This one-day course teaches you how to use the VMware Carbon Black® EDR™ product during incident response. Using the SANS PICERL framework, you will configure the server and perform an investigation on a possible incident. This course provides guidance on using Carbon Black EDR capabilities throughout an incident with an in-depth, hands-on, scenario-based lab.
It is important that you use an email for the registration that you can reach during the course.
Security operations personnel, including analysts and incident responders.
This course requires completion of the following course:
By the end of the course, you should be able to meet the following objectives:
Read the official course description here