1
1

00:00:00,090  -->  00:00:01,470
<v ->In this section of the course,</v>
2

2

00:00:01,470  -->  00:00:03,000
we're going to discuss how you can detect
3

3

00:00:03,000  -->  00:00:06,330
and analyze host-related indicators of compromise.
4

4

00:00:06,330  -->  00:00:08,370
We're going to continue to focus on domain one,
5

5

00:00:08,370  -->  00:00:10,830
security operations in this section of the course
6

6

00:00:10,830  -->  00:00:13,410
and specifically, on objective 1.2.
7

7

00:00:13,410  -->  00:00:16,200
Objective 1.2 states that given a scenario,
8

8

00:00:16,200  -->  00:00:17,970
you must be able to analyze indicators
9

9

00:00:17,970  -->  00:00:20,010
of potentially malicious activity.
10

10

00:00:20,010  -->  00:00:22,710
So in this section of the course, we're going to be focused
11

11

00:00:22,710  -->  00:00:26,430
on host-related IOCs or indicators of compromise.
12

12

00:00:26,430  -->  00:00:28,620
As we move through this section, we're going to be looking
13

13

00:00:28,620  -->  00:00:31,650
at exactly what a host-related indicator of compromise is
14

14

00:00:31,650  -->  00:00:33,900
and how they can be used to detect malicious activity
15

15

00:00:33,900  -->  00:00:36,120
within our workstations and servers.
16

16

00:00:36,120  -->  00:00:37,650
After that, we're going to be moving
17

17

00:00:37,650  -->  00:00:40,950
into some common IOC types and how do identify them.
18

18

00:00:40,950  -->  00:00:43,170
This includes things like malicious processes,
19

19

00:00:43,170  -->  00:00:44,730
conducting memory forensics,
20

20

00:00:44,730  -->  00:00:46,560
analyzing processor consumption,
21

21

00:00:46,560  -->  00:00:49,050
analyzing disk or file system consumption,
22

22

00:00:49,050  -->  00:00:51,450
identifying unauthorized privileges in use,
23

23

00:00:51,450  -->  00:00:53,310
scanning for unauthorized software,
24

24

00:00:53,310  -->  00:00:56,010
detecting unauthorized changes or hardware additions,
25

25

00:00:56,010  -->  00:00:58,620
and a concept of maintaining persistence.
26

26

00:00:58,620  -->  00:01:00,570
Finally, we're going to take a short quiz
27

27

00:01:00,570  -->  00:01:02,580
to see what you learned during this section of the course
28

28

00:01:02,580  -->  00:01:04,260
and review each of those quiz questions
29

29

00:01:04,260  -->  00:01:06,960
to ensure you understand why the right answers were right.
30

30

00:01:06,960  -->  00:01:10,140
So let's start analyzing our workstations and servers to see
31

31

00:01:10,140  -->  00:01:12,510
if we can identify some host-related IOCs
32

32

00:01:12,510  -->  00:01:14,490
in this section of the course.
