Threat Hunting: Network Data
1h 36mBeginner2024-01-25
Authors

Mike Wylie
Information Security Expert and Threat Manager
Course details
Despite investing resources in cybersecurity, organizations can still fall prey to cyberattacks. While properly configured technology can prevent most attacks, cybercriminals have developed techniques to evade detection. In this course, Michael Wylie, an information security expert, provides his insights, lessons learned, and advice on threat hunting using network telemetry. He discusses topics such as data sources, advantages and disadvantages of different data types, and methods for detecting malicious activity on your network.
Skills covered
Network SecurityIncident ResponseCybersecurityDeep Dive (X:Y)
Concepts
0. Introduction
- 01 - Network threat hunting essentials - Staying proactive
- 02 - The importance of network threat hunting
1. Thinking like the Adversary - Threat Actors
- 03 - Threat actor types and motivations
- 04 - Crown jewel identification
2. Network Data Sources
- 05 - Network threat hunting data sources
- 06 - Threat hunting in packets
- 07 - Threat hunting using network flow
- 08 - Threat hunting in infrastructure logs
3. Network Threat Hunting Tools
- 09 - Use an SIEM (Security Information and Event Management) for threat-hunting
- 10 - Use Wireshark for threat-hunting
- 11 - Use IDS or IPS for threat-hunting
- 12 - Use Bro or Zeek for threat-hunting
- 13 - Security Onion
4. Hunting the Undetected
- 14 - Leverage IOCs in threat hunting
- 15 - Baseline to identify anomalies
- 16 - Least frequency analysis to identify outliers
- 17 - Hypothesis threat hunting
5. How Hackers Abuse Protocols
- 18 - HTTP protocol attack methods
- 19 - HTTPS protocol attack methods
- 20 - SMB protocol attack methods
- 21 - DNS protocol attack methods
6. Network Threat Hunts
- 22 - Hunt command and control (C2)
- 23 - Hunt lateral movement
- 24 - Hunt remote desktop software
Conclusion
- 25 - Continue with network threat hunting