|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cyber-threat-intelligence-basics-fundamentals/
课程评论:没有评论
Coursera 课程《网络威胁情报 - 基础与原理》旨在为有志于网络安全、计算机科学、国际关系与地缘政治的年轻毕业生,以及初级网络安全专业人士(如 SOC 分析师、CERT 分析师)提供深入的网络威胁情报(CTI)知识。 课程内容涵盖 CTI 的理论基础,包括: * **核心概念定义:** 明确网络空间、威胁、情报、可疑活动指标(IoCs)等基本术语。 * **CTI 特定模型:** 详细介绍和解释网络杀伤链(Cyber Kill Chain)、钻石模型(Diamond Model)、痛苦金字塔(Pyramid of Pain)以及 MITRE ATT&CK 等关键分析框架。 * **CTI 目标层级:** 阐述战术级、操作级、战略级情报在 CTI 中的作用。 * **实况报告分析:** 提供当前 CTI 报告的实例分析。 * **知识巩固:** 通过小测验检验学习效果。 此外,课程还提供实践经验,帮助学员完成 CTI 相关任务: * **威胁行为者初步分析:** 学习分析威胁行为者的背景、操作模式、评估其风险并提出建议。 * **暗网资产监控:** 指导学员搭建虚拟环境,建立 VPN 连接,识别暗网论坛和勒索软件团伙的活动。 * **攻击者基础设施追踪:** 教授利用 SSL 证书和 JARM 指纹进行追踪的技术。 课程还提供未来 CTI 分析师所需的丰富资源,包括: * **开源情报(OSINT)报告整合框架:** 学习如何整合和利用 OSINT 数据。 * **情报工作手册(Intelligence Workbook):** 提供实用的分析工具和方法。 * **分析与报告范例:** 借鉴优秀的分析报告,提升实战能力。 本课程以其精炼、直观和资源丰富而著称,是加入 CTI 社区的理想起点。
Cyber Threat Intelligence is a relatively new field within cyber security. As cyber attacks increase both in terms of volume and sophistication, organizations felt the need to anticipate future cyber attacks by analyzing threat actors, malwares, used modus operandi, motivations and possible affiliations.Are you a young graduate in the field of cyber security, computer science, international relations & geopolitics?Are you a junior cyber security professionals (SOC analysts, CERT analysts)?Are you interested in cyber security and would like to know more about Cyber Threat Intelligence?If yes, this class will provide you:The theoretical foundations of Cyber Threat Intelligence with:Definitions of the fundamentals (cyberspace, threat, intelligence, Indicators of Compromise,etc.)Definition and explanation of CTI specific models (Cyber Kill Chain, Diamond Model, Pyramid of Pain, MITRE ATT & CK)Explanation of CTI objectives (Tactical level, Operational level, Strategic Level Intelligence)Concrete examples of reports published nowadaysQuizzes to test your knowledgeThe practical experience to complete CTI related tasks:Primo-analysis of a threat actor (context, modus operandi analysis, assessment and recommendations)Asset monitoring in the Darkweb (setup a virtual environment, VPN connection, identify Darkweb forums and ransomware group activities)Adversary controlled infrastructure hunting (SSL certificate pivoting and JARM fingerprint pivoting)Resources for your future tasks as a CTI analyst:OSINT report integration frameworkIntelligence WorkbookAnalysis and reports examplesThis class is synthetic, straight to the point and well resourced. Enjoy the class and welcome to the CTI community!