1 Course Introduction
- Introductions and course logistics
- Course objectives
2 Planning and Architecture
- Hardware and software requirements
- Architecture
- Data flows
- Server installation review
- Installing sensors
3 Server Installation & Administration
- Configuration and settings
- Carbon Black EDR users and groups
4 Process Search and Analysis
- Filtering options
- Creating searches
- Process analysis and events
5 Binary Search and Banning Binaries
- Filtering options
- Creating searches
- Hash banning
6 Search best practices
- Search operators
- Advanced queries
7 Threat Intelligence
- Enabling alliance feeds
- Threat reports details
- Use and functionality
8 Watchlists
- Creating watchlists
- Use and functionality
9 Alerts / Investigations / Response
- Using the HUD
- Alerts workflow
- Using network isolation
- Using live response