Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity (CBRTHD)
Duration: 5 Days
SGD 2,100.00
The Conducting Threat Hunting and Defending using Cisco Technologies for CyberOps (CBRTHD) is a Cisco threat hunting training that introduces and guides you to a proactive security search through networks, endpoints, and datasets to hunt for malicious, suspicious, and risky activities that may have evaded detection by existing tools.
Course Objectives
Define threat hunting and identify core concepts used to conduct threat hunting investigations
Examine threat hunting investigation concepts, frameworks, and threat models
Define cyber threat hunting process fundamentals
Define threat hunting methodologies and procedures
Describe network-based threat hunting
Identify and review endpoint-based threat hunting
Identify and review endpoint memory-based threats and develop endpoint-based threat detection
Define threat hunting methods, processes, and Cisco tools that can be utilized for threat hunting
Describe the process of threat hunting from a practical perspective
Describe the process of threat hunt reporting
Target Audience
Security Operations Center staff
Security Operations Center (SOC) Tier 2 Analysts
Threat Hunters
Cyber Threat Analysts
Threat Managers
Risk Managements
Course Prerequisites
The knowledge and skills you are expected to have before attending this training are:
General knowledge of networks
Cisco CCNP Security certification
These skills can be found in the following Cisco Learning Offerings:
Implementing and Administering Cisco Solutions (CCNA)
Performing CyberOps Using Cisco Security Technologies (CBRCOR)
Conducting Forensic Analysis and Incident Response Using Cisco Technologies for CyberOps (CBRFIR)
Course Outline
Threat Hunting Theory
Threat Hunting Concepts
Threat Hunting Types
Conventional Threat Detection vs Threat Hunting
Threat Hunting Concepts, Frameworks and Threat Models
Cybersecurity Concepts
Common Threat Hunting Platforms
Threat Hunting Frameworks
Threat Modeling
Case Study: Use the PASTA Threat Model
Threat Hunting Process Fundamentals
Threat Hunting Approaches
Threat Hunting Tactics and Threat Intelligence
Defining Threat Hunt Scope and Boundaries
Planning the Threat Hunt Process
Threat Hunting Methodologies and Procedures
Investigative Thinking
Identify Common Anolmalies
Analyze Device and System Logs
Determine the Best Threat Hunt Methods
Automate the Threat Hunting Process
Network-Based Threat Hunting
Operational Security Considerations
Performing Network Data Analysis and Detection Development
Performing Threat Hunting in the Cloud
Endpoint-Based Threat Hunting
Threat Hunting for Endpoint-Based Threats
Acquiring Data from Endpoint
Performing Host-Based Analysis
Endpoint-Based Threat Detection Development
Analyze Endpoint Memory
Examining Systems Memory Using Forensics
Developing Endpoint Detection Methods
Uncovering New Threats, Indicators and Building TTPs
Threat Hunting with Cisco Tools
Threat Hunting with Cisco Tools
Cisco XDR Components
Threat Hunting Investigation Summary: A Practical Approach
Conducting a Threat Hunt
Reporting the Aftermath of a Threat Hunt Investigation
Measure the Success of a Threat Hunt
Report Your Findings
Threat Hunting Outcomes
Lab Outline
Categorize Threats with MITRE ATTACK Tactics and Techniques
Compare Techniques Used by Different APTs with MITRE ATTACK Navigator
Model Threats Using MITRE ATTACK and D3FEND
Prioritize Threat Hunting Using the MITRE ATTACK Framework and Cyber Kill Chain
Determine the Priority Level of Attacks Using MITRE CAPEC
Explore the TaHiTI Methodology
Perform Threat Analysis Searches Using OSINT
Attribute Threats to Adversary Groups and Software with MITRE ATTACK
Emulate Adversaries with MITRE Caldera
Find Evidence of Compromise Using Native Windows Tools
Hunt for Suspicious Activities Using Open-Source Tools and SIEM
Capturing of Network Traffic
Extraction of IOC from Network Packets
Usage of ELK Stack for Hunting Large Volumes of Network Data
Analyzing Windows Event Logs and Mapping Them with MITRE Matrix
Endpoint Data Acquisition
Inspect Endpoints with PowerShell
Perform Memory Forensics with Velociraptor
Detect Malicious Processes on Endpoints
Identify Suspicious Files Using Threat Analysis
Conduct Threat Hunting Using Cisco Secure Firewall, Cisco Secure Network Analytics, and Splunk
Conduct Threat Hunt Using Cisco XDR Control Center and Investigate
Initiate, Conduct, and Conclude a Threat Hunt
*Course fee/pax. Minimum 4 registration is required to schedule the Class.
(CBRTHD)
Conducting Threat Hunting and Defending using Cisco Technologies for Cybersecurity
Cybersecurity certification courses
Ethical hacking training
Network security certification
Information security training
Cybersecurity bootcamp
SOC analyst training
Penetration testing course
Cybersecurity online certification
IT security certifications for beginners
Advanced cybersecurity training
IBM cybersecurity certification
IBM security training courses
IBM QRadar training
IBM cyber security professional certificate
IBM SIEM certification
Palo Alto certification training
Palo Alto firewall course
PCNSE certification training
Palo Alto network security certification
Palo Alto online training
CompTIA Security+ certification
CompTIA CySA+ training
CompTIA PenTest+ course
CompTIA Network+ certification
CompTIA A+ cybersecurity path
Cisco cybersecurity certification
Cisco CCNA security training
Cisco CCNP security course
Cisco network security certification
Cisco ethical hacking course
Cybersecurity certification Singapore
Ethical hacking course Singapore
Cisco certification Singapore
CompTIA Security+ Singapore
Palo Alto training Singapore
IBM cybersecurity course Singapore
Cybersecurity training Malaysia
Ethical hacking Malaysia course
Cisco certification Malaysia
CompTIA certification Malaysia
Palo Alto Malaysia training
IBM cybersecurity Malaysia
Cybersecurity certification Thailand
Ethical hacking course Thailand
Cisco Thailand training
CompTIA Thailand certification
Palo Alto Thailand course
IBM cybersecurity Thailand
Cybersecurity training Cambodia
Ethical hacking Cambodia course
Cisco certification Cambodia
CompTIA Cambodia training
Palo Alto Cambodia certification
IBM cybersecurity Cambodia
Cybersecurity training Myanmar
Ethical hacking Myanmar course
Cisco Myanmar certification
CompTIA Myanmar training
Palo Alto Myanmar certification
IBM cybersecurity Myanmar
Cybersecurity certification USA
Ethical hacking course USA
Cisco certification USA
CompTIA Security+ USA
Palo Alto training USA
IBM cybersecurity certification USA
Cybersecurity certification UK
Ethical hacking course UK
Cisco certification UK
CompTIA UK training
Palo Alto UK certification
IBM cybersecurity UK
Cybersecurity certification UAE
Cybersecurity course Dubai
Ethical hacking Dubai
Cisco certification Dubai
CompTIA UAE training
Palo Alto Dubai certification
IBM cybersecurity UAE
Best cybersecurity certification for beginners in Singapore
Online CompTIA Security+ course with certification USA
Cisco CCNA security training institute in Dubai
Palo Alto PCNSE certification training in Malaysia
IBM cybersecurity certification online UK