Module 12 Overview
April 5-11 · Reading: 16 pages · Estimated total: 7 hours
Two questions this week, and they are different questions.
What is the malware? CyBOK §6 gives you a taxonomy (standalone or host-dependent, persistent on disk or transient in memory, user-activated or auto-spreading) and a survey of how malware is analyzed and detected.
What did the people do? CyBOK §7 is about operations rather than code: the elements of a malicious operation, how it is organized, and what motivates it. This is the more useful frame most of the time, because modern intrusions increasingly involve very little malware. The operators in this week's case moved between machines for six days using tools that were already installed.
The shared vocabulary for the second question is MITRE ATT&CK, and learning to use it is the practical skill of the week.
You will not download, run, or analyze malware in this course. You analyze a written record of an incident, which is what most security work actually consists of.
Learning Objectives
By the end of this week, the successful student will be able to:
- 4.3: Classify malware by the CyBOK taxonomy and map an incident's observed behavior, including phishing used for initial access, to MITRE ATT&CK techniques.
Assignments and Tasks
Due by Sunday at 11:59 p.m. Mountain Time
- Read 12.01 Readings and Lecture Notes and work through the worked example (3 hrs)
- 12.02 Lab 7: Malware Triage Without Malware (1 hr 35 min, 38 points)
Read the incident report all the way through once before you start mapping. The last section ("What was never established") matters as much as the rest.
Time Estimate
| Activity | Time |
|---|---|
| Reading (16 pages plus browsing ATT&CK) | 2 hrs 20 min |
| The notes page and the worked example | 40 min |
| Lab 7 | 1 hr 35 min |
| Review and slack | 2 hrs 15 min |
| Total | ~7 hrs |