Security Event Triage: Detecting Network Anomalies with Behavioral Analysis

In this course on network behavioral analysis, you will explore the use of frequency, protocol, and population analysis methodologies to uncover events associated with multiple threat actors intrusions into a simulated enterprise network.

Advanced LevelSelf-Paced Learning
     
  • 4
  •  | 
  • Reviews ( 22 )
Subscription (Free Trial Available)
✓ Compare courses before making a decision
Check Latest Price →
Price may vary. Check latest price on provider site.
🧠 Best suited for advanced learners
⚠ May not be ideal for beginners

Learning Journey Context

Designed for experienced practitioners. We recommend having a solid grasp of Information Technology fundamentals before starting this specialization.

Career Relevance

Relevant for professionals pursuing roles within Information Technology.

Quick Facts

2 hour 1 minutes
pluralsight
Advanced
Self-Paced Online
Core Courses
pluralsight
English
Below sections are verified from last major sync. For real-time updates and today's latest lectures, Check official page here.

What You’ll Learn

Developing the skills necessary for a security analyst to properly detect and triage advanced network intrusion tactics and techniques requires experience and the use of advanced detection capabilities. Neither of which are easily obtained. In this course, Security Event Triage: Detecting Network Anomalies with Behavioral Analysis, you will learn foundational knowledge required to separate good network traffic from bad and identify a myriad threat actor activity on an enterprise network. First, you will learn how to use frequency analysis to detect command and control, automated logins, and beaconing. Next, you will learn to leverage protocol analysis to identify DNS tunneling, anomalous HTTPS traffic, authentication brute forcing, and DHCP abuse. Finally, you will explore the use of population analysis by harnessing machine learning to identify HTTPS exfiltration and connect the dots associated with enterprise network intrusions. When you are finished with this course, you will have the skills and knowledge of network behavioral analysis needed to detect and triage events found at multiple levels of the cyber kill chain. Create your own network behavioral analysis workstation to follow along using your own environments data using the guide located here: https://github.com/arosenmund/pluralsight/tree/master/NBAD.

This course is part of our Security Event Triage series which leverages MITRE ATT&CK to identify advance persistent threat tactics at all levels of the cyber kill chain.

See how this course curriculum compares with alternatives

Outcomes

  • Course Overview : 1min.
  • Introduction to Network Behavioral Analysis : 11mins.
  • Frequency Analysis : 33mins.
  • Protocol Analysis : 35mins.
  • Population Analysis : 25mins.
  • Detecting the Anomalies : 13mins.
See side-by-side differences in learning outcomes

FAQs

Top Alternatives

Highly-rated courses worth your attention

Security Event Triage: Detecting System Anomalies
4.0· 1 Hrs 47 minutes
Advanced
Free
Security Event Triage: Analyzing Live System Process and Files
4.0· 1 Hrs 34 minutes
Advanced
Free
Google IT Support Professional Certificate
4.8· 6 months at 10 Hrs a week
Beginner
Free
The Bits and Bytes of Computer Networking
4.7· 27 Hrs (approximately)
Beginner
Free
Google IT Automation with Python Professional Certificate
4.8· 6 months at 10 Hrs a week
Beginner
Free
Crash Course on Python
4.8· 32 Hrs (approximately)
Beginner
Free
Security Event Triage: Detecting Network Anomalies with Behavioral Analysis
4(22+ learners)
✓ Compare side-by-side before spending money
Check Latest Price →
Price may vary. Check latest price on provider site.
🧠 Best suited for advanced learners
⚠ May not be ideal for beginners