Introduction to Threat Intelligence and Attribution

Overview

Overview

Duration 2 days
Course Time 9.00am - 1.30pm
Enquiry Click here to contact us
This course is delivered by Mandiant Academy.

This course is a fast-paced introduction to threat intelligence and attribution. It is designed to provide insight into attribution methodology and demonstrate the proper handling of threat intelligence information.

The course explores the main components of a threat group and shows how FireEye analysts use raw tactical intelligence and weigh connections and relationships to build a set of related activities that corresponds to a group of threat actors. Participants will become familiar with several factors they should consider when attributing related activity, and view real-world examples of research and pivoting. The course also examines operational and strategic intelligence, which helps determine the “who” and the “why” behind an attack.

The course also clarifies critical security terminology so learners can separate valuable information from hype.



Key Takeaways

Key Takeaways

At the end of this course, the participiants will be able to:

  • Understand various definitions of threat intelligence and attribution
  • Distinguish between tactical, operational and strategic threat intelligence
  • Use tactical intelligence in the early stages of a cyber attack to evaluate data and correctly identify indicators that can be grouped into a set of related activity and attributed to a threat group
  • Gain insight into common errors that can occur when analysing common forensic artifacts and interpreting information presented from various sources
  • Examine operational and strategic intelligence to determine the attribution and sponsorship of an attack operation
  • Understand how attribution analysis can provide crucial context to threat activity that enables more informed decisions and improved resource allocation
  • Understand why attributing cyber operations to a threat group can have significant implications — and even affect geopolitical dynamics
  • Consider attribution from a threat group’s point of view


Who Should Attend

Who Should Attend

This course is targeted at Cyber intelligence analysts, cyber threat analysts, security analysts and penetration testers.

Prerequisites
A working understanding of basic information security principles. A general understanding of threat intelligence and indicators of compromise (IoCs). Experience conducting forensic analysis, network traffic analysis, log analysis, security assessments and penetration testing, security architecture and system administration duties are a plus, but not required.



ICT and SS Competency Framework

ICT and SS Competency Framework

As part of the ICTCF, this course falls under the Cybersecurity functional cluster and tagged to the following competencies:
  • Cybersecurity: Cyber Threat Intelligence

The course is mapped to the following job roles:
  • CISOs
  • Cybersecurity Engineers


Course Structure

Course Structure

This course is delivered via virtual instructor-led format and will cover the following topics:

  • Threat Intelligence and Attribution
  • Tactical Intelligence and Attribution
  • Tactical Intelligence Attribution Challenges
  • Operational Intelligence and Attribution
  • Strategic Intelligence and Attribution
  • Using Open-Source Threat Intelligence


Instructors

Instructors


Fees

Fees


Full Fee

Full course fee

S$1140

7% GST on nett course fee

S$79.80

Total nett course fee payable, including GST S$1219.80




How To Register

How To Register


Agency-sponsored

Step 1 Apply through your organisation's training request system.

Step 2 Your organisation's training request system (or relevant HR staff) confirms your organisation's approval for you to take the course.

Your organisation will send registration information to the academy.

Organisation HR L&D or equivalent staff can click here for details of the registration submission process.


Step 3 The Digital Academy will inform you whether you have been successful in enrolment.