1
1

00:00:00,090  -->  00:00:01,410
<v ->In this section of the course,</v>
2

2

00:00:01,410  -->  00:00:03,630
we're going to discuss how we can detect and analyze
3

3

00:00:03,630  -->  00:00:07,920
application-related indicators of compromise, known as IOCs.
4

4

00:00:07,920  -->  00:00:10,050
We're going to continue to focus on domain one,
5

5

00:00:10,050  -->  00:00:12,480
security operations, in this section of the course,
6

6

00:00:12,480  -->  00:00:15,000
and specifically objective 1.2.
7

7

00:00:15,000  -->  00:00:17,730
Objective 1.2 states that given a scenario,
8

8

00:00:17,730  -->  00:00:19,800
you must be able to analyze indicators
9

9

00:00:19,800  -->  00:00:21,810
of potentially malicious activity.
10

10

00:00:21,810  -->  00:00:24,510
So in this section, we're going to focus solely
11

11

00:00:24,510  -->  00:00:27,240
on the application-related indicators of compromise
12

12

00:00:27,240  -->  00:00:29,430
that are listed underneath this objective.
13

13

00:00:29,430  -->  00:00:31,350
As we begin to move throughout this section,
14

14

00:00:31,350  -->  00:00:32,183
we're going to start out
15

15

00:00:32,183  -->  00:00:35,340
by looking at exactly what an application-related IOC is
16

16

00:00:35,340  -->  00:00:37,217
and how they're used to detect malicious activity
17

17

00:00:37,217  -->  00:00:39,960
within our workstations and our servers.
18

18

00:00:39,960  -->  00:00:42,810
Then, we're going to move into some common IOC types
19

19

00:00:42,810  -->  00:00:44,400
and how to identify them.
20

20

00:00:44,400  -->  00:00:46,800
This includes identifying anomalous activity,
21

21

00:00:46,800  -->  00:00:49,800
service interruptions, analyzing application logs,
22

22

00:00:49,800  -->  00:00:52,260
and how to detect new accounts that have been created
23

23

00:00:52,260  -->  00:00:53,640
on your systems.
24

24

00:00:53,640  -->  00:00:56,580
Next, we're going to cover forensics for virtualized systems,
25

25

00:00:56,580  -->  00:00:58,440
applications, and mobile devices
26

26

00:00:58,440  -->  00:01:00,180
during this section of the course as well,
27

27

00:01:00,180  -->  00:01:03,360
because these are more focused on application-related IOCs
28

28

00:01:03,360  -->  00:01:05,940
in your forensic efforts on these types of systems,
29

29

00:01:05,940  -->  00:01:08,130
then looking at them from a purely network
30

30

00:01:08,130  -->  00:01:09,660
or host-based perspective.
31

31

00:01:09,660  -->  00:01:11,460
And finally, we're going to take a short quiz
32

32

00:01:11,460  -->  00:01:13,620
to see what you learned during this section of the course
33

33

00:01:13,620  -->  00:01:15,750
and review each of those quiz questions fully,
34

34

00:01:15,750  -->  00:01:18,390
to ensure you can explain why the right answers were right.
35

35

00:01:18,390  -->  00:01:20,910
So, let's start analyzing our applications
36

36

00:01:20,910  -->  00:01:22,830
to see if we can find indicators of compromise
37

37

00:01:22,830  -->  00:01:24,330
in this section of the course.
