Modern Threat Hunting Strategies to Identify Attacks

Modern Threat Hunting Strategies to Identify Attacks

2h 9mIntermediate2024-08-28

Authors

Paula Januszkiewicz

Paula Januszkiewicz

Course details

Fortify your organization's defenses against sophisticated cyber threats by learning how to implement methods and techniques that can prevent, identify, and mitigate attacks. Examine the critical areas of permissions, privileges, and network tracing to enhance the protection against cyberattacks. Discover a checklist of steps to take that strengthen security hygiene. Learn about static and dynamic malware analysis. Review practical case studies of misconfigured service accounts and Kerberoasting attacks.

The course also covers methods for uncovering lateral movements and network communications that criminals use to navigate through and harm networks. Learn about important techniques for extracting and reviewing logs and traces from disks and memory, for comprehensive monitoring and responding quickly to potential threats. Join instructor Paula Januszkiewicz who equips you to be able to implement robust security measures and contribute to the overall system integrity of your organization.

Skills covered

Vulnerability ManagementIncident ResponseCybersecurityDeep Dive (X:Y)

Concepts

Introduction

  • Threat hunting in the modern world

Permissions and Privileges - Impact on Attack Success

  • Permissions and deflecting cyberattacks
  • Privileges and deflecting cyberattacks
  • Security hygiene checklist - Permissions and privileges

Modern Threat Hunting Practices

  • Detecting unnecessary services
  • Reviewing places with persistence
  • Case Study - Misconfigured service account
  • Steps for static malware analysis
  • Steps for dynamic malware analysis
  • Uncovering lateral movement

Uncovering Network Communication

  • Network tracing in threat hunting
  • Tools for network tracing
  • Types of vulnerabilities found in network tracing
  • Proactive security - Network tracing and system processes
  • Security hygiene checklist - Network tracing

Data, Extracting Traces, and Logs

  • Data correlation techniques
  • Case study - Kerberoasting Attack
  • Extracting traces of attacks from the disk
  • Extracting traces of attacks from the memory
  • Reviewing logs for useful events
  • Case study - Practical attack scenario

Conclusion

  • Next steps
80,000 Toman