Course Outline
Introduction
Understanding Malware
- Types of malware.
- The evolution of malware.
Overview of Malware Attacks
- Propagating attacks.
- Non-propagating attacks.
ATT&CK Matrices
- Enterprise ATT&CK.
- Pre-ATT&CK.
- Mobile ATT&CK.
MITRE ATT&CK
- 11 distinct tactics.
- Techniques.
- Procedures.
Preparing the Development Environment
- Setting up a version control center (GitHub).
- Downloading a project that hosts a data-based to-do list system.
- Installing and configuring ATT&CK Navigator.
Monitoring a Compromised System (WMI)
- Implementing command-line scripts to conduct lateral attacks.
- Using ATT&CK Navigator to identify the compromise.
- Evaluating the compromise through the ATT&CK framework.
- Performing process monitoring.
- Documenting and patching vulnerabilities in the defense architecture.
Monitoring a Compromised System (EternalBlue)
- Implementing command-line scripts to conduct a lateral attack.
- Utilizing ATT&CK Navigator to identify the compromise.
- Assessing the compromise through the ATT&CK framework.
- Performing process monitoring.
- Documenting and patching holes in the defense architecture.
Summary and Conclusion
Requirements
- A foundational understanding of information system security.
Audience
- Information systems analysts.
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent