Study at Your Own Pace
IHRP is entirely self-paced, with interactive slides students can access online without restriction. Students have lifetime access to the training materials and can take the course from home, from the office or anywhere with an internet connection.
Highly Practical
Thanks to extensive use of Hera Lab and coverage of the latest research in incident handling and response, the IHRP course is not only the most practical training course on the subject but also the most current. Apply incident response techniques against real-world networks and assets.
The Course at a Glance
- Starting from basic incidents through to advanced incident response activities
- Professionally analyse, manage and respond to security incidents across heterogeneous networks and assets
- Understand the mechanics of modern cyber attacks and how to detect them
- Use and tune open source IDS solutions (Bro, Snort, Suricata) effectively
- Make the most of open source SIEM solutions (ELK, Splunk and others)
- Regularly use regex and log management solutions to detect attacks
- Detect and even proactively hunt attacks by analysing traffic, flows and endpoints, and by using analytical and tactical threat intelligence
- Gives you access to private forums
- Makes you a professional incident responder
Course Material
- 10 comprehensive Hera labs
- 13 modules
- 4 sections
Course Delivery
- Self-paced, HTML5, PDF, MP4
- Offline access available
- Access from PC, tablet and smartphone
Curriculum
- Section: Incident Management Overview
Module 1: The Incident Management Process
The Incident Management Process module introduces you to the Preparation → Detection and Analysis → Containment, Eradication and Recovery → Post-Incident Activity cycle (the incident response lifecycle). It also addresses incident management procedures, activities and best practices for maximising effectiveness and performance and for reducing key security metrics such as time to detect, time to respond and risk points per host.
Section: Network Traffic and Flow Analysis
Module 1: Intrusion Detection Through Traffic Analysis (Part 1)
In this module you will first learn to detect attacks at the IEEE 802.x link and IP layers. Both IPv4 and IPv6 are in scope.
Module 2: Intrusion Detection Through Traffic Analysis (Part 2)
This module begins by covering how to analyse common application protocols for suspicious behaviour or anomalies. You will then learn how to make effective use of open source IDS solutions and how to tune them in order to detect real-world attacks. Snort, Bro and Suricata are addressed.
Module 3: Intrusion Detection Through Flow Analysis
In this module you will learn attack detection through flow analysis. Volumetric discovery, anomalous DNS discovery, SMB anomalies and flow visualisation are used to detect exfiltration, lateral movement, malware beacons and more.
Section: Practical Incident Management
Module 1: Preparing For and Defending Against Reconnaissance and Information Gathering
In this module you will learn all the techniques attackers use to carry out reconnaissance and information gathering, and how to prepare for and defend against them. The techniques to be detected range from Google/Shodan “hacking” through exposed OWA, JavaScript injection and SSL certificates, to DNS querying and enumeration.
Module 2: Preparing For and Defending Against Scanning
In this module you will learn all the techniques attackers use to carry out scanning activity, and how to prepare for and defend against them. The techniques covered range from war dialling and war driving to nmap/Nessus scans and WebRTC-based scanning.
Module 3: Preparing For and Defending Against Exploitation
In this module you will learn all the techniques, tactics and procedures by which attackers gain an initial foothold on a network, and how to prepare for and defend against them. The attacks covered range from passive and active sniffing, DNS cache poisoning and remote/web attacks through to abusing and brute-forcing Microsoft authentication.
Module 4: Preparing For and Defending Against Post-Exploitation
In this module you will learn all the techniques, tactics and procedures attackers use after gaining an initial foothold in order to escalate privileges and move laterally and vertically. Detection techniques such as privileged access monitoring and privilege escalation detection, anomalous system interaction monitoring, log manipulation detection, covert channel detection and persistence detection are addressed, alongside detection of RATs, attempts to identify likely attack paths, and credential reuse. Note that the full spectrum of Kerberos attacks (pass-the-hash, Kerberoasting and others) is also covered.
Section: SOC 3.0 Operations and Analytics
Module 1: SIEM Fundamentals and Open Source Solutions
In this module you will become comfortable working with some of the most effective open source SIEM solutions, such as customised ELK and Splunk.
Module 2: Logging
This module covers actionable logging, including formats, manipulation and custom parsing.
Module 3: SMTP, DNS and HTTP(S) Analytics
In this module you will see how common protocol analytics can dramatically increase your network visibility in order to detect anomalous and potentially malicious actions. More specifically, you will see how to extract actionable intrusion-related information by performing SMTP, DNS, HTTP and HTTPS analytics.
Module 4: Endpoint Analytics
In this module you will learn about the most important logs and events, correlation strategies and SIEM queries you can use to detect adversaries on your endpoints at scale. You will also see how tactical threat intelligence and adversary simulation software can help you raise your endpoint adversary detection capability. Effective use of Osquery for querying endpoints at scale is also covered.
Module 5: Baselining and Detecting Deviations
In this module you will see how baselining your environment can lead to easier, more efficient and more effective attack detection.
Prerequisites
- Basic knowledge of networking
- Basic knowledge of protocols
- Basic knowledge of operating systems
- Basic knowledge of security devices
Who Can Attend
- SOC analysts
- CSIRT members
- Incident handlers
- Incident responders
- Red team members who want to understand blue team tactics and carry out stealthier penetration tests
- IT security staff responsible for defending their organisation’s assets
Laboratories
The IHRP course is a practice-based curriculum. Integrated with Hera Lab, the most advanced virtual lab in IT security, this product offers an unmatched practical learning experience. Hera is the only virtual lab that provides each student with fully isolated access to every real-world network scenario on the platform. Students can access Hera Lab from anywhere over VPN.
The modules are accompanied by numerous hands-on labs in which you will be tasked with detecting:
- Real-world attacks and malware
- Attacks or attempted attacks at every stage of the cyber kill chain
LAB-1
Traffic Analysis Challenges (offline) — During this lab you will refresh your networking knowledge, learn to recognise TCP spoofing and internal botnet-like activity, and work to identify attacks by analysing network traffic, including IPv6-based traffic.
LAB-2
Enterprise-Wide Incident Response — Part 1: GRR — In this lab you will learn how to use the GRR incident response framework to carry out faster and more efficient IR activity. During the lab you will have the opportunity to detect malware, various stealthy persistence techniques and (unsuccessful) privilege escalation attempts on a heterogeneous, enterprise-like network.
LAB-3
Enterprise-Wide Incident Response — Part 2: Velociraptor — In this lab you will learn how to use the Velociraptor incident response framework to carry out faster and more efficient IR activity. During the lab you will be able to detect fileless malware and make use of specific Velociraptor features to proactively monitor endpoints on a heterogeneous, enterprise-like network.
LAB-4
Suricata Fundamentals — In this lab you will learn about Suricata’s capabilities, features and configuration. In addition, you will become familiar with configuring Suricata to your detection needs and learn everything about Suricata inputs and outputs. Finally, you will be shown how to parse Suricata output effectively and extract critical information.
LAB-5
Using Suricata Effectively — In this lab you will learn how to use Suricata effectively. In particular, you will first become familiar with Suricata rules and then learn how to develop your own signatures after analysing PCAP files containing malicious traffic. Suricata rules will be written to detect malicious traffic originating from ransomware, phishing attempts, trojans and malicious documents.
LAB-6
Using Bro Effectively — In this lab you will learn about Bro’s capabilities, features and architecture. In addition, you will gain knowledge of effective Bro scripting so that you can tailor Bro to your detection requirements. Finally, effective manipulation and analysis of Bro logs to extract critical information will be demonstrated.
LAB-7
Using Snort Effectively — In this lab you will learn about Snort’s capabilities, features and architecture. In addition, you will become comfortable with effective Snort rule scripting so that you can tailor Snort to your detection requirements.
LAB-8
Using Splunk Effectively (2 scenarios) — In this lab you will learn Splunk’s detection capabilities, features and architecture. The lab consists of two separate attack detection scenarios. The first will make you comfortable with writing effective Splunk searches. The second will help you understand how tactical threat intelligence can be turned into actionable Splunk searches that surface malicious activity on your network.
LAB-9
Using ELK Effectively — In this lab you will learn about ELK’s capabilities, features and architecture. You will also gain knowledge of effective ELK query writing so that you can tailor ELK to your detection and analysis requirements.