MITRE ATT&CK Training Course
MITRE ATT&CK is a comprehensive framework of tactics and techniques designed to classify cyberattacks and evaluate organizational risk. It enhances security awareness by identifying vulnerabilities in defenses and helping to prioritize threats.
This instructor-led, live training (available online or onsite) is designed for information system analysts who want to leverage MITRE ATT&CK to reduce the risk of security breaches.
Upon completion of this training, participants will be able to:
- Configure the necessary development environment to begin implementing MITRE ATT&CK.
- Categorize how attackers interact with systems.
- Document adversary behaviors within systems.
- Monitor attacks, identify patterns, and evaluate existing defensive tools.
Format of the Course
- Interactive lecture and discussion.
- Extensive exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline
Introduction
What is Malware?
- Types of malware
- The evolution of malware
Overview of Malware Attacks
- Propagating
- Non-propagating
Matrices of ATT&CK
- Enterprise ATT&CK
- Pre-ATT&CK
- Mobile ATT&CK
MITRE ATT&CK
- 11 tactics
- Techniques
- Procedures
Preparing the Development Environment
- Setting up a version control center (GitHub)
- Downloading a project that hosts a to-do list system of data
- Installing and configuring ATT&CK Navigator
Monitoring a compromised system (WMI)
- Executing command line scripts to conduct a lateral attack
- Utilizing ATT&CK Navigator to identify the compromise
- Evaluating the compromise through the ATT&CK framework
- Performing process monitoring
- Documenting and patching the holes in the defense architecture
Monitoring a compromised system (EternalBlue)
- Executing command line scripts to conduct a lateral attack
- Utilizing ATT&CK Navigator to identify the compromise
- Evaluating the compromise through the ATT&CK framework
- Performing process monitoring
- Documenting and patching the holes in the defense architecture
Summary and Conclusion
Requirements
- An understanding of information system security
Audience
- Information systems analysts
Open Training Courses require 5+ participants.
MITRE ATT&CK Training Course - Booking
MITRE ATT&CK Training Course - Enquiry
MITRE ATT&CK - Consultancy Enquiry
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent
Manar Abu Talib - Dubai Electronic Security Center
Course - MITRE ATT&CK
Upcoming Courses
Related Courses
AI-Powered Cybersecurity: Threat Detection & Response
21 HoursThis instructor-led live training in Slovakia (online or onsite) is tailored for beginner-level cybersecurity professionals seeking to leverage AI for enhanced threat detection and response.
By the end of this training, participants will be able to:
- Understand AI applications in cybersecurity.
- Implement AI algorithms for threat detection.
- Automate incident response with AI tools.
- Integrate AI into existing cybersecurity infrastructure.
AI-Powered Cybersecurity: Advanced Threat Detection & Response
28 HoursThis instructor-led, live training in Slovakia (online or onsite) is designed for intermediate to advanced cybersecurity professionals seeking to elevate their skills in AI-driven threat detection and incident response.
Upon completion of this training, participants will be able to:
- Deploy advanced AI algorithms for real-time threat detection.
- Customize AI models to address specific cybersecurity challenges.
- Develop automation workflows for effective threat response.
- Secure AI-driven security tools against adversarial attacks.
Blue Team Fundamentals: Security Operations and Analysis
21 HoursThis instructor-led, live training in Slovakia (online or onsite) is aimed at intermediate-level IT security professionals who wish to develop skills in security monitoring, analysis, and response.
By the end of this training, participants will be able to:
- Understand the role of a Blue Team in cybersecurity operations.
- Use SIEM tools for security monitoring and log analysis.
- Detect, analyze, and respond to security incidents.
- Perform network traffic analysis and threat intelligence gathering.
- Apply best practices in security operations center (SOC) workflows.
Bug Bounty Hunting
21 HoursBug Bounty Hunting involves finding security weaknesses in software, websites, or systems and reporting them responsibly to receive rewards or recognition.
This instructor-led live training (available online or onsite) is designed for beginner-level security researchers, developers, and IT professionals who want to learn the basics of ethical bug hunting and how to join bug bounty programs.
By the end of this training, participants will be able to:
- Understand the core concepts of vulnerability discovery and bug bounty programs.
- Use key tools like Burp Suite and browser dev tools for testing applications.
