MITRE ATT&CK Training Course
MITRE ATT&CK serves as a comprehensive framework of tactics and techniques designed to classify cyberattacks and evaluate an organization's risk profile. This framework enhances organizational security awareness by identifying vulnerabilities in defenses and helping to prioritize risks.
This instructor-led, live training (available online or onsite) is tailored for information system analysts seeking to leverage MITRE ATT&CK to mitigate the risk of security breaches.
Upon completion of this training, participants will be equipped to:
- Establish the necessary development environment to begin implementing MITRE ATT&CK.
- Categorize the ways attackers interact with systems.
- Document adversary behaviors observed within systems.
- Monitor attacks, decode patterns, and evaluate the effectiveness of existing defensive tools.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practice sessions.
- Hands-on implementation within a live-lab environment.
Customization Options
- To request a customized training session for this course, please contact us to make arrangements.
Course Outline
Introduction
What is Malware?
- Types of malware
- The evolution of malware
Overview of Malware Attacks
- Propagating
- Non-propagating
Matrices of ATT&CK
- Enterprise ATT&CK
- Pre-ATT&CK
- Mobile ATT&CK
MITRE ATT&CK
- 11 tactics
- Techniques
- Procedures
Preparing the Development Environment
- Setting up a version control center (GitHub)
- Downloading a project that hosts a to-do list system of data
- Installing and configuring ATT&CK Navigator
Monitoring a compromised system (WMI)
- Instating command line scripts to conduct a lateral attack
- Utilizing ATT&CK Navigator to identify the compromise
- Assessing the compromise through the ATT&CK framework
- Performing process monitoring
- Documenting and patching the holes in the defense architecture
Monitoring a compromised system (EternalBlue)
- Instating command line scripts to conduct a lateral attack
- Utilizing ATT&CK Navigator to identify the compromise
- Assessing the compromise through the ATT&CK framework
- Performing process monitoring
- Documenting and patching the holes in the defense architecture
Summary and Conclusion
Requirements
- A solid understanding of information system security
Audience
- Information systems analysts
Open Training Courses require 5+ participants.
MITRE ATT&CK Training Course - Booking
MITRE ATT&CK Training Course - Enquiry
MITRE ATT&CK - Consultancy Enquiry
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent
Manar Abu Talib - Dubai Electronic Security Center
Course - MITRE ATT&CK
Upcoming Courses
Related Courses
AI-Powered Cybersecurity: Threat Detection & Response
21 HoursThis instructor-led, live training South Korea (online or onsite) is designed for beginner-level cybersecurity professionals who want to learn how to leverage AI to improve threat detection and response capabilities.
By the end of this training, participants will be able to:
- Understand AI applications in cybersecurity.
- Implement AI algorithms for threat detection.
- Automate incident response with AI tools.
- Integrate AI into existing cybersecurity infrastructure.
AI-Powered Cybersecurity: Advanced Threat Detection & Response
28 HoursThis instructor-led, live training in South Korea (online or onsite) targets cybersecurity professionals at the intermediate to advanced levels who seek to enhance their skills in AI-driven threat detection and incident response.
By the end of this training, participants will be able to:
- Deploy advanced AI algorithms for real-time threat detection.
- Tailor AI models to address specific cybersecurity challenges.
- Create automation workflows for effective threat response.
- Protect AI-driven security tools from adversarial attacks.
Blue Team Fundamentals: Security Operations and Analysis
21 HoursProvided as instructor-led, live training in South Korea (online or onsite), this program is aimed at intermediate-level IT security professionals who wish to develop skills in security monitoring, analysis, and response.
By the end of this training, participants will be able to:
- Understand the role of a Blue Team in cybersecurity operations.
- Use SIEM tools for security monitoring and log analysis.
- Detect, analyze, and respond to security incidents.
- Perform network traffic analysis and threat intelligence gathering.
- Apply best practices in security operations center (SOC) workflows.
Bug Bounty Hunting
21 HoursBug Bounty Hunting involves finding security weaknesses in software, websites, or systems and responsibly reporting them to receive rewards or recognition.
This instructor-led, live training (available online or onsite) is designed for beginner-level security researchers, developers, and IT professionals who want to learn the fundamentals of ethical bug hunting and how to participate in bug bounty programs.
