Threat Investigation (Coursera)

Threat Investigation (Coursera)

If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how threat-centric SOC must prepare for analyzing new and emerging threats by implementing robust security investigation procedures.

Class Deals by MOOC List - Click here and see Coursera's Active Discounts, Deals, and Promo Codes.

By the end of the course, you will be able to:
• Understand cyber-threat hunting concepts
• Describe the five hunting maturity levels (HM0–HM4)
• Describe the hunting cycle four-stage loop
• Describe the use of the Common Vulnerability Scoring System (CVSS) and list the CVSS v3.0 base metrics
• Describe the CVSS v3.0 scoring components (base, temporal, and environmental)
• Provide an example of CVSS v3.0 scoring
• Describe the use of a hot threat dashboard within a SOC
• Provide examples of publicly available threat awareness resources
• Provide examples of publicly available external threat intelligence sources and feeds
• Describe the use of security intelligence feed
• Describe threat analytics systems
• Describe online security research tools
• Simulate malicious actions to populate the event data on the Security Onion tools for later analysis
• Identify resources for hunting cyber threats.
To be successful in this course, you should have the following background:

  1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course
  2. Familiarity with Ethernet and TCP/IP networking
  3. Working knowledge of the Windows and Linux operating systems
  4. Familiarity with basics of networking security concepts.

Course 6 of 7 in the Cybersecurity Operations Fundamentals Specialization.

Syllabus

WEEK 1
Identifying Resources for Hunting Cyber Threats
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how threat-centric SOC must prepare for analyzing new and emerging threats by implementing robust security investigation procedures • By the end of the course, you will be able to: • Understand cyber-threat hunting concepts • Describe the five hunting maturity levels (HM0–HM4) • Describe the hunting cycle four-stage loop• Describe the use of the Common Vulnerability Scoring System (CVSS) and list the CVSS v3.0 base metrics• Describe the CVSS v3.0 scoring components (base, temporal, and environmental) • Provide an example of CVSS v3.0 scoring • Describe the use of a hot threat dashboard within a SOC • Provide examples of publicly available threat awareness resources • Provide examples of publicly available external threat intelligence sources and feeds• Describe the use of security intelligence feed • Describe threat analytics systems • Describe online security research tools • Simulate malicious actions to populate the event data on the Security Onion tools for later analysis • Identify resources for hunting cyber threats. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

WEEK 2
Understanding Event Correlation and Normalization
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you describe event correlation and normalization. By the end of the course, you will be able to: • Describe network security monitoring event sources (IPS, Firewall, NetFlow, Proxy Server, IAM, AV, and application logs)• Describe direct evidence and circumstantial evidence • Describe chain of custody for all evidence and interacting with law enforcement • Describe an example of security data normalization • Provide an example of security events correlation • Explain the basic concepts of security data aggregation, summarization, and deduplication • Use the Security Onion Sguil and ELSA applications as the SIEM platform to monitor the network for peculiarities and start an investigation. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

WEEK 3
Conducting Security Incident Investigations
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will explain how to conduct security incident investigations. By the end of the course, you will be able to: • Explain the objective of security incident investigation: Discover the who, what, when, where, why, and how of the incident • Describe the China Chopper Remote Access Trojan • Identify network traffic that was created by an advanced persistent threat (APT). To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

WEEK 4
Using a Playbook Model to Organize Security Monitoring
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how to use a playbook model to organize security monitoring. By the end of the course, you will be able to: • Describe the security analytics process • Describe the use of a playbook in a SOC • Describe the components of a play in a typical SOC playbook • Describe the use of a playbook management system in the SOC • Explore SOC playbooks. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Usable Security (Coursera) Coursera
University of Maryland, College Park

Usable Security (Coursera)

This course focuses on how to design and build secure systems with a human-centric focus. We will look at basic principles of human-computer interaction, and apply these insights to the design of secure systems with the goal of developing security measures that respect human performance and their goals within a system.

