Search Courses

Quickly search courses, categories, and downloadable labs

Courses Catalog

(22 courses)

Explore our complete collection of technical courses, hands-on lab environments, and downloadable assets.

Active filters:Format: 001
Showing 1322 of 22 coursesPage 2 of 2

Applied Network Defense | Practical Threat Hunting

A structured system to ensure you’re never at a loss for places and methods to start hunting for evil. Practical Threat Hunting is a foundational course that will teach you how to approach threat hunting using a proven, structured, repeatable framework. Practical Threat Hunting is the course that will teach you to hunt in a way that will never leave you at a shortage of places to start or techniques to manipulate data to spot anomalies. You’ll build skills through a series of expert-led lectures, scenario-based demonstrations, and hands-on lab exercises. Through a combination of theory and application, you’ll learn the basics of threat hunting and apply them to your network immediately. Syllabus Two hunting frameworks: Attack-Based Hunting (ABH) and Data-Based Hunting (DBH) Techniques for leveraging threat intelligence and the MITRE ATT&CK framework for hunting input The 9 most common types of anomalies you’ll encounter when reviewing evidence. The 4 ways threat hunters most commonly transform data to spot anomalies Typical staffing models for hunting capabilities in organizations of all sizes along with pros/cons 5 metrics that support and enable threat hunting operations My two-step system for effective note taking while hunting (and how to transition those notes to longer-term storage for easy searching) An ideal design for a hunter’s wiki/knowledgebase A 5-step framework for dissecting and simulating attacks to prepare for hunting expeditions Applied Network Defense | Practical Threat Hunting

9 modules5.2 GB
001002003

Applied Network Defense | Practical Packet Analysis

Capturing packets is easy, but making sense of them isn’t. This course will teach you the fundamentals of packet analysis. You’ll learn all about common protocols, how to troubleshoot network issues, and how to investigate security incidents at the packet level. It’s easy to fire up Wireshark and capture some packets…but making sense of them is another story. There’s nothing more frustrating than knowing the answers you need lie in a mountain of data that you don’t know how to sift through. That’s why I wrote the first Practical Packet Analysis book a decade ago. That book is now in its third edition, has been translated to several languages, and has sold over 25,000 copies. Now, I’m excited to create an online course based on the book. The Practical Packet Analysis online course is the best way to get hands on visual experience capturing, dissecting, and making sense of packets. Syllabus How networking works at the packet level. How to interpret packet data at a fundamental level in hexadecimal or binary. Basic and advanced analysis features of Wireshark. How to analyze packets on the command line with tshark and tcpdump. Reducing capture files with Berkeley packet filters and Wireshark display filters. Techniques for capturing packets to make sure you’re collecting the right data. How to interpret common network and transport layer protocols like IPv4, IPv6, ICMP, TCP, and UDP. How to interpret common application layer protocols like HTTP, DNS, SMTP, and more. Normal and abnormal stimulus and response patterns for common protocols. Troubleshooting connectivity issues at the packet level. Techniques for carving files from packet streams. Understanding network latency and how to locate the source. How common network attacks are seen by an intrusion detection systems. Techniques for investigating security alerts using packet data. How malware communicates on the network. Applied Network Defense | Practical Packet Analysis

15 modules8 GB
001002003+1

Applied Network Defense | Building Intrusion Detection Honeypots

Building Intrusion Detection Honeypots will teach you how to build, deploy, and monitor honeypots designed to catch intruders on your network. You’ll use free and open source tools to work through over a dozen different honeypot techniques, starting from the initial concept and working to your first alert. Building Intrusion Detection Honeypots is the seminal course on strategic honeypot deployment for network defenders who want to leverage deception to find attackers on their network and slow them down. syllabus What makes an intrusion detection honeypot different from research honeypots. How to leverage the four characteristics of honeypots for the defender’s benefit: deception, interactivity, discoverability, and monitoring. How to think deceptively with an overview of deception from a psychological perspective. How to use the See-Think-Do framework to integrate honeypots into your network and lure attackers into your traps. Tools and techniques for building service honeypots for commonly attacked services like HTTP, SSH, and RDP. How to hide honey tokens amongst legitimate documents, files, and folder. To entice attackers to use fake credentials that give them away. Techniques for embedding honey credentials in services and memory so that attackers will find and attempt to use them. How to build deception-based defenses against common attacks like Kerberoasting and LLMNR spoofing. Monitoring strategies for capturing honeypot interaction and investigating the logs they generate. Applied Network Defense | Building Intrusion Detection Honeypots

10 modules3.8 GB
001002

Applied Network Defense | Splunk for Security Analysts

Splunk is a data analysis platform that allows security practitioners to centralize data, search through it, correlate events, and create security analytics and dashboards. It’s also the most popular commercial SIEM used by security teams to perform investigations and threat hunting. Splunk for Security Analysts will teach you how to use Splunk to onboard data, extract meaningful fields, and search through it using real security data to conduct security research and investigations. This course goes beyond the documentation to provide a diverse set of real-world security data that you’ll use to gain confidence with Splunk’s extensive capabilities. syllabus The Splunk Data Pipeline Data Onboarding Finding and Exploring Data Enrichment and Advanced Filtering Sharing, Scheduling, and Alerting Visualization and Dashboards Applied Network Defense | Splunk for Security Analysts

