Incident Response with Sentinel One (2 days)TRAINING OBJECTIVE: To effectively perform their work, individuals responsible for cybersecurity management within an organization need to understand how cybercriminals operate and have the skills to utilize existing tools and security measures to analyze events and implement appropriate incident responses. This training aims to provide practical training for SentinelOne security managers in analyzing actual cyberattacks, assessing the situation, and responding to incidents.https://clico.pl/trainings/templates/copy_of_incident-response-w-zabezpieczeniach-sentinelonehttps://clico.pl/logo.png
Incident Response with Sentinel One (2 days)
TRAINING OBJECTIVE: To effectively perform their work, individuals responsible for cybersecurity management within an organization need to understand how cybercriminals operate and have the skills to utilize existing tools and security measures to analyze events and implement appropriate incident responses. This training aims to provide practical training for SentinelOne security managers in analyzing actual cyberattacks, assessing the situation, and responding to incidents.
Incident Response with Sentinel One (2 days)
CLICO
2
950,0
USD
yes
no
PRACTICAL EXERCISES:
The training is based on exercises that take place on a training network equipped with SentinelOne firewall and EDR security, as well as on individual trainee stations equipped with appropriate tools (MS Windows and Kali Linux stations), as well as various types of Web/SMB servers, email servers, and an Active Directory environment to test real-world cyberattacks.
Participants will practice techniques used in real-world cyberattacks according to MITRE ATT&CK (e.g. OS Credential Dumping: LSASS Memory/Security Account Manager, Web Shell, Exploitation for Privilege Escalation, Lateral Tool Transfer, Pass the Hash, Exploitation of Remote Services - Eternal, Zerologon, Print Nightmare).
10:00 - 17:00
THEORY AND INTRODUCTION TO RED TEAMING, ADVERSARY EMULATION
How does an actual cyber attack work?
MITRE ATT&CK in real-world cyber attack scenarios
Introduction to Cyber Range Lab and Cyber Soldier Offensive Tools
PRACTICAL EXERCISES
System Discovery, Reconnaissance, and Sensitive Data Collection
Basic Offensive Skills Exercise in Cyber Range – Part 1
Scenario - Active Directory Reconnaissance
Scenario - Network Reconnaissance
Scenario - Deploying a Web Shell to an Editable SMB Share on a Web Server, Executing Commands on aWindows System
Analysis of Cyber Attack Traces Using Live Forensics Tools in Endpoint Detection and Response (EDR)
9:00 - 17:00
Password Attacks, Credential Gathering, and Lateral Movement
Basic Offensive Skills Exercise in Cyber Range – Part 2
Analysis of Cyber Attack Traces Using Live Forensics Tools Available in Endpoint Detection and Response (EDR)
Scenario - Cracking Service Account Passwords in Windows Domain (Kerberoasting)
Scenario - Password Spraying Attack on Local Admin Accounts
Scenario - Windows Credential Dumping using Service Account and Webshell
Analysis of Cyber Attack Traces Using Live Forensics Tools in Endpoint Detection and Response (EDR)
Exploitation and Credential Theft, Privilege Escalation
Exploiting SMB Vulnerabilities on Older Windows Servers – MS17-010 Eternal
Analysis of Cyber Attack Traces Using Live Forensics Tools Available in Endpoint Detection and Response (EDR)
Scenario - Credential Dumping from SAM Using Admin Password or NTLM Hash
Scenario - Credential Dumping from LSASS Using Admin Password or NTLM Hash
Scenario - Lateral Movement to Windows System as Administrator
Analysis of Cyber Attack Traces Using Live Forensics Tools in Endpoint Detection and Response (EDR)