School / Prep
ENSEIRB-MATMECA
Study level
Bac + 5
ECTS
1 credits
Internal code
IT320
Description
Give students the fundamentals to join CERT & SOC (Incident Response Center / Threat Analyst). Learn about the threat and give students the skills to do
their first "Threat Analysis". We'll be sure to make the subject practical by implementing :
- an OPENCTI platform
- the development of their DRSD platforms: Detection Ransomware Surveillance Deep
& DarkWeb.
Objectives
Threat Intelligence:
1. Definition
2. Threat Intelligence lifecycle
3. Practicing Threat Intelligence
4. Intelligence Source
5. Traffic Light Protocol
Threat actors and modus operandi:
1. Actors and their motivations
2. Allocation procedure
Analyse de la menace : Tools & Procédures
1. Les outils { Data collection, Data processing, etc ….
2. YARA Rules
3. Analyses de LOG
4. Anatomie des Règles Sigma
5. MSTICpy
6. OPENCTI / MISP
Teaching hours
- CIIntegrated courses16h
Assessment of knowledge
Initial assessment / Main session
| Type of assessment | Nature of assessment | Duration (in minutes) | Number of tests | Evaluation coefficient | Eliminatory evaluation mark | Remarks |
|---|---|---|---|---|---|---|
| Continuous control | Continuous control | 1 |
Second chance / Catch-up session
| Type of assessment | Nature of assessment | Duration (in minutes) | Number of tests | Evaluation coefficient | Eliminatory evaluation mark | Remarks |
|---|---|---|---|---|---|---|
| Project | Report |
