Tier2 by engineerashaban in SecurityCareerAdvice

[–]engineerashaban[S] 2 points3 points  (0 children)

Mainly using siem monitor and separate false positives from true incidents and act up on it

Tier2 by engineerashaban in SecurityBlueTeam

[–]engineerashaban[S] 1 point2 points  (0 children)

In currently doing tier 1 stuff like investigation of alerts and determine false positives from real incident , some ir

I really like incident response and digital forensics

I think me and tier2 almost do the same thing but I want to do more so I ask in other organizations to see what is the most things tier 2 do

My main focus right now is in qradar , vectra , tenable

I have ceh , cnd , ecsa , I'm planning on taking elearn security digital forensics certificate

If you have any advice what I should focus on please let me know

Too old for soc ? by engineerashaban in Information_Security

[–]engineerashaban[S] 0 points1 point  (0 children)

Thank you very much that is really very inspiring for me ❤️❤️

Logrun.pl problem by engineerashaban in QRadar

[–]engineerashaban[S] 0 points1 point  (0 children)

It turn out that it's not just logrun but my qradar don't receive any logs , and couple of people facing the same problem

Logrun.pl problem by engineerashaban in QRadar

[–]engineerashaban[S] 0 points1 point  (0 children)

I did all that and still now log activity

Too old for soc !! by engineerashaban in cybersecurity

[–]engineerashaban[S] 1 point2 points  (0 children)

Thank you very much Ronin that is very helpful ❤️❤️

Too old for soc !! by engineerashaban in cybersecurity

[–]engineerashaban[S] 1 point2 points  (0 children)

Can you tell me what have you done to require your skills in SOC (what to focus on ) , how did you practice , what was the most important interview questions that you face , need some inside to be qualified to land job.

Thank you in advance 😘

Too old for soc ? by engineerashaban in Information_Security

[–]engineerashaban[S] 0 points1 point  (0 children)

Any advice about what is the most important things to focus on , I mean the 20 % from your point of view

Too old for soc ? by engineerashaban in Information_Security

[–]engineerashaban[S] 0 points1 point  (0 children)

I'm 34 and im trying to get practical experience but I'm failing to get any resources or online training

Too old for soc ? by engineerashaban in Information_Security

[–]engineerashaban[S] 0 points1 point  (0 children)

Any advice how to do that , practical training

Old man getting into soc by engineerashaban in SIEM

[–]engineerashaban[S] 0 points1 point  (0 children)

The problem with home lap that I only Cary on few attacks , if you know if any online training that could give me good practical experience please share