Threat Hunting with Windows Event Forwarding and Sumo Logic
Learn how to centralize Windows logs and analyze security telemetry using Sumo Logic to detect and hunt for modern cyber threats.
-
๐ฌ
AI-instructeur
Stel vragen over elke les en krijg altijd meteen een duidelijk antwoord. -
๐
Begin wanneer je wilt
Geen roosters of deadlines โ leer in je eigen tempo, wanneer het jou uitkomt. -
๐
In het Nederlands
Lessen, opdrachten en certificaat โ alles volledig in jouw taal.
Over deze cursus
Security teams face a massive volume of Windows log data, making it difficult to spot actual malicious activity before damage is done. Centralizing and analyzing this data is crucial for modern security operations. This text-based course guides you through setting up Windows Event Forwarding and using Sumo Logic to query, structure, and hunt for security anomalies across your network.
By working through this written material, you will transform raw log data into actionable security intelligence. You will learn the foundational concepts of Windows event generation, log collection architectures, and how to leverage cloud-native analytics to expose stealthy adversaries.
What you'll learn:
- Understand the fundamentals of Windows event logging, Windows Event Forwarding architecture, and subscription types.
- Configure Sysmon logging to capture advanced endpoint telemetry and process creations.
- Ingest and organize Windows security logs inside the Sumo Logic platform.
- Write search queries to identify common attack patterns, lateral movement, and privilege escalation.
- Apply modern threat hunting methodologies to proactively search for persistent threats.
- Analyze log scenarios to distinguish between normal administrative behavior and malicious events.
The course begins with essential terminology and the basics of Windows security event IDs before progressing to log aggregation strategies and query syntax. Designed for beginner security analysts, system administrators, and aspiring threat hunters, this course requires no prior experience with SIEM platforms or log analytics. Start reading today to build your foundational threat hunting capabilities.
Wat je krijgt
-
๐
Voltooiingscertificaat
Voeg toe aan je LinkedIn-profiel -
๐ฌ
Persoonlijke AI-tutor
Vastgelopen bij een les? Vraag je ingebouwde tutor op elk moment van alles. -
๐ง
Audioversie inbegrepen
Leer onderweg โ geen scherm nodig -
โพ๏ธ
Levenslange toegang
Kom altijd terug, geen einddatum -
๐ฑ
Telefoon of computer
Werkt overal, op elk apparaat -
๐ธ
14 dagen retour
Geen vragen -
โก
Kort en gericht
2 u 54 min praktische inhoud
Beoordelingen
Nog geen beoordelingen โ wees de eerste die zijn ervaring deelt.
Lerenden namen ook
๐ฅ Populair
๐ Met certificaat
Een Praktische Gids voor MLPS 2.0 Naleving
Certificaat
Praktijk
5 400 ึ
→
๐ฅ Populair
๐ Met certificaat
Cybersecurity Engineering Grondbeginselen voor Certificering
Certificaat
Praktijk
5 400 ึ
→
๐ผ Klaar voor de arbeidsmarkt
๐ Met certificaat
Praktisch cybersecuritybeheer en -bestuur
Certificaat
Praktijk
5 400 ึ
→
๐ฅ Populair
๐ Met certificaat
Web Penetration Testing voor Beginners: SQL Injection en Kwetsbaarheidsdetectie
Certificaat
Praktijk
5 400 ึ
→
Veelgestelde vragen
Wat heb ik nodig voor deze cursus? +
Alleen een telefoon of computer met internet. Geen installaties of speciale hardware.
Hoe betaal ik? +
Met kaart via Stripe. We bewaren geen kaartgegevens โ Stripe handelt dit veilig af.
Kan ik een terugbetaling krijgen? +
Ja โ volledige terugbetaling binnen 14 dagen, zonder vragen.
Hoe lang heb ik toegang? +
Voor altijd. Eenmaal gekocht is de cursus van jou en kun je hem altijd opnieuw bekijken.
Krijg ik een certificaat? +
Ja. Bij voltooiing ontvang je een certificaat dat je aan je LinkedIn-profiel kunt toevoegen.
Voor leerlingen in
Tech
Design
Financiรซn
Marketing
Gezondheidszorg
Onderwijs
Horeca
Productie