Infosec Skills Challenge: June 2022 *RSA special edition* Course

1 hour, 30 minutes

Syllabus

Sandworm APT Lab 2

Lab - 00:30:00

Sandworm APT is an advanced hacking group that has been active since at least 2009. Most famous for their attacks on Ukrainian electrical companies and the NotPetya attacks in 2016, they are a Russian-backed threat group. In this lab we’ll take a look at and emulate some of the techniques that Sandworm has used in the past to compromise, pivot from, and destroy a server.
Common Attack Types - Insecure Direct Object Reference (IDOR) & Directory Traversal

Lab - 00:30:00

This lab walks a user through an example of Insecure Direct Object Referencing and Directory TraversalInsecure direct object reference (IDOR) is a type of access control vulnerability that occurs when an application exposes a direct reference to an internal object. Finding an IDOR allows attackers to enumerate and extract other information.Directory traversal (also known as file path traversal) is a web security vulnerability that allows an attacker to access restricted directories on the server. The directories can contain anything from application code and credentials for back-end systems to sensitive operating system files. In case read and write permissions are not correctly set, attackers can modify the files and ultimately take full control of the server.
Cyber Threat Hunting - Finding Threats in .vmem Files

Lab - 00:30:00

In this lab you will examine a vmem file for threats using volatility3, the world's most widely used framework for extracting digital artifacts from volatile memory (RAM) samples.

Unlock 7 days of free training

  • 1,400+ hands-on courses and labs
  • Certification practice exams
  • Skill assessments

Plans & pricing

Infosec Skills Personal

$299 / year

  • 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Custom certification practice exams (e.g., CISSP, Security+)
  • Skill assessments
  • Infosec peer community support

Infosec Skills Teams

$799 per license / year

  • Team administration and reporting
  • Dedicated client success manager
  • Single sign-on (SSO)
    Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
  • Integrations via API
    Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
  • 190+ role-guided learning paths and assessments (e.g., Incident Response)
  • 100s of hands-on labs in cloud-hosted cyber ranges
  • Create and assign custom learning paths
  • Custom certification practice exams (e.g., CISSP, CISA)
  • Optional upgrade: Guarantee team certification with live boot camps

Learn about scholarships and financing with

Affirm logo

Award-winning training you can trust