-incident report structure
š Stay connected:
- Cover6 Solutions: [https://www.cover6solutions.com ](https://www.cover6solutions.com )
- YouTube (live streams + replays): https://www.youtube.com/@Cover6Solutions
- Courses and certification prep: https://cover6solutions.com/courses/
š¤ Submit a talk/demo: https://www.papercall.io/cover6community
Rep the community ā https://www.cover6solutions.com/product/cover6-shield-unisex-t-shirt/ Grab a Cover6 Shield tee and show up repping the community that helped get you here.
