|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cisco-certified-specialist-threat-hunting-and-defending/
课程评论:没有评论
课程名称:威胁狩猎与防御 300-220 CBRTHD 课程概述:此课程旨在准备考生通过CyberOps专业认证考试(300-220),重点介绍使用Cisco技术进行高级威胁狩猎和防御。内容包括: 1. **威胁狩猎基础(20%)**:探讨威胁狩猎成熟度模型,理解基于MITRE ATT&CK等标准的威胁建模,分析自动化在SOC操作中的有效性,通过日志分析和威胁情报区分高级持续性威胁。 2. **威胁建模技术(10%)**:学习选择合适的威胁建模方法,应用MITRE ATT&CK战术,并根据网络杀伤链优先考虑攻击。掌握结构化和非结构化威胁狩猎的技巧。 3. **威胁行为者归因技术(20%)**:培养识别攻击战术、技术和程序的能力,运用日志识别检测高级威胁的关键线索,区分威胁行为者与渗透测试人员。 4. **威胁狩猎技术(20%)**:利用脚本语言进行检测,执行云原生的猎捕,分析端点工件以发现未检测到的威胁。学习识别指挥与控制(C2)通信,并使用代码级分析工具进行漏洞评估。 5. **威胁狩猎流程(20%)**:了解内存驻留攻击,针对安全漏洞的逆向工程,识别检测缺口。构建有效的作战手册,推荐工具和配置,以及基于评估结果建议缓解策略。 6. **威胁狩猎结果(10%)**:通过多产品整合提升数据可见性,诊断分析差距,并建议缓解策略。利用演示资源传达发现,推动环境变革。 通过本课程,使您掌握有效的威胁狩猎与防御知识与技能,做好面对现代网络安全环境挑战的准备。
Course Description: Conducting Threat Hunting and Defending using Cisco Technologies for CyberOps v1.0 (300-220)This course prepares candidates for the CyberOps Professional Certification (300-220) exam, focusing on advanced threat hunting and defense using Cisco technologies. It covers:Threat Hunting Fundamentals (20%): Explore the Threat Hunting Maturity Model, understand threat modeling with standards like MITRE ATT & CK, and analyze the effectiveness of automation in SOC operations. Delve into differentiating advanced persistent threats through log analysis and threat intelligence.Threat Modeling Techniques (10%): Learn to select appropriate threat modeling approaches, apply MITRE ATT & CK tactics, and prioritize attacks based on the Cyber Kill Chain. Gain expertise in structured and unstructured threat hunting.Threat Actor Attribution Techniques (20%): Develop skills in identifying attack tactics, techniques, and procedures using logs. Recognize artifacts crucial for detecting advanced threats and distinguishing between threat actors and penetration testers.Threat Hunting Techniques (20%): Utilize scripting languages for detection, perform cloud-native hunts, and analyze endpoint artifacts for undetected threats. Learn to identify C2 communications and use code-level analysis tools for vulnerability assessment.Threat Hunting Processes (20%): Understand memory-resident attacks, reverse engineering for compromises, and identify detection gaps. Construct effective runbooks, recommend tools and configurations, and suggest remediation strategies based on assessments.Threat Hunting Outcomes (10%): Enhance data visibility through multiproduct integration, diagnose analytical gaps, and recommend mitigation strategies. Use presentation resources to convey findings and drive environmental change.Equip yourself with the knowledge and skills necessary for effective threat hunting and defense, preparing you for the challenges of modern cybersecurity environments.