Hover a category to view courses…
Intermediate level — focuses on SIEM usage and alert triage.
Topics:
Tier 1 responsibilities
Alert queue management
Types of alerts (Informational, Low, Medium, High)
Types of incidents (Phishing, Malware, Insider threat)
SIEM dashboards overview
Event correlation basics
Querying logs (KQL-like dummy queries)
Identifying suspicious patterns
L1 triage framework
How to classify alerts
How to validate events
Containment recommendations for common threats
Case study 1 (Phishing scenario)
Case study 2 (Malware detection)
Documentation checklist