Course Outline
Introduction
What is Malware?
- Types of malware.
- The evolution of malware.
Overview of Malware Attacks
- Propagating attacks.
- Non-propagating attacks.
Matrices of ATT&CK
- Enterprise ATT&CK.
- Pre-ATT&CK.
- Mobile ATT&CK.
MITRE ATT&CK Framework
- 11 Tactics.
- Techniques.
- Procedures.
Preparing the Development Environment
- Setting up a version control center (GitHub).
- Downloading a project that hosts a to-do list system of data.
- Installing and configuring ATT&CK Navigator.
Monitoring a compromised system (WMI)
- Establishing command line scripts to conduct a lateral attack.
- Utilizing ATT&CK Navigator to identify the compromise.
- Assessing the compromise through the ATT&CK framework.
- Performing process monitoring.
- Documenting and patching the holes in the defense architecture.
Monitoring a compromised system (EternalBlue)
- Establishing command line scripts to conduct a lateral attack.
- Utilizing ATT&CK Navigator to identify the compromise.
- Assessing the compromise through the ATT&CK framework.
- Performing process monitoring.
- Documenting and patching the holes in the defense architecture.
Summary and Conclusion
Requirements
- A foundational understanding of information system security.
Audience
- Information systems analysts.
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent