Courses Catalog
(66 courses)Explore our complete collection of technical courses, hands-on lab environments, and downloadable assets.
Applied Network Defense | Demystifying Regular Expressions
Most security analysis and detection tools support matching with regular expressions because of limitations in their own feature set. This means that if you can write regular expressions, you can search with infinite precision. This applies to IDS engines, SIEMs, and even command line tools like grep. The phrase “searching for a needle in a haystack” is overused, but it’s a serious component of what security analysts do. A large part of our success is contingent on being able to search through large repositories of data and match things that meet very specific criteria. Demystifying Regular Expressions will help you do exactly that. Syllabus The most common uses of regular expressions and how to apply them in places you weren’t even aware of. The process of iteratively building and testing regular expressions for things you want to match. Techniques for overcoming common gotchas like dealing with whitespace How to Evaluate the efficiency of expressions by the number of steps it takes to match. A definitive guide to escaping so you’ll know when and how to do it How quantifiers can be used to match specific numbers of data occurrences How to use capture groups to reference specific matched content and perform additional operations on it Complex behavioral structures like lookarounds and conditionals The use of modifiers to match case-sensitive, enable free-spacing, or match in single line mode Applied Network Defense | Demystifying Regular Expressions
Applied Network Defense | Osquery for Security Analysis
Osquery for Security Analysis will teach you how to use Osquery to perform thorough investigations of hosts on your network. This isn’t just an Osquery tutorial, it’s a course designed to help you improve your host-based investigation skills using one of the best tools for the job. syllabus How to craft SQL queries to interrogate Windows, Linux, and MacOS hosts Common queries for performing software inventory and asset control Strategies for interrogating processes to determine if they are malicious Techniques for uncovering persistence and lateral movement Triaging suspicious systems using high-value data tables Hunting leveraging MITRE ATT&CK techniques Complete deployment of distributed Osquery across your network using FleetDM and ElasticStack How to leverage differential queries to monitor state changes and generate alerts Extending Osquery with extensions Applied Network Defense | Osquery for Security Analysis
Chris Sanders | Intrusion Detection Honeypots: Detection through Deception
Intrusion Detection Honeypots is the foundational guide to building, deploying, and monitoring honeypots — security resources whose value lies in being probed and attacked. These fake systems, services, and tokens lure attackers in, enticing them to interact. Unbeknownst to the attacker, those interactions generate logs that alert you to their presence and educate you about their tradecraft. Intrusion Detection Honeypots teaches you how to: – Use the See-Think-Do framework to integrate honeypots into your network and lure attackers into your traps. syllabus Leverage honey services that mimic HTTP, SSH, and RDP. Hide honey tokens amongst legitimate documents, files, and folders. Entice attackers to use fake credentials that give them away. Create honey commands, honey tables, honey broadcasts, and other unique detection tools that leverage deception. Monitor honeypots for interaction and investigate the logs they generate. Chris Sanders | Intrusion Detection Honeypots: Detection through Deception
Kaspersky – Hunt APTs with Yara like a GReAT ninja
Have you ever wondered how Kaspersky’s GReAT experts discovered some of the world’s most famous APT attacks? Now, the answer is within your reach. Our specialists have poured years of experience from the prominent cases they have worked on into our online Threat Hunting with Yara training. Course leader Costin Raiu, a 25 year veteran of the threat hunting industry, will teach you the unconventional ways of working with Yara so that you can find threats of the same magnitude as his team. Specifically designed for self-paced learning, our course is deeply practical and enables you to learn-by-doing, hunting for real threats in our dedicated Virtual Lab. Using world-renowned cases like BlueTraveller, Sofacy & WildNeutron as the basis of the course, Costin shares insights and techniques from his team’s exclusive research on these cases. This knowledge will enhance your career and improve your organisation’s threat defences. Syllabus Inception String based rules Efficient rules Taking advantage of Yara modules Hunting for new samples on VTI Wildcards Digital Certificate, imphashes and developer footprints Malicious Office documents, OLE format Expert Yara exercises YarGen, automation and a bit of magic Hunt APTs with Yara like a GReAT ninja
FOR498: Digital Acquisition and Rapid Triage
FOR498 is a specialized course designed for digital forensics professionals and incident responders who need to quickly acquire and assess evidence during critical cyber incidents. The course focuses on rapid data acquisition, efficient forensic analysis, and initial triage processes to support timely decision-making and incident response.
Junior Penetration Tester (eJPTv2)
INE Security’s eJPT is for entry-level Penetration testers that validates that the individual has the knowledge, skills, and abilities required to fulfill a role as a junior penetration tester. This certification exam covers Assessment Methodologies, Host and Network Auditing, Host and Network Penetration Testing, and Web Application Penetration Testing. This exam is designed to be the first milestone certification for someone with little to no experience in cybersecurity, simulating the skills utilized during a real-world engagement. This exam truly shows that the candidate has what it takes to be part of a high-performing penetration testing team.





