Certified Cyber Threat Intelligence Analyst


Certified Cyber Threat Intelligence Analyst, Singapore elarning online course

Course Description

The Cyber Security Threat Intelligence Researcher Certification will help you acquire the skills needed to find out who is behind an attack, what the specific threat group is, the nation from which the attack is being launched, as well as techniques being used to launch this attack.

You will know how to take a small piece of malware, find out who is responsible for launching it, the threat actor location and also how to take down that threat actor, with the support of your local law enforcement.

In today’s cyber security landscape, it isn't possible to prevent every attacks. Today’s attackers have significant funding, are patient, sophisticated, and target vulnerabilities in people and processes as well as technologies. With organizations increasingly relying on digitized information and sharing vast amounts of data across the globe, they have become easier targets for many different forms of attack. As a result, every company’s day-to-day operations, data and intellectual property are seriously at risk. In a corporate context, a cyber attack can not only damage your brand and reputation, it can also result in loss of competitive advantage, create legal/regulatory noncompliance and cause steep financial damage.

Today’s secure environment will have vulnerabilities in it tomorrow, so an organization cannot allow itself to become complacent. There is only so much an organization can do by defending itself against threats that have already occurred. If an organization only reacts to new threats as they come up, are likely acting too late. It is important to understand and prioritize cyber threat intelligence processes, and how they can be integrated into an organization’s security operations in a way that adds value.

Cyber threat intelligence (CTI) is an advanced process enabling organizations to gather valuable insights based on analysis of contextual and situational risks. These processes can be tailored to the organization’s specific threat landscape, industry and market. This intelligence can make a significant difference to organizations' abilities to anticipate breaches before they occur. Giving organizations the ability to respond quickly, decisively and effectively to confirmed breaches allows them to proactively maneuver defense mechanisms into place, prior to and during the attack.

In this course, we’ll introduce you to the 8 phases of threat intelligence:

Hunting - The goal of hunting is to establish techniques to collect samples from different sources that help to start profiling malicious threat actors.

Features Extraction - The goal of Features Extraction is to identify unique Static features in the binaries that help to classify them into a specific malicious group.

Behavior Extraction - The goal of Behavior Extraction is to identify unique Dynamic features in the binaries that help to classify them into a specific malicious group.

Clustering and Correlation - The goal of Clustering and Correlation is to classify malware based on Features and Behavior extracted and correlate the information to understand the attack flow.

Threat Actor Attribution - The goal of Threat Actors is to locate the threat actors behind the malicious clusters identified.

Tracking - The goal of tracking is to anticipate new attacks and identify new variants proactively.

Taking Down - The goal of Taking down is to Dismantled Organized Crime Operations


Course Objectives

1. Phases Overview
2. Hunting
3. Features Extraction
4. Behaviour Extraction
5. Clustering & Correlation
6. Attribution
7. Tracking
8. Taking Down


Related Courses

  • Google Cloud Platform Data Storage Overview & Networking Fundamentals

    Google Cloud Platform Data Storage Overview & Networking Fundamentals

    SGD $20.00

    Course Description

    Google Cloud Platform which has you enterprise covered. GCP offers object storage for different needs and price points as well as managed MySQL and globally-scalable NoSQL databases. Our archival storage provides industry-leading pricing with the performance of disc. Different applications and workloads require different storage and database solutions. GCP offers a full suite of industry-leading storage services that are price performant and meet your needs for structured, unstructured, transactional, and relational data. This course will help you identify the solutions that fit your scenarios, whether they are mobile applications, hosting commercial software, data pipelines, or storing backups.   Google Cloud Platform enables developers to build, test and deploy applications on Google’s highly-scalable, secure, and reliable infrastructure. This course covers specifically Google Cloud Platform Networking services. This course will cover the features and functions of Google Cloud Platform Networking Services so that you will understand the GCP options available.. We will dive into GCP Networking fundamentals such as Software Defined Networking, Load Balancing, Autoscaling and Virtual Private Clouds. As an added bonus we also will dive into Identity and Access Management as well from a networking security perspective. After taking this class you should be able to understand what GCP Cloud services should enable your organization around networking services. Whether you’re a developer or architect this course will help understand the basic capabilities and some of the useful advanced features of GCP networking services and features.

    Read more...

