Course objectives
After completing this course, students will be able to:
- Detect & Correlate: Construct advanced queries in Splunk/ELK to identify Indicators of Compromise (IoCs) across disparate log sources.
- Analyze Endpoints: Identify privilege escalation, credential dumping (LSASS/SAM), and persistence (Scheduled Tasks, Registry) in real-time.
- Trace Network Chains: Use Wireshark and Zeek to reconstruct attack paths, lateral movement, and C2 (Command & Control) communications.
- Perform Light Forensics: Deconstruct malicious documents (Macros/VBA) and perform static analysis on suspicious executables.
- Apply Intelligence: Use MITRE ATT&CK to attribute behaviors to specific threat actor groups and TTPs.
- Report & Remediate: Draft a professional investigation report that includes a timeline of events and actionable recovery recommendations.
Course outlines
- Domain 1: Threat Detection & SIEM Operations
- Constructing custom SIEM queries to identify malicious patterns.
- Correlating multi-source log data to detect initial access.
- Recognizing signs of attacker footholds in enterprise environments.
- Constructing custom SIEM queries to identify malicious patterns.
- Domain 2: Endpoint & Network Analysis
- Analyzing telemetry for local user and system enumeration.
- Differentiating privilege escalation and credential access (SAM/LSASS dumping).
- Tracing lateral movement and authentication-based anomalies in PCAP data.
- Analyzing telemetry for local user and system enumeration.
- Domain 3: Digital Forensics & Evidence Analysis
- Deconstructing malicious documents and extracting VBA payloads.
- Static analysis of PE files for suspicious imports and metadata.
- Examining Windows Registry for execution history and system changes.
- Deconstructing malicious documents and extracting VBA payloads.
- Domain 4: Threat Intelligence & Attribution
- Mapping detected behaviors to MITRE ATT&CK TTPs.
- Assessing behavioral patterns to attribute activity to specific APT groups.
- Mapping detected behaviors to MITRE ATT&CK TTPs.
- Domain 5: Reporting & Communication
- Composing clear investigation reports including impact assessments.
- Conveying technical findings (IOCs, tools, payloads) to stakeholders.
- Composing clear investigation reports including impact assessments.