Discovery of unknown malware on a system. A properly trained incident responder could be the only defense your organization has left during a compromise. Organizations can't afford to believe that their security measures are perfect and impenetrable, no matter how thorough their security precautions might be. It brings together techniques learned earlier in the course and tests your newly acquired skills in an investigation into an attack by an advanced adversary. Engineers specializing in network security or IT, Managers wanting to create threat-hunting teams within their own companies, Understanding of fundamental information security concepts, Working knowledge of networking devices and protocols, Exposure to pentesting and network monitoring tools and methodologies, Basic knowledge of Linux and Windows command line, Think tactically regarding cyber threat defense, Use threat intelligence to form your own hypotheses and begin the hunt, Anticipate and hunt down threats in your organization's systems, Inspect network information to identify dangerous traffic, Understand the Hunting Maturity Model to measure your organization's hunting capability, Learn how to find and investigate malware, phishing, lateral movement, data exfiltration and other common threats, Role of threat hunting in organizational security program, Preparing for the hunt: the hunter, the data, the tools, Starting the hunt (confirming the hypothesis), Threat hunting hypotheses: intelligence-driven, awareness-driven, analytics-driven, Commercial and open-source threat hunting solutions, Network hunting overview (networking concepts, devices and communications, hunting tools), Hunting for suspicious DNS requests and geographic abnormalities, Hunting for suspicious domains, URLs and HTML responses. These trace artifacts can help the analyst uncover deleted logs, attacker tools, malware configuration information, exfiltrated data, and more. We can identify this activity via application execution artifacts. Rapid incident response analysis and breach assessment. These modules are a combination of general threat hunting training, as well as content that is specific to AI-Hunter. The content covers how hunting teams establish goals, methods used by threat hunting teams, and sources available to help read and interpret the threat landscape.

Are we learning how to counter them? Similar groups are penetrating banks and merchants, stealing credit card data.

Students identify covert communications, malicious activity, and other network data anomalies.

What Happens When Data Is Deleted from an NTFS Filesystem? Use collected data to perform effective remediation across the entire enterprise.

FOR508: Advanced Incident Response and Threat Hunting Course will help you to: DAY 0: A 3-letter government agency contacts you to say an advanced threat group is targeting organizations like yours, and that your organization is likely a target. Advanced use of a wide range of best-of-breed open-source tools and the SIFT Workstation to perform incident response and digital forensics. The course uses a hands-on enterprise intrusion lab -- modeled after a real-world targeted APT attack on an enterprise network and based on APT group tactics to target a network -- to lead you to challenges and solutions via extensive use of the SIFT Workstation and best-of-breed investigative tools. Memory analysis was traditionally the domain of Windows internals experts and reverse engineers, but new tools, techniques, and detection heuristics have greatly leveled the playing field making it accessible today to all investigators, incident responders, and threat hunters. Attacks follow a predictable pattern, and we focus our detective efforts on immutable portions of that pattern.

Stealing and Utilization of Legitimate Credentials, Lateral Movement Adversary Tactics, Techniques, and Procedures (TTPs), Log Analysis for Incident Responders and Hunters.