3 modules4.4 GB
001002003

Applied Network Defense | YARA for Security Analysts

Learn to use YARA to detect malware, triage compromised systems, and perform threat intelligence research. Detecting malicious elements within files is a core security skill for incident responders, SOC analysts, threat intelligence analysts, malware analysts, and detection engineers alike. There are different ways to accomplish that goal, but none are more flexible or widely used as YARA. YARA is a pattern-matching tool used to help identify and classify malware in a variety of scenarios. By writing YARA rules, security practitioners can detect whether malware exists within a group of files, triage a potentially compromised host, or identify common elements between samples to bolster threat intelligence. Syllabus YARA Fundamentals YARA Rule Syntax Detection Research Methodology Ruleset Management Adversary Tradecraft Applied Network Defense | YARA for Security Analysts

2 modules4.2 GB
001002003

Kaspersky – Windows incident response

Are you looking to improve the expertise of your in-house digital forensics and incident response team? Or do you want to train yourself in the area of incident response to identify the complex attacks? This Kaspersky Windows Incident Response course brings you concentrated knowledge from the company’s Global Emergency Response Team (GERT) experts. The course’s curriculum is heavily focused on practicing. Our experts will take you through all the stages of responding to an incident based on a real-life ransomware case. You will master incident detection, evidence acquisition, log file analysis, network analysis and creation of IoCs, and also get introduced to memory forensics. You will be working in a simulated virtual environment with all the necessary tools to practice IR. Your coaches Ayman Shaaban and Kai Schuricht have handled security incidents for Kaspersky incident response customers around the globe. You will get not only super-clear theoretical knowledge but also tap into their up-to-date experience, skills and tips. A Kaspersky report shows malware can survive in a company’s digital environment for months and even years under the radar. After completing the course you will be able to verify and handle threats quicker in order to minimize the impact and contain the damage. Syllabus Introduction Incident response process Incident detection: Network & System based Evidence acquisition Memory analysis Log file analysis Network analysis Cyber Threat Intelligence (CTI) Windows incident response

1 modules2.3 GB
001002

Kaspersky – Targeted malware reverse engineering

Skilled reverse engineers aren’t born – they’re made by experience. If you are a cybersecurity specialist with a good understanding of malware analysis methodologies & tools and are looking for more confidence in applying your skills, you can bridge the gap by working hands-on with real-life cases. With this challenge in mind, our intermediate-level course is built around analysis of 10 targeted malware cases used in the wild by powerful APT actors recently. Cases including MontysThree , LuckyMouse & Lazarus have been researched personally by our trainers as part of their work in the Kaspersky GReAT team – so you will get first-hand knowledge and best practices from their exclusive research. By working in the dedicated virtual lab, using an array of tools like IDA Pro, Hex-Rays decompiler, Hiew, 010Editor and many others, you will gain practical experience analyzing real-life targeted malware and will become a more efficient malware analyst and reverse engineer and prove your skills are relevant to today’s threat landscape. Syllabus Introduction and Chafer LuckyMouse Biodata Exploit Topinambour Biodata Trojan DeathStalker MontysThree Lazarus Group Cloud Snooper Cycldek’s Tried Targeted malware reverse engineering

2 modules7.7 GB
001002003+1

Kaspersky – Security operations and threat hunting

Big companies with complex IT infrastructure need to protect it – or face the consequences of being compromised. Sophisticated attackers can bypass automatic defenses unnoticed. Here’s where Security Operations Center (SOC) comes to the rescue, bringing the expertise and skills of its professionals for upgraded business protection. Developed by Kaspersky’s own SOC experts, this course offers a comprehensive training to SOC analysts and other staff dealing with security operations. The knowledge you will get is practical and tested: our experts update it daily, provide security to Kaspersky itself and deliver on-site training to clients all over the world. During the time on the course, you will get to know the diverse roles within a SOC, its services and use cases, get acquainted with the modern attack tactics, techniques, and procedures, and learn how SOC helps deal with them. Within the numerous extensive practice sessions in the restricted areas of the virtual labs, you’ll get an opportunity to develop your skills in incident detection and investigation. Syllabus General Cybersecurity concepts Windows Linux Security operations and threat hunting

1 modules7.4 GB
001002003+1

Kaspersky – Advanced Malware Analysis Techniques

Kaspersky opens a treasure-box: our legendary training program on Advanced Malware Analysis Techniques. It helps established reverse engineers, incident responders & digital forensics specialists level-up their work on cybersecurity incidents and become unique experts. The main focus of the course is advanced static analysis because for cybersecurity incidents involving previously unseen malicious code, this is the most reliable way to determine functionality of the code and find actionable artefacts. It allows organizations affected by APTs to define adequate damage assessment and incident response. The course also heavily features our exclusive know-hows on the automation of decryption, decoding and other processing of the samples which helps not only optimize routine tasks, but preserves your work in the code. You will be introduced to a custom static analysis framework (available for download), proven to be very efficient during decades of Kaspersky APT research. Syllabus Introduction Shell Msfvenom Bangladesh GPCA Regin driver Decrypt string Driver Miniduke Rocra Cobalt Cloud Atlas Miniduke PDF Ragua Py2exe Cridex Carbanak Snake Advanced Malware Analysis Techniques

2 modules5.1 GB
001002003

Reverse Engineering Professional (eCRE)

Are you looking to gain the theoretical and practical knowledge required to perform advanced reverse engineering of third-party software and malware on the assembly language level? The Reverse Engineering Professional Learning Path will teach you several methods to identify, isolate, and finally, analyze portions of code which are of high interest, as well as the most common Windows APIs utilized for file, memory, and registry manipulation by either software protections (such as packers) or malware. During the learning process, you will also get insights into the most common anti-reversing tricks, including different code obfuscation methods, and how to bypass them. The Reverse Engineering Professional Learning Path also prepares you for the eCRE exam and certification. Learning Objects Reverse Engineering Foundations Practical Reverse Engineering eCRE

Overview1.4 GB
001002