Ensilo/Fortiedr: Course Description

Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

Course Description

enSilo/FortiEDR
In this interactive course, you will learn how to use 14. enSilo Cloud Services
enSilo/FortiEDR to protect your endpoints against 15. Advanced Troubleshooting
advanced attacks with real-time orchestrated incident 16. Endpoint Security 101
response functionality.
17. PowerShell and CScript
18. Alert Analysis 401
Product Version
enSilo 4.0 Objectives
After completing this course, you should be able to:
Formats
l Explain the enSilo approach and how it works
l Self-paced online l Identify the communicating components and how they
are configured
Agenda l Schedule, organize, and tune a new deployment
l Carry out basic troubleshooting steps, including:
1. Overview and Technical Positioning
verifying that enSilo is installed and actively blocking
2. Help Desk Level 1 Triage malware, identifying whether enSilo has blocked a
3. Installation and Architecture process or connection, finding logs, and contacting
4. Administration and Troubleshooting enSilo Support
5. GUI Deep-Dive Part 1 l Perform important administrative tasks, including:
6. GUI Deep-Dive Part 2 managing console users, updating Collectors, delete
personal data for GDPR compliance, and view system
7. Events and Alerting
events
8. Best Practices and Deployment
l Complete basic tasks in of each area of the
9. Communication Control Management Console: the Dashboard, the Event
10. NGAV Viewer, the Forensics tab, the Threat Hunting module,
11. Threat Hunting Communication Control, Security Policies, Playbooks,
12. RESTful API Inventory, and the Administration tab
13. Multi-Tenancy

training.fortinet.com
l Manage security events and their status Firewall or FortiClient, must allow connections to the
l Block communication from applications that are risky or online labs.
unwanted, but not inherently malicious
l Define next-generation antivirus, its role in enSilo, and Certification
where it falls in the order of operations
l Find and remove malicious executables from all the There is no certification exam associated with this
devices in your environment course.

l Use RESTful API to manage your enSilo environment


l Administer a multi-tenant environment
l Recognize what enSilo Cloud Service is and how it
works
l Troubleshoot Collector upgrades and performance
issues
l Obtain Collector logs and memory dumps
l Have a basic understanding of the history of malware,
how it exploits trust, and the persistence techniques
used in malware today
l Triage PowerShell and CScript events, verify their
destinations, and retrieve memory
l Prioritize, investigate, and analyze security events
l Remediate malicious events and create exceptions to
allow safe processes

Who Should Attend


IT and security professionals involved in the
administration and support of enSilo FortiEDR should
attend this course.

Prerequisites
l Basic understanding of cybersecurity concepts

System Requirements
If you take the online format of this class, you must
use a computer that has the following:

l A high-speed Internet connection


l An up-to-date web browser
l A PDF viewer
l Speakers or headphones
l One of the following:
l HTML5 support
l An up-to-date Java Runtime Environment (JRE)
with Java plugin enabled in your web browser
You should use a wired Ethernet connection, not a
WiFi connection. Firewalls, including Windows

training.fortinet.com

You might also like