1
1

00:00:00,090  -->  00:00:01,380
<v ->In this section of the course,</v>
2

2

00:00:01,380  -->  00:00:03,300
we're going to cover threat hunting.
3

3

00:00:03,300  -->  00:00:04,800
Our focus again in this section
4

4

00:00:04,800  -->  00:00:06,480
is going to continue to cover objectives
5

5

00:00:06,480  -->  00:00:09,300
across multiple domains, specifically Domain 1,
6

6

00:00:09,300  -->  00:00:12,930
Security Operations, and Domain 2, Vulnerability Management.
7

7

00:00:12,930  -->  00:00:15,750
Objective 1.3 states that given a scenario,
8

8

00:00:15,750  -->  00:00:17,820
you must use appropriate tools or techniques
9

9

00:00:17,820  -->  00:00:19,680
to determine malicious activity.
10

10

00:00:19,680  -->  00:00:22,410
Objective 1.4 states that you must be able to compare
11

11

00:00:22,410  -->  00:00:23,820
and contrast threat intelligence
12

12

00:00:23,820  -->  00:00:25,500
and threat hunting concepts.
13

13

00:00:25,500  -->  00:00:27,240
And objective 2.5 states
14

14

00:00:27,240  -->  00:00:29,100
that you must be able to explain concepts
15

15

00:00:29,100  -->  00:00:32,430
related to vulnerability response, handling, and management.
16

16

00:00:32,430  -->  00:00:34,470
So as we move through this section,
17

17

00:00:34,470  -->  00:00:36,690
we're going to start out by describing the key factors used
18

18

00:00:36,690  -->  00:00:39,510
in threat modeling, such as adversary capability,
19

19

00:00:39,510  -->  00:00:42,720
total attack surface, attack vector, impact,
20

20

00:00:42,720  -->  00:00:44,670
and the likelihood of the attack occurring
21

21

00:00:44,670  -->  00:00:46,800
against a given system or network.
22

22

00:00:46,800  -->  00:00:49,380
Then, we'll discuss the importance of threat hunting
23

23

00:00:49,380  -->  00:00:52,500
and how it should be performed inside of our organizations.
24

24

00:00:52,500  -->  00:00:54,960
After that, we'll start our coverage of various sources
25

25

00:00:54,960  -->  00:00:56,580
of open-source intelligence.
26

26

00:00:56,580  -->  00:00:59,370
This includes things like Google hacking, Shodan,
27

27

00:00:59,370  -->  00:01:01,770
email and social media profiling techniques,
28

28

00:01:01,770  -->  00:01:04,440
and DNS and website harvesting techniques.
29

29

00:01:04,440  -->  00:01:07,050
You'll be amazed at just how much information is out there
30

30

00:01:07,050  -->  00:01:09,120
and available for us to collect and analyze
31

31

00:01:09,120  -->  00:01:11,760
as we start to experiment with open-source intelligence
32

32

00:01:11,760  -->  00:01:13,410
and it's related techniques.
33

33

00:01:13,410  -->  00:01:16,530
Then, we're going to discuss the AbuseIPDB tool,
34

34

00:01:16,530  -->  00:01:18,510
which serves as a centralized database
35

35

00:01:18,510  -->  00:01:20,520
that's going to be dedicated to helping combat the spread
36

36

00:01:20,520  -->  00:01:24,030
of attackers, spammers, and abusive activity on the internet
37

37

00:01:24,030  -->  00:01:26,790
by providing a centralized block list for webmasters,
38

38

00:01:26,790  -->  00:01:29,400
system administrators, and cybersecurity professionals
39

39

00:01:29,400  -->  00:01:31,230
to report and find IP addresses
40

40

00:01:31,230  -->  00:01:32,520
that are known to have been associated
41

41

00:01:32,520  -->  00:01:34,620
with malicious activity online.
42

42

00:01:34,620  -->  00:01:37,500
Next, we'll venture into the deep web and the dark web
43

43

00:01:37,500  -->  00:01:39,240
to see what kind of information can be found
44

44

00:01:39,240  -->  00:01:41,130
in the darkest quarters of the internet.
45

45

00:01:41,130  -->  00:01:43,560
And after that, we're going to discuss bug bounties,
46

46

00:01:43,560  -->  00:01:45,870
which allows companies to incentivize ethical hackers
47

47

00:01:45,870  -->  00:01:48,420
and penetration testers to seek out security holes
48

48

00:01:48,420  -->  00:01:51,210
and vulnerabilities inside their software, websites,
49

49

00:01:51,210  -->  00:01:52,560
and other products.
50

50

00:01:52,560  -->  00:01:54,240
Finally, we're going to take a short quiz
51

51

00:01:54,240  -->  00:01:56,250
to see what you learned during this section of the course
52

52

00:01:56,250  -->  00:01:58,350
and review each of those quiz questions fully
53

53

00:01:58,350  -->  00:02:00,180
to ensure that you can explain why the right answers
54

54

00:02:00,180  -->  00:02:01,013
were right.
55

55

00:02:01,013  -->  00:02:03,450
So, let's start exploring the world of threat hunting
56

56

00:02:03,450  -->  00:02:04,950
in this section of the course.
