Search Courses

Quickly search courses, categories, and downloadable labs

Applied Network Defense Courses

(6 courses)

Explore all courses, labs, and learning resources from Applied Network Defense.

Active filters:Category: Applied Network DefenseFormat: 001
Showing 16 of 6 coursesPage 1 of 1

Applied Network Defense – CyberChef for Security Analysts

CyberChef for Security Analysts will teach you how to use CyberChef to perform common data manipulation, transformation, deobfuscation, and extraction techniques using real security data*. This isn’t just a simple tutorial, you’ll work through diverse exercises using real-world security data to build a toolkit of techniques.Simply put, CyberChef for Security Analysts is an example-driven master class on dealing with the most common types of data you’ll encounter in common blue team roles like SOC analysts, malware reverse engineering, forensic investigations, threat hunting, and threat intelligence.

7 modules4.6 GB
001002003

Applied Network Defense | Practical Threat Hunting

A structured system to ensure you’re never at a loss for places and methods to start hunting for evil. Practical Threat Hunting is a foundational course that will teach you how to approach threat hunting using a proven, structured, repeatable framework. Practical Threat Hunting is the course that will teach you to hunt in a way that will never leave you at a shortage of places to start or techniques to manipulate data to spot anomalies. You’ll build skills through a series of expert-led lectures, scenario-based demonstrations, and hands-on lab exercises. Through a combination of theory and application, you’ll learn the basics of threat hunting and apply them to your network immediately. Syllabus Two hunting frameworks: Attack-Based Hunting (ABH) and Data-Based Hunting (DBH) Techniques for leveraging threat intelligence and the MITRE ATT&CK framework for hunting input The 9 most common types of anomalies you’ll encounter when reviewing evidence. The 4 ways threat hunters most commonly transform data to spot anomalies Typical staffing models for hunting capabilities in organizations of all sizes along with pros/cons 5 metrics that support and enable threat hunting operations My two-step system for effective note taking while hunting (and how to transition those notes to longer-term storage for easy searching) An ideal design for a hunter’s wiki/knowledgebase A 5-step framework for dissecting and simulating attacks to prepare for hunting expeditions Applied Network Defense | Practical Threat Hunting

9 modules5.2 GB
001002003

Applied Network Defense | Practical Packet Analysis

Capturing packets is easy, but making sense of them isn’t. This course will teach you the fundamentals of packet analysis. You’ll learn all about common protocols, how to troubleshoot network issues, and how to investigate security incidents at the packet level. It’s easy to fire up Wireshark and capture some packets…but making sense of them is another story. There’s nothing more frustrating than knowing the answers you need lie in a mountain of data that you don’t know how to sift through. That’s why I wrote the first Practical Packet Analysis book a decade ago. That book is now in its third edition, has been translated to several languages, and has sold over 25,000 copies. Now, I’m excited to create an online course based on the book. The Practical Packet Analysis online course is the best way to get hands on visual experience capturing, dissecting, and making sense of packets. Syllabus How networking works at the packet level. How to interpret packet data at a fundamental level in hexadecimal or binary. Basic and advanced analysis features of Wireshark. How to analyze packets on the command line with tshark and tcpdump. Reducing capture files with Berkeley packet filters and Wireshark display filters. Techniques for capturing packets to make sure you’re collecting the right data. How to interpret common network and transport layer protocols like IPv4, IPv6, ICMP, TCP, and UDP. How to interpret common application layer protocols like HTTP, DNS, SMTP, and more. Normal and abnormal stimulus and response patterns for common protocols. Troubleshooting connectivity issues at the packet level. Techniques for carving files from packet streams. Understanding network latency and how to locate the source. How common network attacks are seen by an intrusion detection systems. Techniques for investigating security alerts using packet data. How malware communicates on the network. Applied Network Defense | Practical Packet Analysis

15 modules8 GB
001002003+1

Applied Network Defense | Building Intrusion Detection Honeypots

Building Intrusion Detection Honeypots will teach you how to build, deploy, and monitor honeypots designed to catch intruders on your network. You’ll use free and open source tools to work through over a dozen different honeypot techniques, starting from the initial concept and working to your first alert. Building Intrusion Detection Honeypots is the seminal course on strategic honeypot deployment for network defenders who want to leverage deception to find attackers on their network and slow them down. syllabus What makes an intrusion detection honeypot different from research honeypots. How to leverage the four characteristics of honeypots for the defender’s benefit: deception, interactivity, discoverability, and monitoring. How to think deceptively with an overview of deception from a psychological perspective. How to use the See-Think-Do framework to integrate honeypots into your network and lure attackers into your traps. Tools and techniques for building service honeypots for commonly attacked services like HTTP, SSH, and RDP. How to hide honey tokens amongst legitimate documents, files, and folder. To entice attackers to use fake credentials that give them away. Techniques for embedding honey credentials in services and memory so that attackers will find and attempt to use them. How to build deception-based defenses against common attacks like Kerberoasting and LLMNR spoofing. Monitoring strategies for capturing honeypot interaction and investigating the logs they generate. Applied Network Defense | Building Intrusion Detection Honeypots

10 modules3.8 GB
001002

Applied Network Defense | Splunk for Security Analysts

Splunk is a data analysis platform that allows security practitioners to centralize data, search through it, correlate events, and create security analytics and dashboards. It’s also the most popular commercial SIEM used by security teams to perform investigations and threat hunting. Splunk for Security Analysts will teach you how to use Splunk to onboard data, extract meaningful fields, and search through it using real security data to conduct security research and investigations. This course goes beyond the documentation to provide a diverse set of real-world security data that you’ll use to gain confidence with Splunk’s extensive capabilities. syllabus The Splunk Data Pipeline Data Onboarding Finding and Exploring Data Enrichment and Advanced Filtering Sharing, Scheduling, and Alerting Visualization and Dashboards Applied Network Defense | Splunk for Security Analysts

3 modules4.4 GB
001002003

Applied Network Defense | YARA for Security Analysts

Learn to use YARA to detect malware, triage compromised systems, and perform threat intelligence research. Detecting malicious elements within files is a core security skill for incident responders, SOC analysts, threat intelligence analysts, malware analysts, and detection engineers alike. There are different ways to accomplish that goal, but none are more flexible or widely used as YARA. YARA is a pattern-matching tool used to help identify and classify malware in a variety of scenarios. By writing YARA rules, security practitioners can detect whether malware exists within a group of files, triage a potentially compromised host, or identify common elements between samples to bolster threat intelligence. Syllabus YARA Fundamentals YARA Rule Syntax Detection Research Methodology Ruleset Management Adversary Tradecraft Applied Network Defense | YARA for Security Analysts

2 modules4.2 GB
001002003