***************MAKE YOUR OWN ICS SIEM/SOC LAB SETUP WITHOUT HARDWARE*************
After three theoretical courses, I introduce you to one of the full practical courses for OT/ICS SIEM/SOC solution creation.
This course is totally practical, in all chapters we are installing, configuring, or deploying something on machines located in azure infrastructure, and it is simple, I promise.
We will cover some key concepts of ICS Cybersecurity from end to end deployment which are as follows:
-
Security information and event management (SIEM): Elasticsearch Logstash Kibana (ELK Stack)
-
SIEM Dashboarding/ Query: Kibana
-
NOC- Network Monitoring/ Operations Dashboarding: Grafana
-
EDR/HIDS : Endpoint Detection and Response/ Host Intrusion Detection: Wazuh
-
Log Management: Beats/Sysmon (Log collector for Windows Event logs and more)
-
Asset Management: OSQuery : FleetDM
-
Endpoint Visibility: Sysmon
-
Malware Detection: Strelka
-
Firewall: pfsense (Firewall)
-
IPS-Intrusion Prevention System: Snort Based
-
Nmap for network based queries
-
Vulnerability Management: Using Nessus
-
Active Directory : Windows Server
-
WSUS : Windows Server Update Services
-
Modbus Communication
-
DNP3 communication
-
OPC Server Client Communication
And this is a dynamic list, and with time keeps on updating and increasing to increase coverage.
The environment is deployed on Azure with the cheapest region and minimum resource requirements. All the steps are guided and well explained so that you can follow and create your own ICS SOC easily. after doing this course you will have a good understanding of cybersecurity technologies that are in use in the ICS landscape as well as in the overall industrial control system environment. You can run all types of tests and simulate this environment, you can also install applications from your organization to test in a similar mode.
–
There are no reviews yet.