  • Intro to Blockchain Technology, Blockchain Security  and R3 Corda

    Intro to Blockchain Technology, Blockchain Security and R3 Corda

    SGD $29.00

    Course Description

    This course will help you identify and differentiate between security threats and attacks on a Blockchain network. Blockchain security methods, best practices, risk mitigation, and all known (to date) cyber-attack vectors on the Blockchain will be covered. You will also learn how to perform a Blockchain network security risk analysis and glean a complete understanding of Blockchain's inherent security features and risks. You will learn the key aspects around Blockchain and Bitcoin, including: What is a blockchain? What is Bitcoin? What are smart contracts? What is a cryptocurrency? What are digital tokens? How blockchain and Bitcoin are related and why it is so important to know the relationship. Some common misconceptions about blockchain and Bitcoin. R3 Corda Blockchain is an enterprise blockchain distributed ledger. A blockchain is a tamper-evident, shared digital ledger that records transactions in a public or private peer-to-peer network. Distributed to all member nodes in the network, the ledger permanently records, in a sequential chain of cryptographic hash-linked blocks, the history of asset exchanges that take place between the peers in the network. This course has been designed for technical architects, pre sales architects, developers and project managers who must make technical decisions about distributed architectures and development platform  

    Read more...

  • A+ Certification Prep

    A+ Certification Prep

    SGD $299.00

    Course Description

    The A+ Certification Prep Course readies students for CompTIA's A+ certification which validates an understanding of the most common hardware and software technologies in business as well as the skills necessary to support complex IT infrastructures. With top experts and an interactive, lab-filled enviornment students gain essential competencies with the equivalent understanding of at least one year of hands-on experience in the field/lab. The A+ Certification by CompTIA is a powerful credential helping IT professionals, worldwide, ignite their careers by proving knowledge needed to assemble elements based on install, customer requirements, configuration and maintenance of software as well as PCs and devices for end users. Students will also gain an understanding of the basics of security, forensics and networking and finally learn to safely and properly diagnose, document and resolve common software and hardware issues while applying troubleshooting expertise. This course prepares students for the CompTIA A+ Certification exams 220-802 and 220-801.

    Read more...


Content

Phases Overview

+

Threat Intelligence Researcher Course Intro

Phases Overview Part 1

Hunting Part 1

Hunting Part 2

Threat Actor Attribution Part 2

Tracking

Taking Down

Phases Overview Part 2

Phases Overview Part 3

Features Extraction Part 1

Features Extraction Part 2

Behavior Extraction Part 1

Behavior Extraction Part 2

Behavior Extraction Part 3

Clustering and Correlation

Threat Actor Attribution Part 1

Hunting

+

VirusTotal Part 1

VirusTotal Part 2

Hacking Forums Part 1

Hacking Forums Part 2

Hacking Forums Part 3

DeepWeb Part 1

DeepWeb Part 2

Honeypot and OSINT

Features Extraction

+

Features Extraction Goal Part 1

Features Extraction Goal Part 2

Import Table Hash (imphash) Part 1

Import Table Hash (imphash) Part 2

Fuzzy Hash (ssdeep)

Behavior Extraction

+

Dynamic Indicators Part 1

Dynamic Indicators Part 2

Dynamic Indicators Part 3

Dynamic Indicators Part 4

Process Infector and Keyloggers

Passive DNS (DNSDB) Part 1

Passive DNS (DNSDB) Part 2

Clustering & Correlation

+

How Clustering & Correlation Works Part 1

How Clustering & Correlation Works Part 2

How Clustering & Correlation Works Part 3

How Clustering & Correlation Works Part 4

GraphDB Part 1

GraphDB Part 2

Initial Compromise

Privilege Escalation

Persistence

Lateral Movement Part 1

Lateral Movement Part 2

Exfiltration Strategy

Profiling the Attacker

Attribution

+

Where are they Located? Part 1

Where are they Located? Part 2

Who are the Targets?

Initial Compromise

Tracking

+

Passive DNS & Internet Port Scan Part 1

Passive DNS & Internet Port Scan Part 2

Passive DNS & Internet Port Scan Part 3

Passive DNS & Internet Port Scan Part 4

Lookups, OSINT, and Hacking Forums Part 1

Lookups, OSINT, and Hacking Forums Part 2

Taking Down

+

Sinkhole Part 1

Sinkhole Part 2

How it works? Part 1

How it works? Part 2

Hacking Forums

Victims Notification

SGD $299.00
(Price excludes GST)
GET ACCESS NOW
Convince your boss email
This site is best viewed using the latest versions of Google Chrome, Apple Safari, Mozilla FireFox, Microsoft Internet Explorer 11 and Edge which supports HTML5/Webkit technologies.