We’re an information security practitioner-focused company dedicated to providing impactful, high quality training and education. Founded by @chrissanders88.
Detection Engineering with Sigma will teach you how to write and tune Sigma rules to find evil in logs using real-world examples that take you through the detection engineering process. networkdefense.co/courses/si…
ALT Leonardo Armesto wrote, “Detection Engineering with Sigma is like learning a 'universal translator' for security alerts. The course shows you how to write a detection rule once and apply it to almost any security system.”
ALT A student wrote, "I thought this course was excellently taught in a digestible and straightforward way as someone who has no experience as an analyst."
Practical Threat Hunting is a structured system to ensure you’re never at a loss for what to hunt for, where to find it, and how to see it amongst the noise.
networkdefense.co/courses/hu…
ALT A student wrote, "I bought this course for the focus on how to organize hunting and describing hunting on a conceptual level, in contrast with a lot of other courses that cover the forensic analysis in depth but do not give context and motivation. It is an excellent introduction to the fundamental concepts of threat hunting.”
Ever wondered how attackers leverage WMI for persistence? In our latest Analyst Skills Vault lesson, Dan Marr demonstrates the technique and how to detect and investigate it.
ALT Reviewing Windows logs showing evidence of WMI-based persistence
(focus on the highlighted part of the image).
You can learn more about our Analyst Skills Vault and sign up here: networkdefense.co/skillsvaul…. We have monthly and annual subscription options and add new videos every month.
Learn to use YARA to detect malware, triage compromised systems, and perform threat intelligence research.
networkdefense.co/courses/ya…
ALT "I not only wanted to learn about YARA (e.g., learning a language and syntax), but I wanted to learn more about malware and adversary tradecraft. I think this course did a wonderful job of covering that material."
You can learn more about our Analyst Skills Vault and sign up here: networkdefense.co/skillsvaul…. We have monthly and annual subscription options and add new videos every month.
Learning Splunk from documentation is one thing.
Using it like a real security analyst is another.
Our Splunk for Security Analysts course focuses on the practical skills analysts actually use in investigations.
ALT "A one-stop shop on best practices for Splunk, from setup all the way through threat detection applications, at a reasonable price." - Max Di Lalla
You’ll work with real security datasets, not toy examples.
Learn how to:
• Onboard data
• Extract meaningful fields
• Search and pivot through events
• Conduct real investigations
networkdefense.co/courses/sp…
In our latest lesson, @DunhamSec demonstrates tools and techniques for identifying process tree anomalies, with a bonus overview of typical Windows process genealogy!
ALT Reviewing typical Windows process genealogy to make it easier to spot anomalies.
In our latest lesson, @DunhamSec demonstrates tools and techniques for identifying process tree anomalies, with a bonus overview of typical Windows process genealogy!
ALT Reviewing typical Windows process genealogy to make it easier to spot anomalies.
ALT Patrick English wrote, "If someone is a serious analyst looking to up their 'thinking game' - this course is definitely worth it. The most useful thing I learned was Diagnostic Inquiry. This gave me the ability to streamline a kind of 'formula' for more efficiency when investigating things. Not just IT / Cyber related investigating/researching either."
ICYMI 👇
Dan Marr breaks down how to detect malware communication using JA4 fingerprints with Wireshark, Suricata, and Zeek in our latest Skills Vault lesson.
ALT Identifying potential malware communication using JA4 fingerprints with Suricata.
You can learn more about our Analyst Skills Vault and sign up here: networkdefense.co/skillsvaul…. We have monthly and annual subscription options and add new videos every month.
Learn to wield the full power of regex for searching in your SIEM, building detection rules, and more.
networkdefense.co/courses/re…
ALT Hudson Carr wrote, “This course is relevant, even with the onset of AI. I've found that AI can help me write regex, but if the AI output didn't solve the problem exactly as I intended, I was lost. Or if the AI was providing slightly off syntax, I could not troubleshoot it effectively. After taking this course I am able to write regex myself but also efficiently iterate with AI to write regex which has been very useful.”
In our latest Skills Vault lesson, Dan Marr shows you how to use JA4 fingerprints to detect malware communication while leveraging tools like Wireshark, Suricata, and Zeek.
ALT Identifying potential malware communication using JA4 fingerprints with Suricata.
You can learn more about our Analyst Skills Vault and sign up here: networkdefense.co/skillsvaul…. We have monthly and annual subscription options and add new videos every month.