Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So we're going to go through in day one or in book one.
We're going to go through step by step what we call the
pickerel framework that has learned recovery.
We're going to go through all of those steps
because when we're looking at it attack something like
Metasploit or
endpoint security Bypass or bypassing a firewall we have
to put that in a frame work context of how do you prepare
for that attack?
How do you identify that attack?
How do you contain that attack and so on
so this day becomes so important because Allows you
to start rationalizing the attack techniques and then
developing your preparation steps the policies processes
procedures training to get ready for that eventuality
tack and then also going through the steps for
identification and containment if we didn't have this day maybe
nothing but a whole bunch of different tools that may or
may not become outdated in a year or so.
So talking about this as a foundational framework and
then using the tools
gives you the mental framework to develop defenses regardless
of whatever.
Attack is coming at your organization.
So we're going to go through each one of these to these
different sections preparation identification containment
eradication recovery Lessons Learned and yes, there are a
whole bunch of labs throughout this day will be covering
Windows cheat sheet command line Kung Fu getting started
at the command line on Windows
is so in central essential because so many of the attacks
Target our Windows systems.
We're going to talk about enterprise-wide identification
and Analysis, which is a lab that's very very near and dear
to my heart specifically.
I'll explain that in a bit.
We'll talk about Espionage intellectual property attacks
legal issues in computer security.
And then finally we have an incident response tabletop lab
that it really think ties together the entire day and
the reason why this lab is so important to cap off this day
because it gives you a framework to very quickly
gamify tabletop exercises with your co-workers with your
employees
with your management at your organization to determine the
overall Readiness at your organization for an
Coming against your organization.
So let's go ahead and let's get started.
We're going to jump between the podium here
and live sessions at an undisclosed location.
So now let's jump over to one of those live sessions and
I'll see you in just a little bit for our next section here
at the podium.
Thank you so much.
Now as I mentioned today is all about those policies, right?
We're going to go through that pickerel framework for
Preparation identification containment eradication
recovery Lessons Learned going to do all of that today.
And for some people that's kind of tough,
right they come to a class.
It's called hacker techniques exploits and incident handling
and they somehow expect they're going to hit the ground
immediately and start talking about hacker tools and
techniques to breaking into things
and they're a little bit confused by all the policy
process and procedure that we cover in.
A what
but this day
without question is the most important day of sans 504.
This is the day that will help you contextualize and prepare
for a tax regardless of what those attacks actually are as
long as we know the techniques and the capabilities of
adversaries and we know what components we can work with we
can defend and reacts to a wide variety
of different times.
And as I mentioned earlier this day establishes the framework
for us going through and covering different.
At Trends and the different phases that an attacker will
go through to try to gain access to your network because
this framework is applicable to every single phase in the
entire attack methodology that is out there today.
Also as part of this Court's we have virtual machines
the virtual machines have every tool that you need for this
class built into them
also almost all of the labs except for day six
are able to be ran locally on your system and I want to
explain that a little bit.
There's a lot of classes and they have a lot of really
really cool things will bring in all kinds of gear the front
of the classroom for you to break into
and that's great.
The only problem I have with that.
It's for a foundational class like 504.
You can't take it home with you.
I wanted to have every single lab in this course
be able to run on a single machine.
So you could continue practicing the different
techniques that we cover in this course moving forward
into the future without needing to have a lab
now the Bible for VMS are 7-Zip compressed.
We have seven zipper windows
on the course USB.
If you're using a Mac, you have to go to the App Store and
download a 7 zip utility.
There's a bunch of them out there pick one install it and
run it I used to.
Hand out caki
the keka would work for one specific version of OS X and
it wouldn't work on anything else.
So it's better just to get it from the app store because it
gets you the right version of the tool that you need to
extract the virtual machines in this course.
Now whenever you open up the virtual machine, it's going to
say if you moved or copied, please select copy
that causes the virtual machine to generate a new Mac address.
So we don't have mac address collisions.
So we want to extract that now because it's going to take some
I'm the passwords in the user IDs for the virtual machines
are SEC 504 for the user ID and the password is SEC 504
and then for becoming root on the Linux machine it's to do
su space -
that - is incredibly important to make sure loads properly
and I wouldn't worry about this too much because in a lot
of our Labs we give you these exact commands.
You don't have to memorize them.
The only thing that you really need to memorize the user ID
and the password for logging in which is pretty
straightforward.
Forward it just so happens to be the class version as well.
If you're
from
another country and you have a different keyboard layout you
can go into the virtual machines and change your
keyboard layout from within the virtual machine as well.
All right, as I mentioned earlier in one of the earlier
videos a key component to being successful in Sands.
504 On Demand is actually doing the labs in order to do the
labs.
You've got to get the virtual machines extracted and we've
already talked about that
but the other key part is the awesome day six or books X
Capture the Flag event.
It's common for many students that are just getting started
with on-demand kind of put this part off until later you
need to do this right now
the capture the flag.
On Demand is special and the reason why it's special is you
get access to the on-demand VPN with a full capture-the-flag
experience
for months.
Whereas in a live setting
and set up for one day and that's it.
You need to get set up you need to get configured and on this
slide slide number eight.
We have step-by-step instructions on how you're
supposed to do that more importantly you're going to
receive an email from Sands.
And in that email it's going to give you step-by-step
instructions and And links to download specific
configuration files to do the capture the flag for Sands 504.
So when you get that email don't just ignore it or send
it to spam or send it to trash you want to pull that email up
you want to go through those Instructions?
Make sure the virtual machines can connect into the Sands VPN
so that you can enjoy the full Capture the Flag experience
when you do the capture the flag and I'll talk about this
more in book six.
Don't just do it.
Once you want to be able to go through that CTF almost as
though so it's cold like you can just do it without
thinking and you'll get that opportunity because you're
doing this on demand and you get access for this VPN
for months after you get started in this class.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.