Course overview
This course provides a comprehensive introduction to modern attack identification. You will explore how security operations centers leverage AI models to parse massive volumes of telemetry, identify anomalies, and isolate active threats across networks and endpoints.
- Identify common indicators of compromise across network traffic and endpoint logs using AI-assisted analysis
- Analyze network protocols and detect anomalies using supervised and unsupervised machine learning models
- Recognize host-level threats including unauthorized process executions and local privilege escalation attempts
- Deconstruct social engineering tactics and phishing attempts using natural language processing tools
- Execute basic incident triage and containment workflows in coordination with automated security systems