Course Outline
Module 1: Understanding the cyber-security landscape
In this module, you will explore the current cybersecurity landscape and learn how adopting the 'assume compromise' philosophy can restrict an attacker’s ability to move laterally between information systems and limit their capacity to escalate privileges within those systems. Although the current cyber-security landscape is vast and perhaps impossible for any single individual to fully comprehend, there are key aspects that those interested in enterprise security fundamentals must understand.
Lessons
- Current Cyber-security Landscape
- Assume Compromise Philosophy
Upon completing this module, students will be able to:
- Describe the current cybersecurity landscape.
- Describe the Assume Compromise Philosophy.
- Identify factors that contribute to the cost of a breach.
Module 2: Red Team: Penetration, Lateral Movement, Escalation, and Exfiltration
Red team versus blue team exercises involve simulating an attack against an organisation’s information systems. The red team simulates, and in some instances executes, the proof-of-concept steps involved in an attack on the organisation’s IT systems. Meanwhile, the blue team simulates the response to that attack. This adversarial approach not only identifies security vulnerabilities within the organisation’s IT configuration but also helps information systems staff learn how to detect and respond to attacks. In this module, you will learn the practice of the Red team versus Blue team approach to detecting and responding to security threats.
Lessons
- Red Team versus Blue Team Exercises
- The Attackers Objective
- Red Team Kill Chain
Upon completing this module, students will be able to:
- Distinguish between responsibilities of red teams and blue teams.
- Identify typical objectives of cyber attackers.
- Describe a kill chain carried out by red teams.
Module 3: Blue Team Detection, Investigation, Response, and Mitigation
In this module, you will explore the roles and goals of the Blue Team within attack exercises. You will learn the structure of an attack against an objective (the Kill Chain) and the methods to limit how an attacker can compromise unprivileged accounts. Additionally, you will learn the techniques used to restrict lateral movement—preventing attackers from using a compromised system to attack others—and how telemetry monitoring is employed to detect attacks.
Lessons
- The Blue Team
- Blue Team Kill Chain
- Restricting Privilege Escalation
- Restrict Lateral Movement
- Attack Detection
Upon completing this module, students will be able to:
- Describe the Blue Team role, goals, and kill chain activities in red team exercises.
- Describe the structure of an attack against an objective (Kill Chain).
- Describe the ways limiting how an attacker can compromise unprivileged accounts.
- Describe the methods used to restrict lateral movement.
- Describe how telemetry monitoring is used to detect attacks.
Module 4: Organizational Preparations
Organisations can implement several ongoing preparations to improve their overall information security approach. This module examines these preparations in detail. You will learn about a conceptual model for thinking about information security and how to approach it effectively, ensuring your organisation adopts a deliberate and robust stance on information security.
Lessons
- CIA Triad
- Organizational Preparations
- Developing and Maintain Policies
Lab : Designing a Blue Team strategy
Upon completing this module, students will be able to:
- Explain the concept of Confidentiality, Integrity, and Availability (CIA) triad.
- Describe the primary activities that should be included in organisational preparations.
- Identify the main principles of developing and maintaining policies.
Upon completing this lab, students will be able to:
- Design a high-level approach to mitigating threats
- Recommend tools and methodology facilitating tracking down origins of cyberattacks
- Provide high-level steps of a recovery effort
- Recommend methods of preventing cyberattacks
- Describe regulatory challenges that result from malware exploits
Requirements
Alongside their professional experience, students undertaking this training should already possess the following technical knowledge:
- Understanding of the current cyber-security ecosystem
- Experience in analysing hacks on computers and networks
- Basic Risk Management
Testimonials (2)
Everything, is a new platform for me and everything was interesting.
Sergiu
Course - AZ-104T00-A: Microsoft Azure Administrator
Thank you for the informative and wonderful course. I would also like to thank the trainer Mr. Ahmed El Gendy for delivering the information in a very smooth and understandable manner. I have benefited greatly from this course and can confidently say that I now understand all the topics and can apply them practically.