By the end of this training, participants will be able to:
- Understand the core concepts of vulnerability discovery and bug bounty programs.
- Use key tools like Burp Suite and browser dev tools for testing applications.
- Identify common web security flaws such as XSS, SQLi, and CSRF.
- Submit clear, actionable vulnerability reports to bug bounty platforms.
Format of the Course
- Interactive lecture and discussion.
- Hands-on use of bug bounty tools in simulated testing environments.
- Guided exercises focused on discovering, exploiting, and reporting vulnerabilities.
Course Customization Options
- To request a customized training for this course based on your organization's applications or testing needs, please contact us to arrange.
Bug Bounty: Advanced Techniques and Automation
21 HoursThe 'Bug Bounty: Advanced Techniques and Automation' course offers an in-depth exploration of high-impact vulnerabilities, automation frameworks, reconnaissance strategies, and the tooling methodologies employed by top-tier bug bounty hunters.
This instructor-led, live training session is available both online and onsite. It is designed for intermediate to advanced security researchers, penetration testers, and bug bounty hunters who aim to streamline their workflows, scale their reconnaissance efforts, and identify complex vulnerabilities across various targets.
Upon completion of this training, participants will be equipped to:
- Automate reconnaissance and scanning processes for multiple targets.
- Utilize state-of-the-art tools and scripts essential for bounty automation.
- Identify complex, logic-based vulnerabilities that standard scans often miss.
- Develop custom workflows for subdomain enumeration, fuzzing, and report generation.
Course Format
- Interactive lectures and discussions.
- Practical application of advanced tools and scripting for automation.
- Guided labs focusing on real-world bounty workflows and advanced attack chains.
Customization Options
- For customized training tailored to your specific bounty targets, automation requirements, or internal security challenges, please contact us to arrange a session.
CHFI - Certified Digital Forensics Examiner
35 HoursThe vendor-neutral Certified Digital Forensics Examiner certification is designed to equip Cyber Crime and Fraud Investigators with skills in electronic discovery and advanced investigation techniques. This course is indispensable for anyone who needs to handle digital evidence during investigations.
The training provides the methodology for conducting computer forensic examinations. Students will learn to apply forensically sound investigative techniques to evaluate crime scenes, collect and document relevant information, interview key personnel, maintain the chain of custody, and draft findings reports.
The Certified Digital Forensics Examiner course is beneficial for organizations, individuals, government offices, and law enforcement agencies seeking to pursue litigation, establish proof of guilt, or take corrective action based on digital evidence.
Certified Incident Handler
21 HoursThe Certified Incident Handler course offers a systematic methodology for effectively and efficiently managing and responding to cybersecurity incidents.
Delivered as an instructor-led live training session (available online or onsite), this program targets intermediate-level IT security professionals seeking to acquire the tactical expertise required to plan, classify, contain, and manage security incidents.
Upon completion of this training, participants will be equipped to:
- Comprehend the incident response lifecycle and its various phases.
- Perform incident detection, classification, and notification protocols.
- Implement effective containment, eradication, and recovery strategies.
- Formulate post-incident reports and continuous improvement plans.
Course Format
- Engaging lectures and group discussions.
- Practical application of incident handling procedures within simulated scenarios.
- Instructor-guided exercises emphasizing detection, containment, and response workflows.
Customization Options
- For organizations seeking customized training aligned with their specific incident response procedures or tools, please contact us to arrange.
Mastering Continuous Threat Exposure Management (CTEM)
28 HoursThis instructor-led, live training in South Korea (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to implement CTEM in their organizations.
By the end of this training, participants will be able to:
- Understand the principles and stages of CTEM.
- Identify and prioritize risks using CTEM methodologies.
- Integrate CTEM practices into existing security protocols.
- Utilize tools and technologies for continuous threat management.
- Develop strategies to validate and improve security measures continuously.
Cyber Threat Intelligence
35 HoursThis instructor-led, live training in South Korea (online or onsite) is designed for advanced cybersecurity professionals who wish to understand Cyber Threat Intelligence and acquire skills to effectively manage and mitigate cyber threats.
