Rapid Incident Response with Cisco Extended Detection & Response (XDR)

🎯 Mission Briefing: Kick off your adventure with a hands-on lab designed to enhance your investigation and incident response expertise.

🌐 Defend against sophisticated APTs with Cisco XDR: Learn how to empower your teams to go from endless investigation to remediating the highest priority incidents with greater speed, efficiency, and confidence. We will explore how to:

· Identify patterns and correlations in threat activity with root cause and attack chain analysis

· Leverage machine learning to prioritize incidents based on risk and impact

· Elevate productivity with automation and guidance


 

Agendas

Workshop Kickoff & Slide Presentation

Introductions, objectives, threat landscape, and tool orientation.

Navigating Cisco XDR

Brief platform walkthrough for first-time users.

Lab-Phase 1: Initial Access

Investigate how attackers first entered the environment through phishing techniques.

Lab-Phase 2: Discovery

Analyze adversary reconnaissance activity within the compromised network.

Lab-Phase 3: Privilege Escalation

Identify lateral movement techniques and privilege abuse across endpoints.

Lab-Phase 4: Credential Access

Uncover the methods used to dump and reuse credentials for persistence.

Lab-Phase 5: Defense Evasion

Track how attackers disabled tools and obscured their presence.

Lab-Phase 6: Exfiltration

Analyze data movement and identify staging or exfiltration behaviors.

Lab-Phase 7: Containment & Response

Use Cisco XDR and integrated tools to contain the threat and recommend response actions.

Q&A, Survey, Certificates

Sponsors

Logicalis-RIR-USA-CLE

Event Information
Event Date 05-14-2025 1:00 pm
Event End Date 05-14-2025 6:00 pm
Cut Off Date 05-14-2025 2:00 pm
Capacity 25
Registered 0
Available Place 25
Created By Dale Long
Workshop Length in Hours 5
Geolocation: amer
Type of event: sales
Webex URL https://cisco.webex.com/cisco/j.php?MTID=m9a5f950ff9b75c4dfbbc318a54841cab
Location Cisco-Ritchfield, OH

Location Map