Sep 7th 2026
5-12 Weeks
Information Systems Auditing, Controls and Assurance (Coursera) Coursera
The Hong Kong University of Science and Technology - HKUST

Information Systems Auditing, Controls and Assurance (Coursera)

Information systems (IS) are important assets to business organizations and are ubiquitous in our daily lives. With the latest IS technologies emerging, such as Big Data, FinTech, Virtual Banks, there are more concerns from the public on how organizations maintain systems’ integrity, such as data privacy, information security, the compliance to the government regulations. Management in organizations also need to be assured that systems work the way they expected. IS auditors play a crucial role in handling these issues.

Sep 7th 2026
4 Weeks
Enhancing Mac Security: Strategies for Protection (Coursera) Coursera
LearnQuest

Enhancing Mac Security: Strategies for Protection (Coursera)

Fortifying Your Digital Fortress: Mac Security Strategies for Ultimate Protection. Discover essential Mac security in this comprehensive course tailored for beginners. Learn to safeguard your Mac workstation effectively as you delve into fundamental security features, threat assessment, and proactive management. Gain insights into automating security processes and adopting top-notch practices, ensuring robust protection for your Mac. Enroll now to master the art of securing your Mac with confidence.

Sep 14th 2026
3 Weeks
IBM Data Privacy for Information Architecture (Coursera) Coursera
IBM

IBM Data Privacy for Information Architecture (Coursera)

Data privacy controls how information is collected, used, shared, and disposed of, in accordance with policies or external laws and regulations. In this course, students will gain an understanding of what data privacy is along with how to identify and understand typical data protection and privatization objectives that an enterprise may have, and how to choose a data protection approach.

Sep 14th 2026
5-12 Weeks
Cloud Computing Security (Coursera) Coursera
University of Colorado System

Cloud Computing Security (Coursera)

In this MOOC, we will learn Cloud Computing basics using AWS as an example, We will guide you to create AWS account, planning AWS resources for your cloud systems, create AWS EC2 instances, access them and configure the popular LAMP web services with MySQL database. We will guide you to create user accounts for your programmer or operators using AWS Identify and Access management GUI, Register your domain name and setup DNS entry for your servers using AWS Route 53 in 22 mintues! and show you how to use AWS Command Line interface to create and managing instances and services programmatically.

Sep 7th 2026
4 Weeks
Global Health Security, Solidarity and Sustainability through the International Health Regulations (Coursera) Coursera
University of Geneva

Global Health Security, Solidarity and Sustainability through the International Health Regulations (Coursera)

Welcome to the MOOC "Global Health Security, Solidarity and Sustainability through the International Health Regulations". We are very excited to have you on board and hope you will enjoy the course! In the coming 6 weeks, you will learn about the International Health Regulations (IHR), history of its creation and evolution, its major principles and implementation procedures, as well as challenges and future opportunities.

Sep 14th 2026
5-12 Weeks
Cloud Computing Fundamentals on Alibaba Cloud (Coursera) Coursera
Alibaba Cloud Academy

Cloud Computing Fundamentals on Alibaba Cloud (Coursera)

Looking to dive into the world of Alibaba Cloud with a comprehensive introduction to the range of products and solutions offered by Alibaba Cloud? Fundamental Architecting on Alibaba Cloud is a course designed for users looking to start this journey with a look into Alibaba Cloud's core products. Fundamental Architecting looks into storage, networking, auto-scaling, and security solutions as well as scenarios to best combine these products to create a complete cloud-based architecture.

Sep 14th 2026
5-12 Weeks
Capstone: Autonomous Runway Detection for IoT (Coursera) Coursera
EIT Digital

Capstone: Autonomous Runway Detection for IoT (Coursera)

The students will develop a larger system using the learning outcomes from these courses, and the students will evaluate the developed system in a real-world programming environment. This course is a true engineering task in which the student must, not only implement the algorithm code, but also handle the interfaces between many different actors and hardware platforms.

Sep 7th 2026
3 Weeks