YoVDO

Becoming a Dark Knight: Adversary Emulation Demonstration for ATT&CK Evaluations

Offered By: Ekoparty Security Conference via YouTube

Tags

Adversary Emulation Courses Cybersecurity Courses Advanced Persistent Threats Courses Lateral Movement Courses Cyber Threat Intelligence Courses Malware Development Courses Process Injection Courses MITRE ATT&CK Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore adversary emulation techniques in this 55-minute conference talk from Ekoparty Security Conference. Learn how the MITRE ATT&CK Evaluations team improves cybersecurity by studying advanced threat actors, developing scenarios, and executing operations against major EDR vendors. Discover the process of merging cyber threat intelligence (CTI) and red team development capabilities, using a Latin American APT as an example. Follow along as speakers demonstrate evaluating technical reports, building scenarios, creating CTI diagrams, and addressing data gaps. Gain insights into the collaboration between CTI and red teams, including malware development, tool creation, and infrastructure setup. Understand the implementation of techniques like process injection, persistence, hands-on-keyboard discovery, and lateral movement. Learn how to launch attacks, analyze defender responses, and uncover attack patterns. Access publicly released code, research, and emulation plans to enhance your own defensive strategies using the "become the villain" methodology.

Syllabus

Becoming a Dark Knight: Adversary Emulation Demonstration for ATT&CK Evaluations -K. Esprit/ C. Self


Taught by

Ekoparty Security Conference

Related Courses

Penetration Testing, Threat Hunting, and Cryptography
IBM via Coursera
Advanced Cyber Threat Intelligence
Cybrary
Intro to Cyber Threat Intelligence
Cybrary
MITRE ATT&CK Defenderā„¢ (MAD) ATT&CKĀ® Cyber Threat Intelligence Certification Training
Cybrary
Cyber Threat Intelligence
IBM via Coursera