Threat Investigation (Coursera)

Threat Investigation (Coursera)

If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how threat-centric SOC must prepare for analyzing new and emerging threats by implementing robust security investigation procedures.

Class Deals by MOOC List - Click here and see Coursera's Active Discounts, Deals, and Promo Codes.

By the end of the course, you will be able to:
• Understand cyber-threat hunting concepts
• Describe the five hunting maturity levels (HM0–HM4)
• Describe the hunting cycle four-stage loop
• Describe the use of the Common Vulnerability Scoring System (CVSS) and list the CVSS v3.0 base metrics
• Describe the CVSS v3.0 scoring components (base, temporal, and environmental)
• Provide an example of CVSS v3.0 scoring
• Describe the use of a hot threat dashboard within a SOC
• Provide examples of publicly available threat awareness resources
• Provide examples of publicly available external threat intelligence sources and feeds
• Describe the use of security intelligence feed
• Describe threat analytics systems
• Describe online security research tools
• Simulate malicious actions to populate the event data on the Security Onion tools for later analysis
• Identify resources for hunting cyber threats.
To be successful in this course, you should have the following background:

  1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course
  2. Familiarity with Ethernet and TCP/IP networking
  3. Working knowledge of the Windows and Linux operating systems
  4. Familiarity with basics of networking security concepts.

Course 6 of 7 in the Cybersecurity Operations Fundamentals Specialization.

Syllabus

WEEK 1
Identifying Resources for Hunting Cyber Threats
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how threat-centric SOC must prepare for analyzing new and emerging threats by implementing robust security investigation procedures • By the end of the course, you will be able to: • Understand cyber-threat hunting concepts • Describe the five hunting maturity levels (HM0–HM4) • Describe the hunting cycle four-stage loop• Describe the use of the Common Vulnerability Scoring System (CVSS) and list the CVSS v3.0 base metrics• Describe the CVSS v3.0 scoring components (base, temporal, and environmental) • Provide an example of CVSS v3.0 scoring • Describe the use of a hot threat dashboard within a SOC • Provide examples of publicly available threat awareness resources • Provide examples of publicly available external threat intelligence sources and feeds• Describe the use of security intelligence feed • Describe threat analytics systems • Describe online security research tools • Simulate malicious actions to populate the event data on the Security Onion tools for later analysis • Identify resources for hunting cyber threats. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

WEEK 2
Understanding Event Correlation and Normalization
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you describe event correlation and normalization. By the end of the course, you will be able to: • Describe network security monitoring event sources (IPS, Firewall, NetFlow, Proxy Server, IAM, AV, and application logs)• Describe direct evidence and circumstantial evidence • Describe chain of custody for all evidence and interacting with law enforcement • Describe an example of security data normalization • Provide an example of security events correlation • Explain the basic concepts of security data aggregation, summarization, and deduplication • Use the Security Onion Sguil and ELSA applications as the SIEM platform to monitor the network for peculiarities and start an investigation. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

WEEK 3
Conducting Security Incident Investigations
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will explain how to conduct security incident investigations. By the end of the course, you will be able to: • Explain the objective of security incident investigation: Discover the who, what, when, where, why, and how of the incident • Describe the China Chopper Remote Access Trojan • Identify network traffic that was created by an advanced persistent threat (APT). To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

WEEK 4
Using a Playbook Model to Organize Security Monitoring
If you are an associate-level cybersecurity analyst who is working in security operation centers, this course will help you understand how to use a playbook model to organize security monitoring. By the end of the course, you will be able to: • Describe the security analytics process • Describe the use of a playbook in a SOC • Describe the components of a play in a typical SOC playbook • Describe the use of a playbook management system in the SOC • Explore SOC playbooks. To be successful in this course, you should have the following background: 1. Skills and knowledge equivalent to those learned in Implementing and Administering Cisco Solutions (CCNA) v1.0 course 2. Familiarity with Ethernet and TCP/IP networking 3. Working knowledge of the Windows and Linux operating systems 4. Familiarity with basics of networking security concepts.

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Global Health Security, Solidarity and Sustainability through the International Health Regulations (Coursera) Coursera
University of Geneva

Global Health Security, Solidarity and Sustainability through the International Health Regulations (Coursera)

Welcome to the MOOC "Global Health Security, Solidarity and Sustainability through the International Health Regulations". We are very excited to have you on board and hope you will enjoy the course! In the coming 6 weeks, you will learn about the International Health Regulations (IHR), history of its creation and evolution, its major principles and implementation procedures, as well as challenges and future opportunities.

