Security Onion Fundamentals for Analysts & Admins Tampa FL - Jun 25-28 2024

Security Onion Fundamentals for Analysts & Admins Tampa FL - Jun 25-28 2024

Learn how to architect, manage, deploy, and effectively use Security Onion in this 4-day course, June 25-28, 2024.

By Security Onion Solutions LLC

Date and time

June 25 · 8am - June 28 · 5pm EDT

Location

Stetson Tampa Law Center

1700 North Tampa Street Tampa, FL 33602

Refund Policy

Contact the organizer to request a refund.
Eventbrite's fee is nonrefundable.

About this event

  • 3 days 9 hours

About Security Onion

Security Onion is a free and open platform built by defenders for defenders. It includes network visibility, host visibility, intrusion detection honeypots, log management, and case management. Security Onion has been downloaded over 2 million times and is being used by security teams around the world to monitor and defend their enterprises. Our easy-to-use Setup wizard allows you to build a distributed grid for your enterprise in minutes!

For more about Security Onion, please see https://securityonion.com

About the Course

This course is geared for analysts and administrators of Security Onion 2.4. Students will gain a foundational understanding of the platform - how to architect, deploy, and manage their Security Onion grid. The course also covers major analyst workflows, reinforced through real-world case studies.

  • 4 full days of class instruction from the developers of Security Onion
  • 300+ pages of course material
  • Certificate of Completion

When is the class?

Tuesday, June 25, 2024 through Friday, June 28, 2024

8-hour class with a one hour lunch from 8:00 AM - 5:00 PM (Eastern Time) each day

When does registration close?

Registration closes Monday, June 10, 2024, at 11:59 PM US Eastern Time.

Where is the class being held?

The class is being held at Stetson Tampa Law Center, 1700 N Tampa St, Tampa, FL 33602.

What hardware, etc. will be required for the class?

Security Onion Solutions will provide laptops for use during the course.

Which version of Security Onion will we be using?

We will use the latest Security Onion 2.4 release as of May 20, 2024.

You don't need it for the class, but the latest stable release can be found here: https://securityonion.com/download

What skills/knowledge should students have before attending this course?

Students should attend the free 2-hour Security Onion Essentials course before the first day of class. One topic covered by this course is building a Security Onion VM. Note that students do not need to build a Security Onion VM for this class. We will be using a pre-installed virtual lab.

Students should have a basic understanding of networks, TCP/IP, and standard protocols such as DNS, HTTP, etc. Some Linux knowledge/experience is recommended, but not required.

What's the cancellation policy?

Security Onion Solutions reserves the right to cancel this class up to one day after registration closes if the class does not meet a minimum number of students. If class is canceled, the training ticket cost will be refunded.

What's the refund policy?

You may log into your Eventbrite account to request a refund up until the last day of ticket sales. Please use the "Request a Refund" button as shown here: https://www.eventbrite.com/support/articles/en_US/How_To/can-i-get-a-refund

Are there discounts available?

There are no discounts available for this course.

Does the class prepare students to pass the Security Onion Certified Professional (SOCP) exam?

Yes! In conjunction with the official Security Onion Documentation book, the instruction and associated course materials from this class will prepare you for the SOCP exam.

What topics are covered in this class?

Note: Syllabus is subject to change

  • Security Onion Console
  • Security Onion System Architecture
  • Security Onion Workflows
    + Alert Triage & Case Creation with SOC Alerts and Cases
    + Threat Hunting with SOC Hunt and Dashboards
    + Detection Engineering with Playbook
  • Grid Management
    + Users
    + Firewalls
    + Monitoring
    + Troubleshooting
  • Tuning the Grid
    + Berkeley Packet Filters
    + Performance Tuning - Zeek and Suricata
    + Data Pipeline Tuning - Curator, Logstash, and Elasticsearch
    + Alert Tuning - Suricata and Playbook
  • Integrating Endpoint Telemetry
  • Managing Zeek
    + Logs
    + Scripts
  • Multiple Labs and Case Studies

Organized by

$3,798