Syllabus overview

April 8, 2022 · View on GitHub

Module 3Information sharing and modeling introduction
What is coveredIntroduction sessions describing the various information sharing and modelling techniques via MISP followed by a practical lab session
Requirements- MISP Introduction (from eLearning materials)
Responsible partnerCIRCL
Contents- Module 3.1 (e.101) Practical Information Sharing between Law Enforcement and CSIRT communities using MISP
-Module 3.2 (e.205) Mapping investigation and cases in MISP
-Module 3.3 (e.206) From evidences to actionable information
Module 3.1Practical Information Sharing between Law Enforcement and CSIRT communities using MISP
What is covered- Objectives
- Description of the 2-day session and setup
- MISP introduction (refresh from mandatory eLearning materials)
- Law-enforcement usage of MISP
- Benefit of using MISP
Requirements- MISP Introduction (from eLearning materials)
Total Duration105minutes
Responsible partnerCIRCL
Course referencee.101
Module 3.2Mapping investigation and cases in MISP
What is covered- Structure evidences
- Contextualise information
- Prepare information for sharing
Requirements- MISP Introduction (from eLearning materials)
Total Duration90minutes
Responsible partnerCIRCL
Course referencee.205
Module 3.3From evidences to actionable information
What is covered- How evidences (from logs, network captures to disk acquired) can be useful for defense?
- How to structure non-technical information?
Requirements- MISP Introduction (from eLearning materials)
Total Duration75minutes
Responsible partnerCIRCL
Course referencee.206
Module 4Labs I - Modeling, Interpreting and Sharing “Hacking Evidence”
What is coveredFinding Hacking evidence:
- Structure the logs and encode it in MISP
  - Include the original log file as an attachment
  - Share resource addresses to find the encoded data back in the original file
- Correlation with pre-encoded/exported event from AIL
  - Fake bitcoin address found in the student’s materials -> Trainers show the a full event they crafted containing as much feature as MISP can offer: Yara rules, timeline, contextualisation, …
Requirements- MISP Introduction (from eLearning materials)
- Module 3
Total Duration90+minutes
Responsible partnerCIRCL
Course referencee.302

Day 4

Module 5Supplementary tools for information sharing
What is coveredInformation enrichment, gathering as well as community management and information distribution handling
Requirements- MISP Introduction (from eLearning materials)
- Module 3
Responsible partnerCIRCL
Contents- Module 5.1 (e.102) Data mining Tor, social networks, OSINT with AIL Project
- Module 5.2 (e.103) Managing information sharing communities - cerebrate introduction
What is covered- Objectives
- Description of the 2-day session and se
-Module 3.2 (e.205) Mapping investigation and cases in MISP
Module 5.1Data mining Tor, social networks, OSINT with AIL Project
What is covered- Overview of the open source project AIL
- Demo and usage of AIL including Tor crawling
- Finding evidences from AIL and produce MISP event reports
- Law-enforcement usage of AIL
Requirements- MISP Introduction (from eLearning materials)
Total Duration105minutes
Responsible partnerCIRCL
Course referencee.102
Module 5.2Managing information sharing communities - Cerebrate introduction
What is covered- Directory and Budapest convention
- Managing sharing groups
- Searching for information
Requirements- MISP Introduction (from eLearning materials)
Total Duration60minutes
Responsible partnerCIRCL
Course referencee.103
Module 6CSIRTs network, notification and sharing scenarios
What is covered- An introduction into how the CSIRTs network handles notification and information sharing in general
- Challenges of collaboration between accredited CSIRTs and LEAs
Requirements
Total Duration30minutes
Responsible partnerCIRCL
Course referencee.104
Module 7Labs II: Encoding information and sharing it
What is coveredExtract an Executable from PCAP & Investigating a compromised Linux Host:
- PCAP is coming from a Linux machine
Analysing PCAP
- extracting evidences
- Pre-encode the event (manual and JSON import in UI)
- Encode the executable and describe what it does
- Connected graph, hashlookup example
- From correlations between the provided events and the ones encoded by the students, find more information and correlation about their events
Requirements- MISP Introduction (from eLearning materials)
Total Duration75minutes
Responsible partnerCIRCL
Course referencee.303
Module 8Labs III - Encoding information and sharing - HTTP and DNS Data to Isolate Threat Actor
What is coveredHTTP and DNS Data to Isolate Threat Actor:
- Target: PCAP about Log4J exfiltration over DNS
- Describe and encode the exfiltration process, data and target in MISP
- Manual and automatic import with PyMISP
- Play with distribution and correctly set it for each data point
- [Advanced exercise] Second stage malware exfiltrating TXT record custom base64 encoded where information is contained in the padding
Requirements- MISP Introduction (from eLearning materials)
Total Duration90+minutes
Responsible partnerCIRCL
Course referencee.304