Skip to main content
00:00/00:00
Lecture 28 of 119

The-Hunting-Maturity-Model-(HMM)-(20-00) hide01.ir

Download Course (Free)

Course Content

0 / 119 completed
Section 1: Course Introduction5 videos

Course-Introduction-(5-13) hide01.ir

8m

About-the-Instructor-(2-30) hide01.ir

4m

The-SOC-201-Methodology-(4-23) hide01.ir

5m

The-Modern-Adversary-(10-17) hide01.ir

19m

Course-Support-(3-05) hide01.ir

5m
Section 2: Lab Setup8 videos

Lab-Setup-(3-31) hide01.ir

5m

Installing-a-Hypervisor-(7-26) hide01.ir

10m

Installing-Ubuntu-(13-20) hide01.ir

13m

Configuring-Ubuntu-(8-17) hide01.ir

10m

Installing-Windows-(11-15) hide01.ir

20m

Configuring-Windows-(7-52) hide01.ir

11m

Installing-Splunk-(16-16) hide01.ir

17m

Configuring-the-Lab-Network-(10-10) hide01.ir

12m
Section 3: Introduction to Incident Response10 videos

Introduction-to-Incident-Response-(5-59) hide01.ir

9m

The-Incident-Response-Process-(14-04) hide01.ir

16m

Incident-Response--Preparation-(14-44) hide01.ir

24m

Incident-Response--Identification-(5-39) hide01.ir

9m

Incident-Response--Containment-(10-45) hide01.ir

18m

Incident-Response--Eradication-(6-05) hide01.ir

11m

Incident-Response--Recovery-(7-43) hide01.ir

13m

Incident-Response--Lessons-Learned-(5-15) hide01.ir

9m

Incident-Response-vs.-Threat-Hunting-(11-39) hide01.ir

16m

The-OODA-Loop-(18-32) hide01.ir

30m
Section 4: Introduction to Threat Hunting13 videos

Introduction-to-Threat-Hunting-(8-58) hide01.ir

15m

The-Argument-for-Threat-Hunting-(13-14) hide01.ir

18m

Threat-Hunting-Teams-(16-55) hide01.ir

24m

Threat-Hunting-Data-Sources-(19-30) hide01.ir

29m

The-Hunting-Maturity-Model-(HMM)-(20-00) hide01.ir

23mNow Playing

Cyber-Threat-Intelligence-(6-22) hide01.ir

12m

The-Cyber-Kill-Chain-(16-52) hide01.ir

18m

The-MITRE-ATT&CK-Framework-(15-05) hide01.ir

50m

Exploring-MITRE-ATT&CK-(12-37) hide01.ir

41m

Structured-Threat-Hunting-(16-01) hide01.ir

28m

Unstructured-Threat-Hunting-(9-21) hide01.ir

15m

MITRE-ATT&CK-Navigator-(21-48) hide01.ir

59m

MITRE-ATT&CK-Navigator--Gap-Analysis-and-Threat-Hunting-(19-02) hide01.ir

1h 2m
Section 5: Data Transformation15 videos

Data-Transformation-(5-36) hide01.ir

8m

Data-Transformation--Searching-(14-16) hide01.ir

22m

Searching-in-the-Command-Line-(19-19) hide01.ir

22m

Searching-in-PowerShell-(27-29) hide01.ir

35m

Data-Transformation--Aggregations-(9-24) hide01.ir

15m

Searching-in-Splunk-(21-54) hide01.ir

37m

Aggregations-in-the-Command-Line-(25-36) hide01.ir

23m

Aggregations-in-PowerShell-(10-24) hide01.ir

13m

Data-Transformation--Statistics-(9-38) hide01.ir

15m

Aggregations-in-Splunk-(34-43) hide01.ir

49m

Statistics-in-the-Command-Line-(22-04) hide01.ir

15m

Statistics-in-PowerShell-(13-24) hide01.ir

11m

Statistics-in-Splunk-(15-23) hide01.ir

22m

Data-Transformation--Visualizations-(5-00) hide01.ir

10m

Visualizations-in-Splunk-(25-31) hide01.ir

34m
Section 6: Understanding Anomalies12 videos

Understanding-Anomalies-(20-33) hide01.ir

38m

Categorizing-Anomalies-(1-11) hide01.ir

2m

Masquerading-(10-39) hide01.ir

25m

Ambiguous-Identifiers-(11-13) hide01.ir

23m

Frequency-&-Volume-Anomalies-(16-14) hide01.ir

25m

Temporal-Anomalies-(14-53) hide01.ir

23m

Location-&-Environment-Anomalies-(14-25) hide01.ir

28m

Obfuscated-PowerShell-Analysis-(6-34) hide01.ir

13m

Structure-&-Format-Anomalies-(16-16) hide01.ir

