1
1

00:00:00,090  -->  00:00:01,090
<v ->In this section of the course,</v>
2

2

00:00:01,090  -->  00:00:02,970
we're going to discuss how you can detect
3

3

00:00:02,970  -->  00:00:05,790
and analyze network indicators or compromise.
4

4

00:00:05,790  -->  00:00:06,960
We're going to continue to focus
5

5

00:00:06,960  -->  00:00:09,210
on Domain One, Security Operations
6

6

00:00:09,210  -->  00:00:10,620
in this section of the course,
7

7

00:00:10,620  -->  00:00:13,830
and specifically we'll be looking at Objective 1.2.
8

8

00:00:13,830  -->  00:00:16,650
Objective 1.2 states that given a scenario,
9

9

00:00:16,650  -->  00:00:18,450
you must be able to analyze indicators
10

10

00:00:18,450  -->  00:00:20,670
of potentially malicious activity.
11

11

00:00:20,670  -->  00:00:22,000
Now, in this section of the course,
12

12

00:00:22,000  -->  00:00:25,350
we're going to focus only on network-based IOCs,
13

13

00:00:25,350  -->  00:00:28,140
but we are going to be moving into host-based IOCs
14

14

00:00:28,140  -->  00:00:30,960
and application-based IOCs, as well as lateral movement
15

15

00:00:30,960  -->  00:00:34,530
and pivoting IOCs in the next few sections of this course.
16

16

00:00:34,530  -->  00:00:36,467
But as we move through this section of the course,
17

17

00:00:36,467  -->  00:00:39,030
we are going to start by looking at what exactly is
18

18

00:00:39,030  -->  00:00:42,210
a network-based IOC and how they're going to be used.
19

19

00:00:42,210  -->  00:00:43,320
Then we're going to move
20

20

00:00:43,320  -->  00:00:46,650
into some common IOC types and identify those as well.
21

21

00:00:46,650  -->  00:00:49,560
This includes things like traffic spikes, beaconing,
22

22

00:00:49,560  -->  00:00:52,020
irregular peer-to-peer communication channels,
23

23

00:00:52,020  -->  00:00:54,327
rogue devices, scans and sweeps,
24

24

00:00:54,327  -->  00:00:56,490
and non-standard port usage.
25

25

00:00:56,490  -->  00:00:58,110
Next, we're going to spend a little bit
26

26

00:00:58,110  -->  00:01:01,410
of time discussing some common TCP and UDP ports
27

27

00:01:01,410  -->  00:01:04,560
because, after all, if you don't know what a normal port is,
28

28

00:01:04,560  -->  00:01:06,630
it's going to be really hard to understand what might be
29

29

00:01:06,630  -->  00:01:10,020
considered to be a non-standard port usage, right?
30

30

00:01:10,020  -->  00:01:11,310
Well, then we're going to move
31

31

00:01:11,310  -->  00:01:13,860
into looking at the data exfiltration techniques
32

32

00:01:13,860  -->  00:01:16,410
and covert channels that could be used by attackers
33

33

00:01:16,410  -->  00:01:18,420
and we'll figure out how we can identify indicators
34

34

00:01:18,420  -->  00:01:21,120
or compromise based around these techniques.
35

35

00:01:21,120  -->  00:01:23,370
After that, I'm going to be performing a demonstration
36

36

00:01:23,370  -->  00:01:25,530
where we're going to analyze some network-based IOCs
37

37

00:01:25,530  -->  00:01:27,180
inside of my lab environment,
38

38

00:01:27,180  -->  00:01:29,730
so you can better understand what various attacks look like
39

39

00:01:29,730  -->  00:01:32,340
when you're working as a cybersecurity analyst.
40

40

00:01:32,340  -->  00:01:34,380
Finally, we're going to take a short quiz to see
41

41

00:01:34,380  -->  00:01:36,240
what you learned during this section of the course
42

42

00:01:36,240  -->  00:01:38,550
and review each of those quiz questions fully to ensure
43

43

00:01:38,550  -->  00:01:41,220
you can explain why the right answers were correct.
44

44

00:01:41,220  -->  00:01:43,470
So let's start analyzing networks to see
45

45

00:01:43,470  -->  00:01:44,670
if we can find any indicators
46

46

00:01:44,670  -->  00:01:46,870
or compromise in this section of the course.
