1
1

00:00:00,090  -->  00:00:01,440
<v ->In this section of the course,</v>
2

2

00:00:01,440  -->  00:00:04,410
we're going to discuss the classification of threats.
3

3

00:00:04,410  -->  00:00:05,850
Our focus in this section
4

4

00:00:05,850  -->  00:00:08,040
is going to be split across several domains,
5

5

00:00:08,040  -->  00:00:10,530
including Domain 1, Security Operations,
6

6

00:00:10,530  -->  00:00:12,480
Domain 2, Vulnerability Management,
7

7

00:00:12,480  -->  00:00:14,880
and Domain 3, Incident Response Management,
8

8

00:00:14,880  -->  00:00:17,490
with coverage across three different objectives.
9

9

00:00:17,490  -->  00:00:19,170
Objective 1.4 states
10

10

00:00:19,170  -->  00:00:21,000
that you must be able to compare and contrast
11

11

00:00:21,000  -->  00:00:23,700
threat-intelligence and threat-hunting concepts.
12

12

00:00:23,700  -->  00:00:26,550
Objective 2.3 states that given a scenario,
13

13

00:00:26,550  -->  00:00:29,550
you must analyze data to prioritize vulnerabilities.
14

14

00:00:29,550  -->  00:00:31,350
And Objective 3.1 states
15

15

00:00:31,350  -->  00:00:33,000
that you must be able to explain concepts
16

16

00:00:33,000  -->  00:00:35,370
related to attack methodology frameworks.
17

17

00:00:35,370  -->  00:00:37,530
So, as we move through this section,
18

18

00:00:37,530  -->  00:00:38,850
we're going to start out by describing
19

19

00:00:38,850  -->  00:00:40,620
how we can classify different threats
20

20

00:00:40,620  -->  00:00:43,860
as either benign, malicious, known, or unknown.
21

21

00:00:43,860  -->  00:00:46,500
Then, we'll dive into the concept of threat actors,
22

22

00:00:46,500  -->  00:00:47,580
including the various types,
23

23

00:00:47,580  -->  00:00:50,760
like script kiddies, hactivists, and APTs.
24

24

00:00:50,760  -->  00:00:51,600
After that,
25

25

00:00:51,600  -->  00:00:53,250
we're going to take a look at the commoditization
26

26

00:00:53,250  -->  00:00:55,230
of malware and zero-day threats
27

27

00:00:55,230  -->  00:00:57,630
and uncovering where some really large amounts of money
28

28

00:00:57,630  -->  00:01:01,140
are being spent and earned based on these zero-days.
29

29

00:01:01,140  -->  00:01:02,940
Next, we'll talk about the different types
30

30

00:01:02,940  -->  00:01:05,130
of threat research that are conducted to classify
31

31

00:01:05,130  -->  00:01:07,350
these different threats that we're going to experience.
32

32

00:01:07,350  -->  00:01:10,050
And then, we'll jump into several attack frameworks
33

33

00:01:10,050  -->  00:01:12,150
to help us identify these threats and attacks,
34

34

00:01:12,150  -->  00:01:14,460
including the Lockheed Martin Cyber Kill Chain,
35

35

00:01:14,460  -->  00:01:15,840
the MITRE ATT&amp;CK Framework,
36

36

00:01:15,840  -->  00:01:18,330
and the Diamond Model of Intrusion Analysis frameworks.
37

37

00:01:18,330  -->  00:01:20,520
After that, we're going to spend some time
38

38

00:01:20,520  -->  00:01:22,950
discussing various indicator management frameworks,
39

39

00:01:22,950  -->  00:01:25,470
such as the Structured Threat Information eXpression,
40

40

00:01:25,470  -->  00:01:26,940
known as STIX,
41

41

00:01:26,940  -->  00:01:29,700
the Trusted Automated eXchange of Indicator Information,
42

42

00:01:29,700  -->  00:01:32,130
known as TAXII, or T-A-X-I-I,
43

43

00:01:32,130  -->  00:01:35,940
the OpenIOC and the MISP frameworks.
44

44

00:01:35,940  -->  00:01:37,770
Finally, we're going to take a short quiz
45

45

00:01:37,770  -->  00:01:39,900
to see what you learned during this section of the course
46

46

00:01:39,900  -->  00:01:42,030
and review each of those quiz questions fully
47

47

00:01:42,030  -->  00:01:44,700
to ensure you can explain why the right answers were right.
48

48

00:01:44,700  -->  00:01:47,130
So, let's get started diving into the concepts
49

49

00:01:47,130  -->  00:01:48,720
surrounding the classification of threats
50

50

00:01:48,720  -->  00:01:50,220
in this section of the course.
