Skip to content
fernet.consultores

Training & Certification

Splunk Enterprise Security Training.

Training in Splunk Enterprise Security for SOC analysts and administrators.

The problem we solve.

Enterprise Security offers far more than is typically used. Without training, analysts work alerts one by one and administrators don't make the most of risk-based alerting or the available content.

What’s included.

  • Analyst workflow
  • Investigations and risk-based alerts
  • Data models and CIM
  • Assets, identities and threat intelligence
  • Detection content and tuning

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We assess the group's starting level and what they need to be able to do by the end.

We design the programme: syllabus, exercises, practice environment and schedule.

We deliver the sessions with guided investigations and configuration exercises.

The group completes a full investigation from start to finish.

We gather feedback and results and refine the programme for future editions.

Technical capabilities.

  • Splunk Enterprise Security
  • Risk-Based Alerting
  • Common Information Model
  • Enterprise Security Content Update
  • MITRE ATT&CK
  • Splunk SOAR

Use cases.

SOC analysts

Investigate faster and with more context.

ES administrators

Configure and maintain the platform.

New rollout

Prepare the team before go-live.

Benefits for your organisation.

  • Faster investigations
  • Better use of the platform
  • Less noise
  • A team ready for audits

Deliverables.

  • Course materials
  • Practical cases
  • Investigation guides
  • Final assessment

Frequently asked questions.

Is it for analysts or administrators?

We have content for both profiles; we tailor it to who attends.

Do you practise on real attacks?

With simulated scenarios prepared for the course, reproducing real techniques without risk to your environment.

Shall we talk about Enterprise Security Training?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service