
Overview
This class will provide the students with a unique perspective on network intrusion investigations and analysis. Students will begin the course by compromising a system ("ethical hacking") leveraging techniques that have been seen in the wild by attackers. Once in, they will walk through the stages of an intrusion, from compromise to entrenchment, and exfiltration of data. The course then takes a unique spin in that students will review the captured network traffic looking for artifacts of their compromise, combing through packet captures to see the footprint that they, as the attacker, have left. Not stopping there, students will then learn the principles of an incident response, leveraging the tools of the trade to collect volatile data as well as forensic imaging of a compromised host. Finally, class attendees with complete the course by performing forensic analysis of the acquired artifacts, rounding out the lifecycle of an intrusion investigation.
This course will significantly benefit security professionals, network administrators, systems administrators, auditors, cyber investigators and anyone who is concerned about the integrity and security of their systems and network infrastructure. This course will also be extremely beneficial to anyone with a firm technical background who might be asked to investigate a data breach incident, intrusion case.
Audience
Prerequisites
Course duration
5 days
Course Objectives
Upon successfully completing the course, students will be able to:
Course outline