Threat Hunting with Windows Event Forwarding and Sumo Logic
Learn how to centralize Windows logs and analyze security telemetry using Sumo Logic to detect and hunt for modern cyber threats.
-
๐ฌ
AI instructor
Magtanong tungkol sa anumang aralin at makakuha ng malinaw na sagot agad, anumang oras. -
๐
Magsimula anumang oras
Walang iskedyul o deadline โ mag-aral sa sarili mong bilis, kahit kailan. -
๐
Sa Filipino
Mga aralin, gawain at sertipiko โ lahat ay ganap na nasa wika mo.
Tungkol sa kursong ito
Security teams face a massive volume of Windows log data, making it difficult to spot actual malicious activity before damage is done. Centralizing and analyzing this data is crucial for modern security operations. This text-based course guides you through setting up Windows Event Forwarding and using Sumo Logic to query, structure, and hunt for security anomalies across your network.
By working through this written material, you will transform raw log data into actionable security intelligence. You will learn the foundational concepts of Windows event generation, log collection architectures, and how to leverage cloud-native analytics to expose stealthy adversaries.
What you'll learn:
- Understand the fundamentals of Windows event logging, Windows Event Forwarding architecture, and subscription types.
- Configure Sysmon logging to capture advanced endpoint telemetry and process creations.
- Ingest and organize Windows security logs inside the Sumo Logic platform.
- Write search queries to identify common attack patterns, lateral movement, and privilege escalation.
- Apply modern threat hunting methodologies to proactively search for persistent threats.
- Analyze log scenarios to distinguish between normal administrative behavior and malicious events.
The course begins with essential terminology and the basics of Windows security event IDs before progressing to log aggregation strategies and query syntax. Designed for beginner security analysts, system administrators, and aspiring threat hunters, this course requires no prior experience with SIEM platforms or log analytics. Start reading today to build your foundational threat hunting capabilities.
Ang makukuha mo
-
๐
Certificate ng pagtatapos
Idagdag sa LinkedIn profile mo -
๐ฌ
Personal na AI tutor
Natigil sa isang aralin? Itanong sa iyong built-in na tutor ang kahit ano, kahit kailan. -
๐ง
Kasama ang audio version
Mag-aral kahit saan โ hindi kailangan ng screen -
โพ๏ธ
Lifetime access
Bumalik anumang oras, walang expiry -
๐ฑ
Telepono o computer
Gumagana saanman, kahit anong device -
๐ธ
14-day refund
Walang tanong -
โก
Maikli at focused
2 oras 54 min ng practical content
Mga Review
Wala pang review โ ikaw ang unang magbahagi.
Kinuha rin ng iba
๐ฅ Sikat
๐ May sertipiko
Isang Praktikal na Gabay sa Pagsunod sa MLPS 2.0
Sertipiko
Pagsasanay
KSh 2,000.00
→
๐ฅ Sikat
๐ May sertipiko
Mga Pundasyon ng Cybersecurity Engineering para sa Sertipikasyon
Sertipiko
Pagsasanay
KSh 2,000.00
→
๐ผ Handa sa trabaho
๐ May sertipiko
Praktikal na Pamamahala at Pamumuno sa Cybersecurity
Sertipiko
Pagsasanay
KSh 2,000.00
→
๐ฅ Sikat
๐ May sertipiko
Web Penetration Testing para sa mga Nagsisimula: SQL Injection at Pagtuklas ng Vulnerability
Sertipiko
Pagsasanay
KSh 2,000.00
→
Mga madalas itanong
Ano ang kailangan ko para sa kursong ito? +
Telepono o computer na may internet lang. Walang install, walang special hardware.
Paano ako magbabayad? +
Sa pamamagitan ng card via Stripe. Hindi namin iniimbak ang detalye ng card โ secure na hinahawakan ng Stripe.
Pwede ba akong mag-refund? +
Oo โ full refund sa loob ng 14 araw, walang tanong.
Hanggang kailan ang access ko? +
Habang buhay. Sa pagbili, sa iyo na ang course โ balikan mo kahit kailan.
Makakakuha ba ako ng certificate? +
Oo. Pagkatapos, makakatanggap ka ng certificate na maidadagdag sa LinkedIn profile mo.
Para sa mga learner sa
Tech
Design
Finance
Marketing
Healthcare
Edukasyon
Hospitality
Manufacturing