We are happy to advise you!
+43 1 6000 880-0     Contact

Cortex XDR 2: Prevention, Analysis, and Response (EDU-260)

 

Who should attend

Cybersecurity analysts and engineers, and security operations specialists

Prerequisites

Participants must be familiar with enterprise security concepts.

Course Objectives

This course is three days of instructor-led training that will help you to:

  • Differentiate the architecture and components of the Cortex XDR family
  • Describe Cortex, Cortex Data Lake, the Customer Support Portal, and the hub
  • Activate Cortex XDR, deploy the agents, and work with the management console
  • Work with the Cortex XDR management console, describe a typical management page, and work with the tables and filters
  • Create Cortex XDR agent installation packages, endpoint groups, policies, and profiles
  • Create and manage exploit and malware profiles, and perform response actions
  • Describe detection challenges with behavioral threats
  • Differentiate the Cortex XDR rules BIOC and IOC, and create and manage them
  • Describe the Cortex XDR causality analysis and analytics concepts
  • Triage and investigate alerts and incidents, and create alert starring and exclusion policies
  • Work with the Causality and Timeline Views and investigate threats in the Query Center

Successful completion of this instructor-led course with hands-on lab activities should enhance the student’s understanding of how to activate a Cortex XDR instance; create agent installation packages to install the Cortex XDR agents; create security policies and profiles to protect endpoints against multi-stage, fileless attacks built using malware and exploits; respond to attacks using response actions; understand behavioral threat analysis, log stitching, agent-provided enhanced endpoint data, and causality analysis; investigate and triage attacks using the incident management page of Cortex XDR and analyze alerts using the Causality and Timeline analysis views; use API to insert alerts; create BIOC rules; and search a lead in raw data sets in Cortex Data Lake using Cortex XDR Query Builder.

Course Content

  • 1. Cortex XDR Family Overview
  • 2. Working with the Cortex Apps
  • 3. Getting Started with Endpoint Protection
  • 4. Malware Protection
  • 5. Exploit Protection
  • 6. Exceptions and Response Actions
  • 7. Behavioral Threat Analysis
  • 8. Cortex XDR Rules
  • 9. Incident Management
  • 10. Alert Analysis Views
  • 11. Search and Investigate
  • 12. Basic Troubleshooting
Online Training

Duration 3 days

Classroom Training

Duration 3 days

Price (excl. tax)
  • Germany:
    Country: DE
    2,100.- €

Schedule

Austria

Currently no local training dates available.  For enquiries please write to info@itls.at.

FLEX & Online Training

Please see below our alternative, English language, FLEX course options.

London, City This is an English language FLEX course.
Time zone: Greenwich Mean Time (GMT)
France
Paris This is an French language FLEX course.
Time zone: Central European Summer Time (CEST)
Paris
Paris This is an French language FLEX course.
Time zone: Central European Summer Time (CEST)
Paris This is an French language FLEX course.
Time zone: Central European Time (CET)
United Kingdom
London, City This is an English language FLEX course.
Time zone: British Summer Time (BST)
London, City This is an English language FLEX course.
Time zone: Greenwich Mean Time (GMT)
This is a FLEX course, which is delivered both virtually and in the classroom. All FLEX courses are also Instructor-led Online Trainings (ILO). Until 30.06. we offer our courses also as online trainings.
English
1 hour difference
Online Training Time zone: British Summer Time (BST)
Online Training This is an English language FLEX course.
Time zone: British Summer Time (BST)
Online Training This is an English language FLEX course.
Time zone: Greenwich Mean Time (GMT)
7 hours difference
Online Training Time zone: Central Daylight Time (CDT) 2 days Guaranteed date!
Online Training Time zone: Central Daylight Time (CDT) 2 days Guaranteed date!
Online Training Time zone: Central Daylight Time (CDT) 2 days Guaranteed date!
Online Training Time zone: Central Daylight Time (CDT) 2 days Guaranteed date!
Guaranteed date:   iTLS will carry out all guaranteed training regardless of the number of attendees, exempt from force majeure or other unexpected events, like e.g. accidents or illness of the trainer, which prevent the course from being conducted.
Instructor-led Online Training:   This computer icon in the schedule indicates that this date/time will be conducted as Instructor-Led Online Training.
This is a FLEX course, which is delivered both virtually and in the classroom. All FLEX courses are also Instructor-led Online Trainings (ILO). Until 30.06. we offer our courses also as online trainings.