Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Certified Advanced Persistent Threat Analyst
Rating: 4.0 out of 5(205 ratings)
1,601 students

Certified Advanced Persistent Threat Analyst

Learn to intelligently detect and take down advanced cyber threats
Last updated 6/2017
English

What you'll learn

  • Have a high level overview of Advanced Persistent Threts
  • Understand The APT Lifecycle
  • Overview of APT1
  • Overview of Stuxnet
  • Equation Group
  • Automated String Decoding
  • Binary Instrumentation
  • Immunity Debugger PyCommands
  • Windows Kernel Drivers Analysis

Course content

4 sections58 lectures7h 29m total length
  • Advanced Persistent Threat Defender Course Intro5:14

    Explore advanced persistent threats (APTs), their life cycle, and modern malware techniques used to persist and evade defenses. Discover mitigation strategies, key groups, and examples like Stuxnet, Adwin, and Poseidon.

  • APT Overview Part 16:14

    Explore what an advanced persistent threat is: a state-sponsored, targeted cyber attack on a specific organization that persists for years, uses zero-days and sophisticated malware across multiple vectors, evading detection.

  • APT Overview Part 25:01

    Identify how persistence lets an apt stay undetected inside networks for long periods. See why antiviruses, firewalls, and IDS miss it, as security products rely on information banks and probing.

  • APT Overview Part 36:44

    Explore high-profile cases like the Sony Pictures leak that damaged trust and movie sales, and learn how sophisticated malware like Stuxnet targeted nuclear facilities to cripple centrifuges.

  • APT Overview Part 48:04

    Identify how APTs target any sector, from government to finance, using zero-day exploits to infiltrate high-value organizations and maintain stealthy, long-term persistence with C2.

  • APT Overview Part 57:37

    Explains how APTs connect to their command and control servers, attach to existing processes via malware injection, and stay stealthy to avoid detection while exfiltrating data securely.

  • Mr. Robot Threat Capabilities21:02

    Explore advanced persistent threat concepts through Mr. Robot demonstrations, learning the threat lifecycle and kill chain—from reconnaissance to actions on objectives—using real-world lab examples.

  • Cyber Kill Chain & APT Lifecycle Part 19:48

    Explore the cyber kill chain and advanced persistent threat life cycle, including reconnaissance, weaponization with malware, and delivery, and learn how spear phishing and USB delivery enable broad campaigns.

  • Cyber Kill Chain & APT Lifecycle Part 29:11

    Explore the cyber kill chain from exploitation to actions on objectives, highlighting vulnerabilities, zero days, installation, and command and control, and outline the APT lifecycle from reconnaissance to initial compromise.

  • Cyber Kill Chain & APT Lifecycle Part 39:03
  • Cyber Kill Chain & APT Lifecycle Part 411:50

    Explain internal reconnaissance through open source intelligence gathering from social profiles and public sites, mapping targets, and selecting initial access methods like phishing and water hole attacks.

  • Cyber Kill Chain & APT Lifecycle Part 510:29

    Learn how attackers establish a foothold in the cyber kill chain and apt threats, using backdoors and staged malware to bypass security through ssl and chunked downloads.

  • Cyber Kill Chain & APT Lifecycle Part 66:56

    Explore how attackers escalate privileges after gaining a foothold, dump password hashes, perform pass-the-hash and hash injection, and move laterally within a network via admin accounts and Active Directory.

  • Cyber Kill Chain & APT Lifecycle Part 710:25

    Describe internal reconnaissance in an apt lifecycle: map services, databases (sql nosql), and user access. Explain stealthy lateral movement to access privileged accounts using hashes and remote tools like psexec.

  • Cyber Kill Chain & APT Lifecycle Part 85:45
  • APT1 Overview9:37

    Explore APT1, a state-sponsored Chinese military unit 61398 discovered by Mandiant in 2010, known for espionage campaigns that steal intellectual property and target hundreds of victims.

  • Stuxnet Overview Part 19:48

    Stuxnet, an advanced persistent threat, targeted PLCs to damage physical infrastructure, spreading via USB with zero-day exploits and digitally signed malware using stolen certificates to infect Iran's nuclear facility.

  • Stuxnet Overview Part 210:26

    Stuxnet describes a joint U.S.-Israel operation targeting Iran's Natanz facility, using stealthy USB infections to alter Siemens PLC software and physically destroy centrifuges while evading detection.

  • Stuxnet Overview Part 36:05

    Explore Stuxnet, Doku and Flame alongside the Equation Group to understand how zero-day exploits and information stealing spread worldwide, linking espionage, USB propagation, and hard disk firmware tactics.

  • Cyberwar: New Domain of Warfare10:50

    Explore cyber warfare as the new domain of warfare. Learn how a zero-day exploit, spear phishing, and state-sponsored APT groups fuel this cyber world war.

  • Quiz 1: Understanding APTs

Requirements

  • Familiar with cyber exploits and breaches that have occurred in the public

Description

Cyber-attacks have become so sophisticated over the years, that a new term has emerged - Advanced Persistent Threat, which we will refer to as APT. An APT is a group of individuals that have both the means and the intent to launch persistent attacks against specific targets. Understanding these groups and their behavior is important when evaluating threats against any organization.

Hackers have traditionally targeted large corporations, but today small to midsize businesses are being attacked with the same type of highly sophisticated malware. These new strains of advanced malware are often referred to as APTs

Modern malware uses Advanced techniques such as encrypted communication channels, kernel-level rootkits, and sophisticated evasion capabilities to get past a network’s defenses. More importantly, they often leverage zero day vulnerabilities – flaws for which no patch is available yet and no signature has been written.

Modern malware is often Persistent and designed to stick around. It’s stealthy and carefully hides its communications. It lives in a victim’s network for as long as possible, often cleaning up after itself by deleting logs, using strong encryption, and only reporting back to its controller in small, obfuscated bursts of communication.

Many attacks are now blended combinations of different techniques. A common tactic for hackers is to initiate an APT with spear phishing. This involves sending a carefully crafted email that appears to be in the from of a known individual or business with a link to a malicious website or an infected download. 

Once the initial breach is successful, attackers can further damage defenses by disabling security protocols, changing security settings or stealing passwords. Groups of highly skilled, motivated, and very well-funded attackers represent significant Threats because they have very specific targets and goals in mind – often financial gain from theft of credit cards and other valuable account information.

Here are the topics that we will be covering in this course. We will begin by going over the APT Lifecycle and teach you a structured approach to analyze and assess inherent vulnerabilities. We will teach you mitigation and countermeasures that may prevent an attacker from gaining a foothold into an organization.

Next, we will get you familiar with APT1 Group and some common ATPs we have seen in the last few years like Stuxnet, and two new ones, Adwind and Poseidon. Lastly, we will get you familiar with the Cyber World War.

 

Who this course is for:

  • anyone interested in preventing cyber attacks