Discuss EDR and SIEM solutions, their configuration, alert tuning, and detection strategies. Examples: Splunk, ELK, CrowdStrike, SentinelOne.
Discuss EDR and SIEM solutions, their configuration, alert tuning, and detection strategies. Examples: Splunk, ELK, CrowdStrike, SentinelOne.
Test your detection rules with controlled red team exercises whenever possible.
EDR tuning is often overlooked. False positives are the number one SOC killer.
Test your detection rules with controlled red team exercises whenever possible.
Splunk is powerful but expensive; I like the free ELK stack for smaller labs.
© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067