TRN_MAP
without VAT
Goals
This one-day course covers practical use cases for development of cyber security capabilities in modern organizations with the help of MITRE ATT&CK framework. Trainees will learn to use MITRE ATT&CK in threat modeling, developing security analytics, planning red and purple team exercises and in many other areas. With the help of practical exercises, they will also learn to use multiple specialized tools for working with the framework.
The course is aimed at:
- Security managers
- Security architects
- Security analysts and other SOC specialists
- Cyber threat intelligence (CTI) specialists
- Detection engineers
- Red team members
- Anyone, who would like to start using MITRE ATT&CK framework in their organization
Duration
1 day (8h/day)
Requirements
- Knowledge of basic cyber security vocabulary
- Awareness of basic principles of cyber security management
- Awareness of common defensive and detection-oriented cyber security tools and solutions (e.g., FW, IPS/IDS, EDR, SIEM, …)
Contents
Introduction to MITRE ATT&CK
- History and development
- Components of ATT&CK and how they may be used
- Other relevant frameworks and models and their connection to ATT&CK (D3FEND, DeTT&CT, RE&CT, …)
Use of MITRE ATT&CK in security management and security architecture
- Threat modeling with the help of ATT&CK framework
- Mapping of existing security controls to different ATT&CK Matrices
- MITRE ATT&CK Navigator, its capabilities and use
Use of MITRE ATT&CK in defensive security
- MITRE ATT&CK as a basis for security monitroing and detection
- Analysis of current ATT&CK coverage by SOC capabilities and SIEM rules
- Detection engineering with ATT&CK - planning and development of detection analytics
- Systematic approach to threat hunting with MITRE ATT&CK
- Cyber threat intelligence (CTI) analysis with ATT&CK
- DeTT&CT Editor, its capabilities and use
Use of MITRE ATT&CK in offensive security
- Planning, development, execution and evaluation of security tests and threat emulation exercises with the use of MITRE ATT&CK
Specific approaches to use of MITRE ATT&CK in OT environments and with Mobile devices
MITRE Engage project tools and MITRE Cyber Resiliency Engineering Framework (CREF) Navigator, their capabilities and use
Literature
Trainees will receive an electronic version of the study materials.
Thank you for your interest.
We will do our best to answer and arrange a term.
Thank you for your interest.
We will answer your request or comment as soon as possible.
Thank you for your interest.
We will do our best to answer and arrange a term.
Training rooms
ALEF operates with training rooms match submarine's style to unexpected, unusual while still being smart and available to work in. We have several type of rooms for small groups and up to larger rooms with modern technical equipment and supportive technologies we provide.
We also deliver the high-quality multimedia sharing for efficient, effective virtual communication on a global scale. In the Competence Center is also available Spark Board. Cisco Sparkboard integrates the most common tools needed for team collaboration in physical meeting rooms into a single elegant device. It also combines white board, video or audio conference features.
All ALEF training centres operates with testing centre that provides full acess to take an exam and get certificate provided by our vendors. ALEF provides to our customer complete management and administration.
Team of lecturers
Our team - consisting of more than 50 instructors - offers a full range of technological knowledge in the field of routing, switching, security, collaboration and data centers. The expertise of instructors is evidenced by a range of top-level international certifications.
The uniqueness of our lecturers lies mainly in their extensive experience in connection with each project, allowing them to respond very flexibly to any question or suggestion from students, and to pass on their practical knowledge to the participants of these courses. Thanks to the synergy of the company’s reliable operation and many years of experience, we have been very flexible in responding to the changes prepared in the Cisco field, so we can guarantee you a wide range of certified courses that enable you and your colleagues to acquire the necessary know-how for future certification tests.
In addition to the certified trainings, we offer special courses that are focused primarily on the development of the necessary configuration skills.
OUR KNOWLEDGE IS YOUR FUTURE