Catalog
details

Ajoutez votre titre ici

Ajoutez votre titre ici

SECT503: NETWORK MONITORING AND THREAT DETECTION IN-DEPTH

Category

INFORMATION TECHNOLOGY

Subcategory

Information system

Code

SIF023

Training Objectives

Configure and operate Snort, Suricata, and FirePOWER for network traffic analysis and intrusion detection. Create and write efficient Snort, Suricata, and FirePOWER rules for threats detection. Configure and run open-source Zeek to provide a hybrid traffic analysis framework. Development automated threats matching scripts in Zeek. Understand TCP/IP layers to identify normal and abnormal traffic for threats detection. Utilize traffic analysis tools to identify signs of compromise or active threats. Perform network forensics to investigate traffic, identify TTPs (Tactics, Techniques, and Procedures), and detect active threats. Extract files and other types of content from network traffic to reconstruct events. Create BPF (Berkeley Packet Filter) filters to selectively examine specific traffic traits at scale. Use Scapy to craft custom packages for network testing and analysis. NetFlow/IPFIX tools to detect network behavior anomalies and potential threats. Applying knowledge of network architecture and hardware to customize the placement of network monitoring sensors and sniff traffic off the wire.

Training Program

Target Audience

Engineers • System administrators • Technical security managers • CND analytics • Security monitoring specialists • Cyber threats investigators

Duration (Days)

6

Minimum Number of Seats

5

Maximum Number of Seats

5

Trainer

SANS

Contact us