Security Concepts
- The CIA triad and its relevance in everyday work
- Comparing security deployments and terminology
- Defense in depth as a strategy
- Comparing access control models
- Correctly reading CVSS terminology
- Recognising visibility gaps in network, host and cloud
- Inferring data exfiltration from traffic profiles
- The 5-tuple approach to scoping a compromised host
- Rule-based versus behavioural and statistical detection
Security Monitoring
- Distinguishing between attack surface and vulnerability
- Which technologies deliver which data, and how they affect visibility
- Network attacks: protocol-based, denial of service, distributed denial of service, man-in-the-middle
- Attacks on web applications: SQL injection, command injection, cross-site scripting
- Social engineering, including with generative AI
- Attacks on endpoints: buffer overflow, command and control, malware, ransomware
- Obfuscation techniques: tunnelling, encryption, proxies
- Certificates and PKI in a security context
Host-Based Analysis
- Endpoint technologies in security monitoring, with rules, signatures and predictive AI
- Identifying components of Windows and Linux systems
- The role of attribution in an investigation
- Determining evidence types from the logs available
- Evaluating logs from operating system, SIEM, SOAR and command line
- Interpreting reports from malware analysis tools and sandboxes
Network Intrusion Analysis
- Mapping events to their source technologies
- Deep packet inspection versus packet filters and stateful firewalls
- Inline interrogation versus taps and traffic monitoring
- Data from taps versus transaction data from NetFlow
- Extracting files from a TCP stream with Wireshark
- Recognising key elements of an attack in a PCAP file
- Reading protocol headers for intrusion analysis
- Regular expressions in practice
Security Policies and Procedures
- Management concepts overview
- The incident response plan per NIST SP 800-61
- Applying the incident handling process to an event
- Mapping stakeholders to NIST IR categories
- Forensics fundamentals per NIST SP 800-86
- Network and server profiling
- Identifying data worth protecting on the network
- Classifying events per the Cyber Kill Chain and Diamond Model
- SOC metrics: time to detection, containment and response