Course Outline
Introduction
Understanding Malware
- Categories of malware
- The historical evolution of malware
Overview of Malware Attack Vectors
- Propagating threats
- Non-propagating threats
ATT&CK Matrices
- Enterprise ATT&CK
- Pre-ATT&CK
- Mobile ATT&CK
MITRE ATT&CK Framework
- The 11 core tactics
- Associated techniques
- Observed procedures
Preparing the Development Environment
- Configuring a version control repository (GitHub)
- Acquiring a sample project featuring a to-do list data system
- Setting up and configuring ATT&CK Navigator
Monitoring Compromised Systems (WMI)
- Executing command-line scripts to simulate lateral movement attacks
- Using ATT&CK Navigator to detect the compromise
- Evaluating the incident through the ATT&CK framework
- Implementing process monitoring
- Recording findings and remedying vulnerabilities in the defense architecture
Monitoring Compromised Systems (EternalBlue)
- Executing command-line scripts to simulate lateral movement attacks
- Using ATT&CK Navigator to identify the breach
- Assessing the incident via the ATT&CK framework
- Conducting process monitoring
- Documenting observations and patching weaknesses in the defensive structure
Summary and Conclusions
Requirements
- Familiarity with information system security principles
Target Audience
- Information systems analysts
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent