MITRE ATT&CK Training Course
MITRE ATT&CK is a comprehensive framework of tactics and techniques designed to classify cyberattacks and evaluate an organization's risk profile. By leveraging ATT&CK, organizations can enhance their security awareness, identify vulnerabilities in their defenses, and prioritize potential risks effectively.
This instructor-led live training, available both online and onsite, is tailored for information systems analysts who aim to utilize MITRE ATT&CK to mitigate the risk of security breaches.
Upon completion of this training, participants will be capable of:
- Establishing the necessary development environment to begin implementing MITRE ATT&CK.
- Categorizing the methods attackers use to interact with systems.
- Documenting adversary behaviors within system environments.
- Tracking attacks, interpreting patterns, and evaluating existing defense tools.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practical sessions.
- Hands-on implementation within a live laboratory environment.
Course Customization Options
- To request a customized training version of this course, please contact us to arrange details.
Course Outline
Introduction
Understanding Malware
- Types of malware.
- The evolution of malware.
Overview of Malware Attacks
- Propagating attacks.
- Non-propagating attacks.
ATT&CK Matrices
- Enterprise ATT&CK.
- Pre-ATT&CK.
- Mobile ATT&CK.
MITRE ATT&CK
- 11 distinct tactics.
- Techniques.
- Procedures.
Preparing the Development Environment
- Setting up a version control center (GitHub).
- Downloading a project that hosts a data-based to-do list system.
- Installing and configuring ATT&CK Navigator.
Monitoring a Compromised System (WMI)
- Implementing command-line scripts to conduct lateral attacks.
- Using ATT&CK Navigator to identify the compromise.
- Evaluating the compromise through the ATT&CK framework.
- Performing process monitoring.
- Documenting and patching vulnerabilities in the defense architecture.
Monitoring a Compromised System (EternalBlue)
- Implementing command-line scripts to conduct a lateral attack.
- Utilizing ATT&CK Navigator to identify the compromise.
- Assessing the compromise through the ATT&CK framework.
- Performing process monitoring.
- Documenting and patching holes in the defense architecture.
Summary and Conclusion
Requirements
- A foundational understanding of information system security.
Audience
- Information systems analysts.
Open Training Courses require 5+ participants.
MITRE ATT&CK Training Course - Booking
MITRE ATT&CK Training Course - Enquiry
MITRE ATT&CK - Consultancy Enquiry
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent
Manar Abu Talib - Dubai Electronic Security Center
Course - MITRE ATT&CK
Upcoming Courses
Related Courses
AI-Powered Cybersecurity: Threat Detection & Response
21 HoursThis instructor-led, live training in Turkey (online or onsite) is designed for cybersecurity professionals at the beginner level who aim to learn how to use AI to improve threat detection and response capabilities.
Upon completing this training, participants will be able to:
- Comprehend the role of AI in cybersecurity.
- Deploy AI algorithms for the purpose of threat detection.
- Utilize AI tools to automate incident response procedures.
- Incorporate AI into current cybersecurity frameworks.
AI-Powered Cybersecurity: Advanced Threat Detection & Response
28 HoursThis instructor-led, live training in Turkey (online or onsite) targets intermediate to advanced cybersecurity professionals seeking to enhance their skills in AI-driven threat detection and incident response.
By the end of this training, participants will be able to:
- Implement advanced AI algorithms for real-time threat detection.
- Customize AI models for specific cybersecurity challenges.
- Develop automation workflows for threat response.
- Secure AI-driven security tools against adversarial attacks.
Blue Team Fundamentals: Security Operations and Analysis
21 HoursThis instructor-led, live training in Turkey (online or onsite) is designed for intermediate-level IT security professionals aiming to enhance their skills in security monitoring, analysis, and response.
Upon completing this training, participants will be able to:
- Grasp the role of the Blue Team in cybersecurity operations.
- Leverage SIEM tools for security monitoring and log analysis.
- Identify, analyze, and respond to security incidents.
- Conduct network traffic analysis and gather threat intelligence.
- Implement best practices within Security Operations Center (SOC) workflows.
Bug Bounty Hunting
21 HoursBug Bounty Hunting involves systematically identifying security vulnerabilities in software, websites, or systems and responsibly reporting them to earn rewards or professional recognition.
This instructor-led live training (available online or onsite) is designed for beginner-level security researchers, developers, and IT professionals eager to grasp the fundamentals of ethical bug hunting and learn how to effectively participate in bug bounty programs.
Upon completion of this training, participants will be able to:
- Grasp the core concepts of vulnerability discovery and the mechanics of bug bounty programs.
- Utilize essential tools such as Burp Suite and browser developer tools for application testing.
- Identify prevalent web security flaws, including XSS, SQLi, and CSRF.
- Submit clear, actionable vulnerability reports to bug bounty platforms.
Course Format
- Interactive lectures and discussions.
- Hands-on practice with bug bounty tools in simulated testing environments.
- Guided exercises focused on discovering, exploiting, and reporting vulnerabilities.
Customization Options
- To request customized training tailored to your organization's applications or specific testing requirements, please contact us to arrange.
Bug Bounty: Advanced Techniques and Automation
21 HoursBug Bounty: Advanced Techniques and Automation delves into high-impact vulnerabilities, automation frameworks, reconnaissance techniques, and the tooling strategies employed by top-tier bug bounty hunters.
This instructor-led, live training (available online or onsite) is designed for intermediate to advanced security researchers, penetration testers, and bug bounty hunters who aim to streamline their workflows, scale reconnaissance efforts, and uncover complex vulnerabilities across multiple targets.
Upon completion of this training, participants will be able to:
- Automate reconnaissance and scanning processes for multiple targets.
- Utilize state-of-the-art tools and scripts for bounty automation.
- Identify complex, logic-based vulnerabilities that fall outside standard scanning methods.
- Develop custom workflows for subdomain enumeration, fuzzing, and reporting.
Course Format
- Interactive lectures and discussions.
- Practical application of advanced tools and scripting for automation.
- Guided labs focusing on real-world bounty workflows and advanced attack chains.
Customization Options
- To arrange a customized training session tailored to your bounty targets, automation requirements, or internal security challenges, please contact us.
CHFI - Certified Digital Forensics Examiner
35 HoursThe vendor-neutral Certified Digital Forensics Examiner certification is designed to equip Cyber Crime and Fraud Investigators with skills in electronic discovery and advanced investigative techniques. This course is indispensable for professionals who encounter digital evidence during investigations.
The Certified Digital Forensics Examiner training provides the methodology for conducting computer forensic examinations. Students will learn to apply forensically sound investigative techniques to evaluate the scene, collect and document relevant information, interview key personnel, maintain the chain of custody, and draft findings reports.
The Certified Digital Forensics Examiner course is beneficial for organizations, individuals, government bodies, and law enforcement agencies seeking to pursue litigation, establish proof of guilt, or implement corrective actions based on digital evidence.
Certified Incident Handler
21 HoursThe Certified Incident Handler program offers a systematic framework for effectively and efficiently managing cybersecurity incidents.
This instructor-led live training, available online or onsite, targets intermediate IT security professionals seeking to build tactical expertise in planning, classifying, containing, and managing security incidents.
Upon completion, participants will be equipped to:
- Comprehend the incident response lifecycle and its distinct phases.
- Perform incident detection, classification, and notification procedures.
- Implement effective containment, eradication, and recovery strategies.
- Create post-incident reports and continuous improvement plans.
Course Format
- Interactive lectures and discussions.
- Practical application of incident handling procedures within simulated scenarios.
- Guided exercises emphasizing detection, containment, and response workflows.
Customization Options
- For customized training tailored to your organization's specific incident response procedures or tools, please contact us to arrange.
Mastering Continuous Threat Exposure Management (CTEM)
28 HoursThis instructor-led, live training in Turkey (online or onsite) targets intermediate-level cybersecurity professionals seeking to implement CTEM in their organizations.
By the end of this training, participants will be able to:
- Understand the principles and stages of CTEM.
- Identify and prioritize risks using CTEM methodologies.
- Integrate CTEM practices into existing security protocols.
- Utilize tools and technologies for continuous threat management.
- Develop strategies to validate and improve security measures continuously.
Cyber Threat Intelligence
35 HoursThis instructor-led, live training in Turkey (online or onsite) is designed for advanced cybersecurity professionals who aim to understand Cyber Threat Intelligence and develop the skills to effectively manage and mitigate cyber threats.
By the end of this training, participants will be able to:
- Understand the fundamentals of Cyber Threat Intelligence (CTI).
