Administering Phantom 4.8

Administering Phantom 4.8

Summary

This 9 hour course prepares IT and security practitioners to install, configure and use a Phantom server in their environment and will prepare developers to attend the playbook development course.

Description

  • Phantom topics and concepts
  • Installation
  • Initial configuration
  • Apps and assets
  • User management
  • Ingesting data
  • Events and containers
  • Investigation
  • Running actions and playbooks
  • Case management
  • Case workflows
  • Multi tenancy
  • Clustering

Duration

2 Days

Objectives

Module 1 – Introduction, Deployment and Installation
  • Describe Phantom operating concepts
  • Identify documentation and community resources
  • Identify installation and upgrade options
  • Phantom & Splunk Architectue
  • Splunk/Phantom relationships

Module 2 – Initial Configuration
  • Product settings
  • Access control
  • Authentication settings
  • Response settings

Module 3 – User Management
  • Understanding roles
  • Creating users
  • Managing user access

Module 4 – Apps, Assets and Playbooks
  • Describe how apps and assets work in Phantom
  • Add and configure new apps
  • Configure assets
  • Manage playbooks

Module 5 – Ingesting Data
  • Assets as data sources
  • Configuring data polling
  • Labels and tags
  • Data ingestion management
  • Event settings

Module 6 – Analyst Queue
  • Work with the analyst queue
  • Filtering and sorting
  • Using search
  • Container export and import
  • Aggregation settings

Module 7 – Investigation
  • Use investigation page to work on events
  • Use indicators to find matching artifacts in multiple events
  • Using the heads-up display
  • Using notes

Module 8 – Actions, Playbooks and Files
  • Manually run actions and examine action results
  • Manually run playbooks
  • Use the vault to store related files

Module 9 – Case Management and Workbooks
  • Use case management for complex investigations
  • Use case workflows
  • Define new workbooks
  • Customize case management

Module 10 – Reporting and System Health
  • Run reports
  • Use Phantom audit tools
  • Monitor system health

Module 11 – Customization
  • Create custom severity levels
  • Create custom status levels
  • Add custom fields and CEF settings
  • Create custom workbooks

Module 12 – Advance Topics
  • Define clustering best practices
  • Configure multi-server Phantom clusters
  • Configure multi-tenancy
  • Backup/restore

 

Prerequisites

Classes:

  • None

 

Onsite Training

For groups of three or more

Request Quote

Public Training

EMEA UK Time - Virtual

APAC Singapore - Virtual

AMER Eastern Time - Virtual

AMER Pacific Time - Virtual


Don't see a date that works for you?

Request Class