1
1

00:00:00,360  -->  00:00:01,710
<v ->In this section of the course,</v>
2

2

00:00:01,710  -->  00:00:03,900
we're going to cover endpoint monitoring.
3

3

00:00:03,900  -->  00:00:05,670
Now, our focus in this section of the course
4

4

00:00:05,670  -->  00:00:06,720
is going to continue to be
5

5

00:00:06,720  -->  00:00:09,210
in Domain One with Security Operations,
6

6

00:00:09,210  -->  00:00:12,600
and specifically Objectives, 1.1 and 1.3.
7

7

00:00:12,600  -->  00:00:13,819
Objective 1.1 states
8

8

00:00:13,819  -->  00:00:15,810
that you must be able to explain the importance
9

9

00:00:15,810  -->  00:00:17,940
of system and network architecture concepts
10

10

00:00:17,940  -->  00:00:19,440
in security operations,
11

11

00:00:19,440  -->  00:00:22,080
with our focus here being on the Windows Registry,
12

12

00:00:22,080  -->  00:00:24,960
system processes and file structures of a system
13

13

00:00:24,960  -->  00:00:27,450
whenever malware is attacking that system.
14

14

00:00:27,450  -->  00:00:29,280
Objective 1.3 on the other hand,
15

15

00:00:29,280  -->  00:00:30,780
states that given a scenario,
16

16

00:00:30,780  -->  00:00:33,540
you must be able to use appropriate tools or techniques
17

17

00:00:33,540  -->  00:00:35,490
to determine malicious activity.
18

18

00:00:35,490  -->  00:00:37,590
This includes things like sandboxing,
19

19

00:00:37,590  -->  00:00:40,080
EDR, or endpoint detection response,
20

20

00:00:40,080  -->  00:00:41,680
creating a allow list and block list
21

21

00:00:41,680  -->  00:00:43,680
to be able to control access and permissions
22

22

00:00:43,680  -->  00:00:46,440
to execute various files and things like that.
23

23

00:00:46,440  -->  00:00:48,060
Now, as we move through this section,
24

24

00:00:48,060  -->  00:00:49,440
we're going to start out with a discussion
25

25

00:00:49,440  -->  00:00:52,230
of the methods of endpoint data collection and analysis
26

26

00:00:52,230  -->  00:00:54,690
that we're going to be able to use within our organizations.
27

27

00:00:54,690  -->  00:00:57,360
Then, we're going to explore the concept of sandboxing
28

28

00:00:57,360  -->  00:00:59,550
and how it's used for malware analysis.
29

29

00:00:59,550  -->  00:01:01,110
Speaking of malware analysis,
30

30

00:01:01,110  -->  00:01:03,600
we're also going to cover the idea of reverse engineering,
31

31

00:01:03,600  -->  00:01:06,330
where an analyst tries to take a compiled piece of software
32

32

00:01:06,330  -->  00:01:09,420
and determine how it really operates underneath its code.
33

33

00:01:09,420  -->  00:01:10,740
Next, we're going to discuss
34

34

00:01:10,740  -->  00:01:13,050
the different types of malware exploitation techniques
35

35

00:01:13,050  -->  00:01:16,620
such as droppers, downloaders, shell code, code injection
36

36

00:01:16,620  -->  00:01:18,270
and Living off the Land.
37

37

00:01:18,270  -->  00:01:21,330
After that, we're going to cover the use of behavioral analysis
38

38

00:01:21,330  -->  00:01:23,850
to identify known good and anomalous behavior,
39

39

00:01:23,850  -->  00:01:26,130
as well as performing a hands-on demonstration
40

40

00:01:26,130  -->  00:01:28,980
to show you how to conduct malware analysis using tools
41

41

00:01:28,980  -->  00:01:32,130
like Process Explorer, netstat, Process Monitor,
42

42

00:01:32,130  -->  00:01:35,070
System Monitor, auto-runs, and many others.
43

43

00:01:35,070  -->  00:01:37,740
Next, we're going to discuss the configuration changes
44

44

00:01:37,740  -->  00:01:41,160
used with EDR, or endpoint detection and response systems,
45

45

00:01:41,160  -->  00:01:43,290
to increase the security of your endpoints,
46

46

00:01:43,290  -->  00:01:44,430
as well as how you can use
47

47

00:01:44,430  -->  00:01:47,160
block list and allow list in your configurations
48

48

00:01:47,160  -->  00:01:49,080
to better protect your devices.
49

49

00:01:49,080  -->  00:01:50,880
Finally, we're going to take a short quiz
50

50

00:01:50,880  -->  00:01:53,010
to see what you learned during this section of the course,
51

51

00:01:53,010  -->  00:01:54,120
and, of course, we're going to review
52

52

00:01:54,120  -->  00:01:55,710
the answers to those quiz questions
53

53

00:01:55,710  -->  00:01:58,530
to ensure you understand why the right answers were right.
54

54

00:01:58,530  -->  00:02:01,050
As you can see, it's going to be a really busy section,
55

55

00:02:01,050  -->  00:02:02,910
with a lot of stuff for us to cover,
56

56

00:02:02,910  -->  00:02:04,110
so let's go ahead and get started
57

57

00:02:04,110  -->  00:02:05,610
in this section of the course.
