Course Outline
Introduction
Defining Malware
- Categories of malware
- The progression of malware development
Overview of Malware Attack Vectors
- Self-propagating threats
- Non-propagating threats
ATT&CK Matrix Variants
- Enterprise ATT&CK
- Pre-ATT&CK
- Mobile ATT&CK
Introduction to MITRE ATT&CK
- The 11 core tactics
- Specific techniques
- Adversary procedures
Configuring the Development Environment
- Establishing a version control repository (GitHub)
- Retrieving a sample project featuring a to-do list data system
- Installing and configuring ATT&CK Navigator
Monitoring Compromised Systems (WMI)
- Deploying command-line scripts to execute lateral movement attacks
- Using ATT&CK Navigator to detect the intrusion
- Evaluating the compromise via the ATT&CK framework
- Conducting process monitoring
- Documenting vulnerabilities and remediating gaps in the defense structure
Monitoring Compromised Systems (EternalBlue)
- Deploying command-line scripts to execute lateral movement attacks
- Using ATT&CK Navigator to detect the intrusion
- Evaluating the compromise via the ATT&CK framework
- Conducting process monitoring
- Documenting vulnerabilities and remediating gaps in the defense structure
Summary and Wrap-up
Requirements
- Fundamental knowledge of information system security
Target Audience
- Information systems analysts
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent