inflearn logo

Complete SIEM Deployment in One Go: First Steps in Threat Hunting Using Wazuh and ELK (Basics)

From Theory to the Field: Proving Core Competencies of a Security Expert through Wazuh+ELK SIEM Implementation Design and operate a Threat Hunting system, the core of security monitoring, firsthand. Through hands-on practice based on real-world attack scenarios, transform into a professional security engineer capable of delivering immediate results in the field.

(4.9) 9 reviews

143 learners

Level Basic

Course period Unlimited

Linux
Linux
Microsoft Windows
Microsoft Windows
security
security
wazuh
wazuh
ossec
ossec
Linux
Linux
Microsoft Windows
Microsoft Windows
security
security
wazuh
wazuh
ossec
ossec

What you will gain after the course

  • Building a Real-World Threat Hunting System: You will systematically practice how to build your own threat hunting system using a combination of Wazuh and ELK (SIEM).

  • Mastering Various Integration Methods: We will deeply explore the differences between Agent and Agentless methods, their respective use cases, and implement them in practice.

  • Threat Detection with Real-World Attack Scenarios: We will conduct hands-on exercises to simulate and detect actual attacks through three scenarios: ransomware, webshells, and defacement attacks.

  • How to use Sysmon & Suricata: Practice how to further enhance the detection capabilities of a threat hunting system using Sysmon and Suricata tools.

  • Application in Real-World Security Environments: To ensure that the content learned in the lecture can be applied in the field, we deeply explore system construction and operational strategies within actual security environments.

🎯 Why is an understanding of threat hunting essential? 🎯


🔍 What is "Threat Hunting"?

Unlike traditional reactive security monitoring, threat hunting is a proactive security approach that identifies and analyzes security threats in advance to respond before an attack occurs. This refers to the process where security experts constantly monitor systems to preemptively find threats that have gone undetected.


💡 Why is threat hunting important?

Cyber attacks are becoming more sophisticated by the day. Traditional security solutions alone are becoming insufficient to counter these advanced attacks. For this reason, security experts must more proactively identify, analyze, and respond to threats. Threat hunting is the optimal methodology that fulfills this necessity.


🔐 Wazuh & ELK - An Invitation to the New World of Security!

  • You will learn how to integrate and utilize Wazuh with tools such as sysmon, suricata, and virustotal.


Wazuh and ELK are tools that allow you to perform this threat hunting process more efficiently, and they have established themselves as essential tools for threat hunting experts. By learning how to utilize Wazuh and ELK through this course, you can acquire proactive security response capabilities.


🚨 Then how is it different from general security monitoring?

While general security monitoring primarily focuses on detecting and responding to known threats, threat hunting requires the ability to discover and respond to even new, unknown threats. This goes beyond simply blocking attacks; it signifies a level of security monitoring that identifies the root cause and origin of an attack to prevent it in advance.


Are you ready to take your security skills to the next level?

This course is perfect for taking that first step. We invite you to the world of threat hunting using Wazuh and ELK! Register for the course right now and begin your journey toward becoming a security expert! 🌟🛡️🚀

Practice-oriented lectures!

Build threat hunting infrastructure in a virtual environment and practice operational skills.

We apply the essential elements of actual threat hunting based on virtual scenarios.

Check the hunted content and perform correlation analysis.

It covers how to use the dashboard and the most important methods.

We will help you follow along with the class smoothly!

  • Snapshot virtual images provided for each chapter (via Naver Drive)

  • For inquiries, feel free to contact me via Inflearn, the DISCORD '인프런_강의_위협헌팅' channel, or by sending a DM to 'Zeromini'.

  • Discord Channel: https://discord.gg/uCQEnRaSMG


Upcoming
Threat Hunting Series

By utilizing tools such as Ansible, you will advance threat hunting systems in large-scale infrastructure environments and sequentially learn threat hunting methods that reflect recent issues, such as detailed RuleSets and new malware.

Recommended for
these people

Who is this course right for?

  • For those who have basic knowledge of building security environments and want to challenge themselves to build an advanced threat hunting system: This course starts with fundamental security knowledge and allows you to systematically learn how to build an advanced threat hunting system through hands-on practice.

  • IT and security managers who want to strengthen their security infrastructure in a corporate environment: This is suitable for those who want to upgrade their corporate security to the next level by learning how to detect and respond to threats through real-world attack scenarios.

  • For those interested in security tools such as Sysmon and Suricata: you can deeply explore how to utilize these tools along with methods for the efficient operation of security systems.

  • Job seekers and students dreaming of becoming security experts: This is especially recommended for those who want to develop the security skill set required in the field. This course covers core content that can enhance your competitiveness in the security sector.

Need to know before starting?

  • Basic Security Knowledge: A fundamental understanding of common attack types, security terminology, and security philosophy will make it easier to follow the course content.

  • Basic Linux Operating Knowledge: Since the course includes content on system construction and operation in a Linux environment, you should be familiar with basic Linux commands and environment settings.

  • Log Management and Analysis: Having basic knowledge of log file structures and analysis methods will be of great help in the threat detection and analysis covered in the lecture.

  • Basic network knowledge: A fundamental understanding of the OSI 7 Layer, TCP/IP, and major protocols and ports is required.

Hello
This is zeromini

Career Verified

699

Learners

21

Reviews

74

Answers

5.0

Rating

2

Courses

Gemini_Generated_Image_g51o61g51o61g51o.png.webp

We aim for rapid employment success based on expertise.
We propose IT career development that can respond to the future.

Final Job Placement Status of ZeroMini Students

Bank of Korea, Financial Security Institute, Korea Development Bank, Korea Securities Depository, KEPCO KDN, KEPCO KPS, Korea Southern Power, National Information Society Agency, Korea Gas Corporation, Korea SMEs and Startups Agency, Korea Airports Corporation, Korea Local Information Research & Development Institute, Koscom, Korea Railroad Corporation, Korea Electric Power Corporation, Korea Water Resources Corporation, Incheon Transit Corporation, Incheon International Airport Corporation, National University Hospital, Export-Import Bank of Korea, Korea Employment Information Service, Korea Housing Finance Corporation, National Federation of Credit Guarantee Foundations, Korea Fishing Communities Organization, Government Employees Pension Service, Korea Technology Finance Fund, Samsung Securities, Naver Cloud, Korea Expressway Corporation, Korea Rural Community Corporation, Korea Financial Telecommunications & Clearings Institute, Nonghyup Bank, University IT Staff, Korea Shipping Association, Gyeongsang National University Hospital, Korea Mid-West Power, Ourhome, Korea Housing & Urban Guarantee Corporation, Korea Public Finance Information Service, Korea South-East Power, Nonghyup Information Systems, Korea Tourism Organization, Korea Trade Insurance Corporation, Korea LX, Korea Education and Research Information Service, Korea Asset Management Corporation, Health Insurance Review and Assessment Service, Korea Radioactive Waste Agency, Seoul Guarantee Insurance, National Health Insurance Service, KT, Korea Ocean Business Corporation, Korea Authority of Land & Infrastructure Safety, Human Resources Development Service of Korea, Woori Bank, Jeonbuk Bank, Kyobo Information & Communication, Seoul Design Foundation, Pusan National University Hospital, Financial Supervisory Service, Korea Energy Agency, Seoul Facilities Corporation, Korean Teachers' Credit Union, Daejeon Tourism Organization, Korea Agro-Fisheries & Food Trade Corporation, Woori Financial Capital, Korean Red Cross, Small & Medium Business Distribution Center, Korea Industrial Complex Corporation, Credit Finance Association, Korea Social Security Information Service, Korea Health Personnel Licensing Examination Institute, Korea Venture Investment, AREX, Korea Basic Science Institute, Korea Strategic Trade Institute, Korea Land and Housing Corporation, National Pension Service, Gyeonggi Credit Guarantee Foundation, Hanam Urban Corporation, Korea Power Exchange

More

Curriculum

All

24 lectures ∙ (6hr 2min)

Course Materials:

Lecture resources
Published: 
Last updated: 

Reviews

All

9 reviews

4.9

9 reviews

  • vulcanus6394님의 프로필 이미지
    vulcanus6394

    Reviews 1

    Average Rating 5.0

    5

    61% enrolled

    This is informative. It's fun and I've never seen ELK work this well...

    • zeromini
      Instructor

      Hello, this is Job Bomber Zeromini. Thank you for your valuable review ^^

  • ykg04261353님의 프로필 이미지
    ykg04261353

    Reviews 4

    Average Rating 5.0

    5

    33% enrolled

    • thejysplay8464님의 프로필 이미지
      thejysplay8464

      Reviews 1

      Average Rating 5.0

      5

      86% enrolled

      • taerim51511688님의 프로필 이미지
        taerim51511688

        Reviews 19

        Average Rating 4.9

        5

        33% enrolled

        • bangga331889님의 프로필 이미지
          bangga331889

          Reviews 22

          Average Rating 4.7

          5

          100% enrolled

          Similar courses

          Explore other courses in the same field!

          25% off for new members

          $49.40

          25%

          $59.40