- Analyze the current cyber threat landscape.
- Collect and process intelligence data.
- Perform advanced threat analysis.
- Leverage Threat Intelligence Platforms (TIPs) and automate threat intelligence processes.
Fundamentals of Corporate Cyber Warfare
14 HoursThis instructor-led, live training in Turkey (online or onsite) explores various facets of enterprise security, from AI to database protection. It also covers the latest tools, processes, and mindset needed to protect from attacks.
DeepSeek for Cybersecurity and Threat Detection
14 HoursThis instructor-led, live training, accessible via online or on-site formats, is designed for intermediate-level cybersecurity professionals looking to utilize DeepSeek for advanced threat detection and automation.
By the conclusion of this training, participants will be able to:
- Leverage DeepSeek AI for real-time threat detection and analysis.
- Implement AI-driven anomaly detection techniques.
- Automate security monitoring and response using DeepSeek.
- Integrate DeepSeek into existing cybersecurity frameworks.
Duty Managers Cyber Resilience
14 HoursThis instructor-led, live training in Turkey (online or onsite) targets intermediate-level duty managers and operational leaders aiming to develop strong cyber resilience strategies to safeguard their organizations against cyber threats.
By the end of this training, participants will be able to:
- Understand cyber resilience fundamentals and their relevance to duty management.
- Develop incident response plans to maintain operational continuity.
- Identify potential cyber threats and vulnerabilities within their environment.
- Implement security protocols to minimize risk exposure.
- Coordinate team response during cyber incidents and recovery processes.
Junior Detection Engineer Essentials
21 HoursDetection engineering involves the design, implementation, and continuous improvement of strategies to spot malicious activities across networks and systems.
This live, instructor-led training, available either online or at your location, is designed for entry-level cybersecurity professionals aiming to acquire practical skills in creating and optimizing security detections.
After completing this course, participants will be able to:
- Create robust detection rules and signatures using widely used security tools.
- Analyze logs and telemetry data to recognize suspicious patterns.
- Leverage threat intelligence to enhance detection capabilities.
- Refine alerts and minimize false positives within a Security Operations Center (SOC) environment.
Course Format
- Guided learning accompanied by practical demonstrations.
- Scenario-based exercises and hands-on data analysis.
- Real-world rule development within an interactive lab setting.
Customization Options
- If your organization needs a customized version of this program, please reach out to discuss available options.
Open-Source EDR Fundamentals: Deployment, Detection & Response
14 HoursOpenEDR serves as an open-source endpoint detection and response solution, delivering continuous telemetry, threat detection, and analysis of adversarial activities across endpoints.
This instructor-led live training (available online or onsite) targets beginner to intermediate IT and security professionals eager to deploy, configure, and manage OpenEDR to detect and counter cyber threats effectively.
Upon completion of this training, participants will be equipped to:
- Deploy and configure OpenEDR agent and server components to facilitate telemetry collection.
- Conduct fundamental detection and monitoring activities using OpenEDR dashboards and event views.
- Analyze endpoint events to pinpoint suspicious behavior and potential threats.
- Seamlessly integrate OpenEDR alerts into incident response workflows and reporting processes.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practical practice.
- Hands-on implementation within a live-lab environment.
Customization Options
- For customized training requests, please get in touch with us to make arrangements.
Mastering Open-Source EDR & Mitre ATT&CK for Threat Hunting
21 HoursOpenEDR is an open-source endpoint detection and response platform that offers analytic detection with MITRE ATT&CK visibility for event correlation and root cause analysis of adversarial activity in real time.
This instructor-led live training (available online or onsite) targets advanced-level SOC analysts, threat hunters, and incident responders who wish to design and operate threat-hunting programs using OpenEDR and map detections to the MITRE ATT&CK framework.
Upon completing this training, participants will be able to:
- Deploy and configure OpenEDR agents and server components for telemetry collection and analysis.
- Map observable endpoint telemetry to MITRE ATT&CK techniques and build detection logic accordingly.
- Design and execute threat-hunting workflows that use behavioral analytics and event correlation to identify adversarial activity.
- Integrate OpenEDR findings into incident response playbooks and perform root cause analysis.
Course Format
- Interactive lectures and discussions.
- Numerous exercises and practice sessions.
- Hands-on implementation in a live lab environment.
Customization Options
- To request customized training for this course, please contact us to arrange.