Call : (+91) 968636 4243
Mail : info@EncartaLabs.com
EncartaLabs

Falcon Forensics

( Duration: 1 Day )

This Falcon Forensics training course is for threat hunters or anyone who will utilize Falcon Forensics to collect forensic information and use that information to perform investigations. The course utilizes Falcon Forensics within the Investigate application to perform basic investigations using various dashboards. You will learn about the forensic data collected, basic Splunk syntax and searches related to investigations.

By attending Falcon Forensics workshop, delegates will learn to:

  • Identify the information collected and artifacts created when running Falcon Forensics
  • Navigate the Falcon Forensics dashboards
  • Recall the Event Data Dictionary and sourcetypes
  • Identify interesting items in the Quick Wins dashboard
  • Use the Host Timeline dashboard to effectively narrow in on a specific timeline and host
  • Investigate interesting information in the Host Info dashboard
  • Investigate using Splunk queries

  • Knowledge of Falcon Platform
  • Have an intermediate knowledge of cybersecurity incident investigation and the incident lifecycle
  • Have a working knowledge of Windows forensic artifacts including amcache/shimcache/prefetch, registry, event logs, scheduled tasks/jobs, users/groups, etc.

COURSE AGENDA

1

Welcome

2

Introduction To Falcon Forensics

  • Using Falcon Forensics to conduct forensic investigations
  • How Falcon Forensics works
  • Information that Falcon Foresnics collects
  • Artifacts created when running Falcon Forensics
3

Deploy Falcon Forensics

  • Items necessary for deployment
  • Basic steps to deploy the binary to specific hosts
  • Alternative methods of deployment
4

Investigate With Dashboards

  • Navigating the Falcon Forensics dashboards
  • Using the Quick Wins dashboard to identify interesting items
  • Pivoting to a Splunk query from a dashboard panel
  • Exporting data from a panel
  • Using the Host Timeline dashboard to view a specific timeline and host
  • Using the Host Info dashboard to investigate interesting information
5

Investigate With Splunk Searches

  • Introduction to Splunk and how to use it
  • Investigating using Splunk queries
  • Using Splunk macros in an investigation
  • Using advanced Splunk search commands

Encarta Labs Advantage

  • One Stop Corporate Training Solution Providers for over 6,000 various courses on a variety of subjects
  • All courses are delivered by Industry Veterans
  • Get jumpstarted from newbie to production ready in a matter of few days
  • Trained more than 50,000 Corporate executives across the Globe
  • All our trainings are conducted in workshop mode with more focus on hands-on sessions

View our other course offerings by visiting https://www.encartalabs.com/course-catalogue-all.php

Contact us for delivering this course as a public/open-house workshop/online training for a group of 10+ candidates.

Top
Notice
X