Sep 14th 2026
5-12 Weeks
Security & Safety Challenges in a Globalized World (Coursera) Coursera
Leiden University

Security & Safety Challenges in a Globalized World (Coursera)

Security and safety challenges rank among the most pressing issues of modern times. Challenges such as, cyber-crime, terrorism, and environmental disasters impact the lives of millions across the globe. These issues also rank high on the agenda of politicians, international organizations and businesses. They also feature prominently in the public conscience and in governmental policies.

Sep 21st 2026
5-12 Weeks
Cybersecurity Job Search and Interviews: Getting Started (Coursera) Coursera
University System of Georgia

Cybersecurity Job Search and Interviews: Getting Started (Coursera)

Are you planning to have a career in cybersecurity? This course can help you plan your preparation for such a career as well as give some advice on finding positions and landing a position. What you will learn: the process and resources for finding the perfect cybersecurity job; the cybersecurity professional’s role in an organization’s cybersecurity effort; the knowledge preparation for the cybersecurity professional from an education versus training perspective.

Sep 14th 2026
5-12 Weeks
Tencent Cloud Solutions Architect Associate (Coursera) Coursera
Tencent Cloud

Tencent Cloud Solutions Architect Associate (Coursera)

This course is primarily aimed at cloud professionals that are interested in learning about Tencent Cloud‘s cloud architectures. The course equips learners with a foundational knowledge in cloud architecture design and prepares them to take the Tencent Cloud Solutions Architect Associate examination. After completing this course, learners will be able to design cloud solutions that incorporate the principles of high availability, high security, high scalability, and cost optimization.

Sep 14th 2026
5-12 Weeks
Becoming a Cybersecurity Consultant (Coursera) Coursera
EIT Digital

Becoming a Cybersecurity Consultant (Coursera)

The course targets individuals planning to develop a career in cybersecurity, middle managers and executives. The course covers the following main learning objectives: Threats - Technology - Economics and it is structured in 2 parts: an online part and a face-to-face/live webinar part. The present online course is designed to cover theoretical concepts a Cybersecurity Consultant (medium level) should know.

Sep 7th 2026
3 Weeks
Security and Privacy for Big Data - Part 1 (Coursera) Coursera
EIT Digital

Security and Privacy for Big Data - Part 1 (Coursera)

This course sensitizes regarding security in Big Data environments. You will discover cryptographic principles, mechanisms to manage access controls in your Big Data system. By the end of the course, you will be ready to plan your next Big Data project successfully, ensuring that all security related issues are under control. You will look at decent-sized big data projects with security-skilled eyes, being able to recognize dangers. This will allow you to improve your systems to a grown and sustainable level.

Sep 7th 2026
1 Week
Healthcare Data Management and Information Systems (Coursera) Coursera
Northeastern University

Healthcare Data Management and Information Systems (Coursera)

This course is the continuation of the Health Informatics for Healthcare Professionals course. If you have not yet taken the introductory course, it is recommend that you complete that course prior to this course. The foundational knowledge from the introduction is carried through in this deeper dive into informatics in healthcare.

Sep 14th 2026
4 Weeks
Kali Linux (Coursera) Coursera
Board Infinity

Kali Linux (Coursera)

"Introduction to Kali Linux" is a meticulously designed course to guide beginners through the essentials of Kali Linux, a powerful tool for cybersecurity. Spanning two modules, the course begins with a comprehensive introduction to Kali Linux, its installation, navigation, and essential tools. It then advances into practical applications, covering network monitoring, ethical hacking principles, penetration testing, and vulnerability assessment.

Sep 14th 2026
2 Weeks
SQL for Security Specialist (Coursera) Coursera
Codio

SQL for Security Specialist (Coursera)

This course is designed specifically for SQL Security Specialists with a focus on PostgreSQL. It assumes a solid foundation in SQL and guides learners through advanced topics specific to PostgreSQL. You'll explore crucial concepts, such as complex queries, performance optimization, and database administration tasks unique to PostgreSQL.

Sep 14th 2026
3 Weeks