
How to Learn More About SIEM and EDR Alerts
CybersecuritySIEMEDRIncident Response
The author, who previously worked as a SOC L1 and has only one month of experience as a SOC L2, is seeking advice on how to better manage SIEM and EDR alerts. They want to improve their investigation skills by following procedures or playbooks to sort, mitigate, and remediate common alerts such as multiple failed login attempts, credential theft, and privilege escalation. The author mentions having completed the ISC(CC) certification and plans to take the Sec+ and Cysa+ certifications.