SDF: Persistence Fast Triage

所在平台: Udemy

课程主页: https://www.udemy.com/course/sdf-persistence-fast-triage/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** SDF: Persistence Fast Triage **课程概述:** 本课程专注于网络攻击中的持久化机制,识别其作为攻击关键节点的重要性。通过分析系统痕迹,可以有效地检测到攻击者的持久化行为。快速识别受感染系统对于有效的调查、范围界定、遏制、缓解和修复至关重要。课程旨在教授学员如何利用现有的系统痕迹(如 Windows 事件日志中的服务和计划任务,以及 Windows 注册表中自动运行项和修改事件)来快速发现持久化机制。课程将从数字取证与事件响应(DFIR)的角度深入剖析这些痕迹,提供关键要素和分析策略。学员将学习如何使用任何取证平台或安全设备进行分析,并通过 Splunk 了解 SIEM(安全信息和事件管理)逻辑示例。课程将使用开源工具和 Python 脚本进行实践练习,并提供完整的 Python 脚本。 **课程重点:** * **持久化机制的重要性:** 学习为何持久化是攻击者的必要手段,以及其作为检测机会的关键作用。 * **痕迹分析:** 专注于分析反复出现在调查中的关键痕迹,包括: * Windows 事件日志(服务) * Windows 事件日志(计划任务) * Windows 注册表(自动运行项) * Windows 注册表(修改事件) * **DFIR 方法论:** 从数字取证与事件响应的角度,理解如何识别和分析上述痕迹。 * **工具和技术:** 学习使用现有的取证平台、安全设备,并通过 Splunk 实现 SIEM 逻辑。 * **Python 脚本实践:** 利用开源工具和 Python 脚本进行实际操作,掌握快速发现持久化机制的技能。 * **资源优化:** 了解早期检测持久化对于做出明智的资源分配决策的价值。

课程评论(0条)

课程详情

Research conducted on malicious campaigns found the successful establishment of a persistence mechanism(s) necessary for the attacker to achieve their goals. Installing persistence is a choke point in the attack method and provides an opportunity for detection through the analysis of affected system artifacts.The identification of a compromised system is a high priority. Discovering the compromise early during an investigation improves scoping, containment, mitigation, and remediation efforts. If persistence is not detected, it may reduce the perceived risk of the system. Either finding is valuable for making resource assignment decisions.This class teaches you how to utilize readily available artifacts to uncover persistence mechanisms quickly. Each module breaks down the artifact from a DFIR point of view, identifying key elements and analysis strategy guidelines along the way. Just about any forensic platform or security appliance may be used once you understand how to approach the artifact. Splunk is used to provide SIEM logic examples. Open-source tools, with a little python scripting, is used for the practical exercises. The completed python scripts are provided as well.The main artifact categories covers evidence that appears in investigations repeatedly:Windows event logs for servicesWindows event logs for scheduled tasks Windows registry autoruns and registry modification events.

课程标签

0人关注该课程

主题相关的课程