- Identify common web security flaws such as XSS, SQLi, and CSRF.
- Submit clear, actionable vulnerability reports to bug bounty platforms.
Format of the Course
- Interactive lecture and discussion.
- Hands-on use of bug bounty tools in simulated testing environments.
- Guided exercises focused on discovering, exploiting, and reporting vulnerabilities.
Course Customization Options
- To request a customized training for this course based on your organization's applications or testing needs, please contact us to arrange.
Bug Bounty: Advanced Techniques and Automation
21 HoursBug Bounty: Advanced Techniques and Automation offers an in-depth exploration of high-impact vulnerabilities, automation frameworks, reconnaissance methodologies, and the tooling strategies employed by elite bug bounty hunters.
This instructor-led, live training (available online or onsite) is designed for security researchers, penetration testers, and bug bounty hunters at intermediate to advanced levels who aim to automate their workflows, scale reconnaissance efforts, and uncover complex vulnerabilities across multiple targets.
Upon completion of this training, participants will be able to:
- Automate reconnaissance and scanning processes for multiple targets.
- Leverage state-of-the-art tools and scripts utilized in bounty automation.
- Identify complex, logic-based vulnerabilities that extend beyond standard scanning capabilities.
- Construct custom workflows for subdomain enumeration, fuzzing, and reporting.
Format of the Course
- Interactive lectures and discussions.
- Practical application of advanced tools and scripting for automation.
- Guided laboratory sessions focused on real-world bounty workflows and advanced attack chains.
Course Customization Options
- To request a customized training tailored to your bounty targets, automation requirements, or internal security challenges, please contact us to arrange.
CHFI - Certified Digital Forensics Examiner
35 HoursThe vendor-neutral Certified Digital Forensics Examiner certification is designed to equip Cyber Crime and Fraud Investigators with skills in electronic discovery and advanced investigative methodologies. This course is vital for any professional who may encounter digital evidence during an investigation.
The Certified Digital Forens Examiner training focuses on the systematic methodology required for conducting computer forensic examinations. Students will learn to apply forensically sound techniques to evaluate crime scenes, collect and document relevant data, interview key personnel, maintain the chain of custody, and produce comprehensive findings reports.
The Certified Digital Forensics Examiner program offers significant value to organizations, individual professionals, government agencies, and law enforcement bodies that need to pursue litigation, establish proof of guilt, or implement corrective actions based on digital evidence.
Certified Incident Handler
21 HoursThe Certified Incident Handler course delivers a structured methodology for managing and responding to cybersecurity incidents with efficiency and effectiveness.
Delivered by an instructor via live online or on-site sessions, this training is designed for IT security professionals with intermediate-level expertise who aim to acquire the tactical skills and knowledge necessary to plan, classify, contain, and manage security incidents.
Upon completion of this training, participants will be capable of:
- Comprehending the incident response lifecycle and its various phases.
- Executing procedures for incident detection, classification, and notification.
- Applying containment, eradication, and recovery strategies effectively.
- Formulating post-incident reports and plans for continuous improvement.
Course Format
- Interactive lectures and discussions.
- Practical application of incident handling procedures within simulated scenarios.
- Guided exercises targeting detection, containment, and response workflows.
Customization Options
- To arrange customized training tailored to your organization's specific incident response procedures or tools, please contact us.
Mastering Continuous Threat Exposure Management (CTEM)
28 HoursThis instructor-led, live training in Slovakia (available online or onsite) is designed for intermediate-level cybersecurity professionals aiming to implement CTEM in their organizations.
After finishing this training, participants will be able to:
- Comprehend the core principles and phases of CTEM.
- Spot and rank risks using established CTEM methods.
- Embed CTEM practices into current security frameworks.
- Apply specialized tools and technologies for ongoing threat oversight.
- Create plans to continuously verify and enhance security controls.
Cyber Threat Intelligence
35 HoursThis instructor-led, live training in Slovakia (online or onsite) is designed for advanced cybersecurity professionals seeking to understand Cyber Threat Intelligence and develop skills to effectively manage and mitigate cyber threats.
Upon completion of this training, participants will be capable of:
- Grasping the core principles of Cyber Threat Intelligence (CTI).
- Evaluating the contemporary cyber threat landscape.
- Gathering and processing intelligence data.
