School / Prep
ENSEIRB-MATMECA
Study level
Bac + 5
Internal code
EIN9-SECU6
Description
Give students the fundamentals to join CERT & SOC (Incident Response Center / Threat Analyst). Learn about the threat and give students the skills to do
their first "Threat Analysis". We'll be sure to make the subject practical by implementing :
- an OPENCTI platform
- the development of their DRSD platforms: Detection Ransomware Surveillance Deep
& DarkWeb.
Objectives
Threat Intelligence:
1. Definition
2. Threat Intelligence lifecycle
3. Practicing Threat Intelligence
4. Intelligence Source
5. Traffic Light Protocol
Threat actors and modus operandi:
1. Actors and their motivations
2. Allocation procedure
Analyse de la menace : Tools & Procédures
1. Les outils { Data collection, Data processing, etc ….
2. YARA Rules
3. Analyses de LOG
4. Anatomie des Règles Sigma
5. MSTICpy
6. OPENCTI / MISP
Teaching hours
- CIIntegrated courses16h
Assessment of knowledge
Initial assessment / Main session - Tests
Type of assessment | Type of test | Duration (in minutes) | Number of tests | Test coefficient | Eliminatory mark in the test | Remarks |
---|---|---|---|---|---|---|
Continuous control | Continuous control | 1 |
Second chance / Catch-up session - Tests
Type of assessment | Type of test | Duration (in minutes) | Number of tests | Test coefficient | Eliminatory mark in the test | Remarks |
---|---|---|---|---|---|---|
Project | Report |