35m

Alternate-Data-Stream-(ADS)-Analysis-(19-26) hide01.ir

19m

Entropy-Analysis-(4-56) hide01.ir

7m

Absence-&-Suppression-Anomalies-(7-57) hide01.ir

16m
Section 7: Dissecting Threat Reports6 videos

Mapping-Steps-to-Artifacts-(4-40) hide01.ir

8m

Breaking-Down-Attack-Steps-(5-05) hide01.ir

10m

Dissecting-Threat-Reports-(18-54) hide01.ir

38m

Mapping-Artifacts-to-Evidence-Sources-(7-51) hide01.ir

14m

Visualizing-with-MITRE-ATT&CK-Navigator-(4-34) hide01.ir

13m

Intrusion-Analysis-Resources-(5-56) hide01.ir

26m
Section 8: Threat Hunting Lab18 videos

Hunting-Execution-Artifacts-(9-46) hide01.ir

18m

Tracing-an-Attack-Chain-(27-04) hide01.ir

35m

Hunting-Cmd-Execution-(20-20) hide01.ir

38m

Hunting-Persistence-Artifacts-(7-33) hide01.ir

17m

Hunting-PowerShell-Execution-(36-09) hide01.ir

1h 7m

Hunting-Process-Trees-(9-26) hide01.ir

19m

Hunting-Persistence--Registry-Run-Keys-(17-20) hide01.ir

35m

Hunting-Persistence--Lookup-Tables-(27-30) hide01.ir

45m

Hunting-Defense-Evasion-Artifacts-(16-39) hide01.ir

24m

Hunting-Command-and-Control-(C2)-Artifacts-(7-40) hide01.ir

13m

Hunting-C2--Ingress-Tool-Transfer-(LOLBAS)-(7-35) hide01.ir

9m

Hunting-C2--Ingress-Tool-Transfer-(Network-Connection-Events)-(4-21) hide01.ir

4m

Hunting-Lateral-Movement-Artifacts-(8-27) hide01.ir

12m

Hunting-C2--Ingress-Tool-Transfer-(File-System-Events)-(12-57) hide01.ir

23m

Hunting-Lateral-Movement--PsExec-(Service-Creation)-(9-38) hide01.ir

10m

Hunting-Lateral-Movement--PsExec-(Reversing-Regex)-(14-25) hide01.ir

15m

Hunting-Lateral-Movement--PsExec-(Named-Pipes)-(4-12) hide01.ir

6m

Module-Recap-(5-46) hide01.ir

8m
Section 9: Collection at Scale7 videos

Introduction-to-Collection-(3-24) hide01.ir

2m

Introduction-to-WMI-(11-11) hide01.ir

21m

WMIC-Collection-and-Filter-Examples-(5-51) hide01.ir

7m

Collection-with-WMIC-(18-56) hide01.ir

30m

Remote-Collection-with-WMIC-(5-38) hide01.ir

5m

Scripting-WMI-Collection-(10-31) hide01.ir

12m

WMI-Automated-Collection-Frameworks-(6-57) hide01.ir

11m
Section 10: PowerShell 10110 videos

Introduction-to-PowerShell-(4-58) hide01.ir

9m

PowerShell-101-(1-55) hide01.ir

4m

PowerShell-101--Cmdlets-(6-09) hide01.ir

8m

PowerShell-101--Aliases-(6-45) hide01.ir

6m

PowerShell-101--Objects-and-the-Pipeline-(9-08) hide01.ir

12m

PowerShell 101 - Providers hide01.ir

18m

PowerShell-101--Selecting,-Sorting,-and-Formatting-(17-35) hide01.ir

22m

PowerShell 101 - Variables and Data Types hide01.ir

22m

PowerShell 101 - Control Flow hide01.ir

19m

Working with WMI and CIM hide01.ir

14m
Section 11: PowerShell for Incident Response14 videos

Live Incident Response Using PowerShell hide01.ir

53m

PowerShell Remoting hide01.ir

11m

PS Remoting - One-to-One Remoting hide01.ir

12m

PS Remoting - One-to-Many Remoting hide01.ir

23m

PowerShell Authentication hide01.ir

16m

PS Remoting - Script Execution at Scale hide01.ir

12m

Malicious PowerShell Usage hide01.ir

19m

Introduction to the Kansa IR Framework hide01.ir

21m

Kansa - Remote Collection (Part 1) hide01.ir

21m

Kansa - Modules hide01.ir

38m

Kansa - Remote Collection (Part 2) hide01.ir

31m

Collection and Analysis Challenge hide01.ir

11m

Kansa - Collection Analysis hide01.ir

41m

Collection Analysis Challenge Walkthrough hide01.ir

1h 30m
Section 12: Conclusion1 videos

Course Wrap Up hide01.ir

7m