- Conducting advanced threat analysis.
- Utilizing Threat Intelligence Platforms (TIPs) to automate threat intelligence workflows.
Fundamentals of Corporate Cyber Warfare
14 HoursThis instructor-led, live training in Slovakia (online or onsite) covers the different aspects of enterprise security, from AI to database security. It also includes coverage of the latest tools, processes and mindset needed to protect from attacks.
DeepSeek for Cybersecurity and Threat Detection
14 HoursThis instructor-led, live training in Slovakia (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to leverage DeepSeek for advanced threat detection and automation.
By the end of this training, participants will be able to:
- Utilize DeepSeek AI for real-time threat detection and analysis.
- Implement AI-driven anomaly detection techniques.
- Automate security monitoring and response using DeepSeek.
- Integrate DeepSeek into existing cybersecurity frameworks.
Duty Managers Cyber Resilience
14 HoursThis instructor-led, live training in Slovakia (online or onsite) is aimed at intermediate-level duty managers and operational leaders who wish to build robust cyber resilience strategies to safeguard their organizations against cyber threats.
By the end of this training, participants will be able to:
- Understand cyber resilience fundamentals and their relevance to duty management.
- Develop incident response plans to maintain operational continuity.
- Identify potential cyber threats and vulnerabilities within their environment.
- Implement security protocols to minimize risk exposure.
- Coordinate team response during cyber incidents and recovery processes.
Junior Detection Engineer Essentials
21 HoursDetection engineering involves the design, implementation, and continuous refinement of methods to detect malicious activities across systems and networks.
This instructor-led, live training session (available online or onsite) targets beginner-level cybersecurity professionals seeking to develop practical skills in creating and tuning security detections.
After completing this training, participants will be equipped with the following capabilities:
- Create effective detection rules and signatures using standard security tools.
- Analyze logs and telemetry data to spot suspicious activities.
- Leverage threat intelligence to enhance detection logic.
- Refine alerts and minimize false positives within a Security Operations Center (SOC) environment.
Course Format
- Guided instruction paired with practical demonstrations.
- Scenario-based exercises and hands-on analysis.
- Real-world detection development within an interactive lab setting.
Customization Options
- If your organization requires a customized version of this program, please reach out to us to discuss your specific needs.
Open-Source EDR Fundamentals: Deployment, Detection & Response
14 HoursOpenEDR is an open-source endpoint detection and response platform designed to deliver continuous telemetry, detection, and analysis of hostile activity on endpoint devices.
This guided, live training (available online or onsite) targets beginner to intermediate IT and security professionals seeking to deploy, configure, and operate OpenEDR to detect and respond to cyber threats.
Upon completing this training, participants will be able to:
- Deploy and configure OpenEDR agents and server components to collect telemetry.
- Conduct basic detection and monitoring using OpenEDR dashboards and event views.
- Analyze endpoint events to identify suspicious activity and potential threats.
- Integrate OpenEDR alerts into incident response workflows and reporting processes.
Course Format
- Interactive lectures and discussions.
- Numerous exercises and practice sessions.
- Hands-on implementation within a live-lab environment.
Course Customization Options
- To request customized training for this course, please contact us to arrange.
Mastering Open-Source EDR & Mitre ATT&CK for Threat Hunting
21 HoursOpenEDR is an open-source endpoint detection and response platform that offers analytical detection capabilities with MITRE ATT&CK visibility for real-time event correlation and root cause analysis of adversarial activity.
This instructor-led training, available either online or onsite, is designed for advanced-level SOC analysts, threat hunters, and incident responders who want to design and operate threat-hunting programs using OpenEDR while mapping detections to the MITRE ATT&CK framework.
Upon completing this training, participants will be able to:
- Deploy and configure OpenEDR agents and server components to enable telemetry collection and analysis.
- Map observable endpoint telemetry to MITRE ATT&CK techniques and construct corresponding detection logic.
- Design and execute threat-hunting workflows that leverage behavioral analytics and event correlation to identify adversarial activity.
- Integrate OpenEDR findings into incident response playbooks and conduct root cause analysis.
Format of the Course
- Interactive lecture and discussion.
- Numerous exercises and practice sessions.
- Hands-on implementation within a live-lab environment.
Course Customization Options
- To request customized training for this course, please contact us to arrange it.