1
1

00:00:00,090  -->  00:00:01,589
<v ->In this section of the course</v>
2

2

00:00:01,589  -->  00:00:03,840
we're going to be covering email monitoring.
3

3

00:00:03,840  -->  00:00:06,240
Our focus in this section is going to continue to be
4

4

00:00:06,240  -->  00:00:09,450
in domain 1, security operations, and specifically,
5

5

00:00:09,450  -->  00:00:12,900
we'll continue our focus on objective 1.3.
6

6

00:00:12,900  -->  00:00:15,570
Objective 1.3 states that given a scenario,
7

7

00:00:15,570  -->  00:00:18,420
you must be able to use appropriate tools or techniques
8

8

00:00:18,420  -->  00:00:20,460
to determine malicious activity.
9

9

00:00:20,460  -->  00:00:22,050
As we move through this section,
10

10

00:00:22,050  -->  00:00:24,060
we're going to start out by conducting an analysis
11

11

00:00:24,060  -->  00:00:26,820
of your email monitoring tools output as you start
12

12

00:00:26,820  -->  00:00:29,280
to explore the different types of indicators of compromise,
13

13

00:00:29,280  -->  00:00:31,830
known as IOCs, that could be used to determine
14

14

00:00:31,830  -->  00:00:34,920
if an email phishing campaign or impersonation campaign
15

15

00:00:34,920  -->  00:00:37,620
has been occurring inside your organization.
16

16

00:00:37,620  -->  00:00:40,230
Then we're going to explore how you can conduct an analysis
17

17

00:00:40,230  -->  00:00:44,580
of an email header or an email's content for malicious data.
18

18

00:00:44,580  -->  00:00:46,830
Next, we'll focus on the proper configuration
19

19

00:00:46,830  -->  00:00:49,290
of your email server to give you additional security,
20

20

00:00:49,290  -->  00:00:52,440
as well as how to conduct an analysis of an SMTP log
21

21

00:00:52,440  -->  00:00:53,910
and how to secure emails
22

22

00:00:53,910  -->  00:00:56,460
using S/MIME and digital signatures.
23

23

00:00:56,460  -->  00:00:59,340
After that, I'm going to perform a hands-on demonstration
24

24

00:00:59,340  -->  00:01:01,500
that shows you how to analyze an email's header
25

25

00:01:01,500  -->  00:01:04,590
to determine if an indicator of compromise or IOC
26

26

00:01:04,590  -->  00:01:07,230
can be identified within that email header.
27

27

00:01:07,230  -->  00:01:09,420
Now finally, we're going to take a short quiz
28

28

00:01:09,420  -->  00:01:11,460
to see what you learned during this section of the course
29

29

00:01:11,460  -->  00:01:13,590
and review each of those quiz questions fully
30

30

00:01:13,590  -->  00:01:16,620
to ensure you can explain why the right answers are right.
31

31

00:01:16,620  -->  00:01:19,620
This is going to be a fun section as we begin to dive deep
32

32

00:01:19,620  -->  00:01:22,080
into determining how secure your email really is
33

33

00:01:22,080  -->  00:01:23,490
within your organization
34

34

00:01:23,490  -->  00:01:26,130
because email is such a common attack vector
35

35

00:01:26,130  -->  00:01:28,080
that's used by threat actors all the time
36

36

00:01:28,080  -->  00:01:30,210
during their social engineering campaigns.
37

37

00:01:30,210  -->  00:01:32,250
This includes the use of things like phishing,
38

38

00:01:32,250  -->  00:01:35,070
spear phishing, or whaling against your end users
39

39

00:01:35,070  -->  00:01:37,620
and we need to be able to identify it and stop it.
40

40

00:01:37,620  -->  00:01:40,020
So let's dive into the world of email monitoring
41

41

00:01:40,020  -->  00:01:41,520
in this section of the course.