Upon completion of this training, participants will be capable of:
- Gaining a solid grasp of Cyber Threat Intelligence (CTI) fundamentals.
- Evaluating the current cyber threat landscape.
- Collecting and processing intelligence data effectively.
- Conducting advanced threat analysis.
- Leveraging Threat Intelligence Platforms (TIPs) to automate threat intelligence workflows.
Fundamentals of Corporate Cyber Warfare
14 HoursThis instructor-led, live training in South Korea (online or on-site) covers various aspects of enterprise security, from artificial intelligence to database security. It also addresses the latest tools, processes, and mindsets necessary to protect against attacks.
DeepSeek for Cybersecurity and Threat Detection
14 HoursThis instructor-led, live training in South Korea (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to leverage DeepSeek for advanced threat detection and automation.
By the end of this training, participants will be able to:
- Utilize DeepSeek AI for real-time threat detection and analysis.
- Implement AI-driven anomaly detection techniques.
- Automate security monitoring and response using DeepSeek.
- Integrate DeepSeek into existing cybersecurity frameworks.
Duty Managers Cyber Resilience
14 HoursThis instructor-led, live training in South Korea (online or onsite) is designed for intermediate-level duty managers and operational leaders who aim to develop robust cyber resilience strategies to protect their organizations from cyber threats.
Upon completion of this training, participants will be able to:
- Grasp the fundamentals of cyber resilience and understand their significance to duty management.
- Create incident response plans to maintain operational continuity.
- Identify potential cyber threats and vulnerabilities within their specific environment.
- Apply security protocols to minimize risk exposure.
- Coordinate team responses during cyber incidents and recovery processes.
Junior Detection Engineer Essentials
21 HoursDetection engineering involves the design, implementation, and refinement of techniques to identify malicious activities across various systems and networks.
This instructor-led live training, available online or onsite, is designed for beginner-level cybersecurity professionals seeking to acquire practical skills in creating and tuning security detections.
After completing this training, participants will possess the skills to:
- Create effective detection rules and signatures using standard security tools.
- Analyze logs and telemetry data to spot suspicious behaviors.
- Utilize threat intelligence to enhance detection logic.
- Optimize alerts and reduce false positives within a SOC environment.
Course Format
- Guided instruction accompanied by practical demonstrations.
- Scenario-based exercises and hands-on analysis.
- Real-world detection development in an interactive lab environment.
Customization Options
- If your organization needs a customized version of this program, please contact us to discuss available options.
Open-Source EDR Fundamentals: Deployment, Detection & Response
14 HoursOpenEDR is an open-source endpoint detection and response platform designed to deliver continuous telemetry, detection, and analysis of adversarial activities on endpoints.
This instructor-led live training (available online or onsite) is designed for beginner to intermediate IT and security professionals looking to deploy, configure, and operate OpenEDR to detect and respond to cyber threats.
Upon completion of this training, participants will be able to:
- Deploy and configure OpenEDR agents and server components for telemetry collection.
- Perform basic detection and monitoring using OpenEDR dashboards and event views.
- Analyze endpoint events to identify suspicious activity and potential threats.
- Integrate OpenEDR alerts into incident response workflows and reporting.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practice sessions.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request customized training for this course, please contact us to arrange.
Mastering Open-Source EDR & Mitre ATT&CK for Threat Hunting
21 HoursOpenEDR is an open-source endpoint detection and response platform that provides analytic detection with MITRE ATT&CK visibility for event correlation and root cause analysis of adversarial activity in real time.
This instructor-led, live training (online or onsite) is aimed at advanced-level SOC analysts, threat hunters, and incident responders who wish to design and operate threat-hunting programs using OpenEDR and map detections to the MITRE ATT&CK framework.
Upon completing this training, participants will be able to:
- Deploy and configure OpenEDR agents and server components for telemetry collection and analysis.
- Map observable endpoint telemetry to MITRE ATT&CK techniques and build detection logic accordingly.
- Design and execute threat-hunting workflows that use behavioral analytics and event correlation to identify adversarial activity.
- Integrate OpenEDR findings into incident response playbooks and perform root cause analysis.
Format of the Course
- Interactive lecture and discussion.
- Lots of exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.