Course Overview:

TechNow’s TN-911: Cyber Threat Intelligence (CTI) Analysis and 800-172 Updates Seminar, is a one day seminar that covers the objectives of TechNow’s TN-905: Cyber Threat Intelligence Analysis five day course in a one day seminar format plus some other security enhancements of 800-172.  Upon request, this seminar can be presented in multi-day format based upon the depth of knowledge required. The NIST PUB 800-172 security enhancement update to 800-171 regarding 03.11.1 Risk Assessment, introduces the security enhancements of a Threat Awareness Program, Threat Hunting, and Predictive Cyber Analytics.  TN-911 distills the TN-905 CTI five day course and aligns it to assessing compliance with 800-172.  For the seminar, selected course labs are converted to demos, and the important points and outcomes of topics are presented. The TN-911 CTI Seminar discusses the applicability of the 800-172 security enhancements to the organization being assessed, and how to think about the the appropriate strength of the controls related to the organizations criticality of the information and the risk involved for contracted work with the DoD.

TechNow’s TN-911: Cyber Threat Intelligence Analysis Seminar addresses significant changes that have been made to SP 800-172 in transitioning to Revision 3, regarding new enhanced security requirements based on (1) the latest threat intelligence and (2) empirical data from cyber-attacks.  With the intent of addressing CUI that may be associated with a critical program or a high value asset.

Those programs and assets are potential targets for advanced persistent threat (APT).  Cyber Threat Intelligence supports the required functions of NIST 800-172 of Penetration Resistant Architecture (PRA), Damage Limiting Operations (DLO) and Cyber Resiliency (CRS).

Regarding 800-172 This seminar includes:

  • 3.2.1E Awareness Training (rev 3 – Advanced Literacy and  Awareness Training)
  • 3.11.6E Supply Chain Risk Management SCRM (rev 3 withdrawn, moved to other controls)
  • 3.11.7E SCRM Planning (rev 3 withdrawn, moved to other controls)
  • 3.12.1E Penetration Testing
  • 800-172, 3.11 Risk Assessment
    • 03.11.01E Threat Awareness Program
    • 03.11.02E Threat Hunting
    • 03.11.03E Predictive Cyber Analytics.

TN-911 CTI Seminar directly discusses 3.11 topics:

    03.11.01E Threat Awareness Program:

    Share threat information, including threat events of 03.11.01E is specifically covered as:

  • Create Indicators of Compromise (IOCs) using STIX
  • Understand a solution for collecting, storing, distributing and sharing cyber security indicators and threats about cyber security incidents analysis and malware analysis.
  • How to assess an environment to validate:
    • Support for day-to-day operations to share structured threat information efficiently.
    • Confirming the presence of curated, frequently updated feeds, and the automation of enrichment   workflow
    • Contextualization of intelligence with internal data to prioritize alerts and improve detection
    • Updated threat hunting based upon inbound Threat Intelligence

    03.11.02E Threat Hunting:

    Introduction to Threat Hunting practices to effectively search for indicators of compromise and to detect, track, and disrupt threats that evade existing controls.

  • How to assess an environment to validate:
  • A formalized process is being followed for Threat Hunting
    • Phases of trigger (incident or CTI), SIEM utilization, and response
  • Integration of machine learning to provide proactive, automated, and scalable Threat Hunting
  • Leveraging threat intelligence for proactive threat hunting by querying historical logs for indicators of compromise (IOCs) from feeds to identify:
  •  Dormant threats
  •  Advance Persistent Threats (APT)

    03.11.03E Predictive Cyber Analytics

    Introduction leveraging data, machine learning, and real-time analysis with automation to anticipate threats before they occur.

  • How to assess an environment to validate:
    • Data aggregation from network logs, user activities, system logs, and external threat intelligence feeds into a centralized platform like a SIEM
  • Use of machine learning algorithms to identify patterns, uncover correlations, and spot anomalies in real-time
  • Integration with incident response workflows
  • Staff skill competency level and integration into Predictive Cyber Analytics to mitigate advanced adversarial techniques against machine learning such as:
    • Attacks of Evasion, Poisoning, and Model Tampering
    • Utilization of exercises or Red Teaming to validate practices and effectiveness of Predictive Cyber Analytics.

    3.2.1E Awareness Training (rev 3 – Advanced Literacy and  Awareness Training)

  •       Validate that training addresses APT

    3.11.6E Supply Chain Risk Management SCRM (rev 3 withdrawn, moved to other controls)

      Validate cybersecurity supply chain risk management C-SCRM:

  • Cross-functional team responsible for supply chain risk management (SCRM) and C-SCRM
  • Validating standard risk management with respect to supply chain
    • FARM (Frame, Assess, Respond, and Monitor)
    • Tasks outlined in NIST Pub 800-161

    3.11.7E SCRM Planning (rev 3 withdrawn, moved to other controls)

  • This is discussed in topic 3.11.6E

    3.12.1E Penetration Testing

        Validate the organization is progressing through standardized Penetration Testing Protocols.

  • Evaluate Penetration Test reports for completeness and scope.

Attendees to TN-911: Cyber Threat Intelligence (CTI) Analysis and 800-172 Seminar will receive TechNow approved course materials and expert instruction.

Seminar Duration: 1 day (more upon request)

Seminar Objectives:

  • Learn to comprehend and develop complex scenarios
  • Identify and create intelligence requirements through practices such as threat modeling
  • Utilize threat modeling to drive intelligence handling and practices 
  • Breakdown tactical, operational, and strategic-level threat intelligence
  • Generate threat intelligence to detect, respond to, and defeat focused and targeted threats
  • How to collect adversary information creating better value CTI
  • How to filter and qualify external sources, mitigating low integrity intelligence
  • Create Indicators of Compromise (IOCs) in STIX
  • Move security maturity past IOCs into understanding and countering the behavioral tradecraft of threats
  • Breaking down threats mapped against their tradecraft to tweak IOCs
  • Establish structured analytical techniques to be successful in any security role
  • Learn and apply structured principles in support of CTI and how to communicate that to any security role.

Seminar Prerequisites:

 
 

Course Overview:

PERL programmers need a clear roadmap for improving their skills. Intermediate PERL teaches a working knowledge of PERL's objects, references, and modules — all of which makes the language so versatile and effective. This class offers a thorough introduction to intermediate programming in PERL. Topics include packages and namespaces, references and scoping, manipulating complex data structures, writing and using modules, package implementation, and using CPAN.

Attendees to P-315: Intermediate PERL Programming will receive TechNow approved course materials and expert instruction.

Dates/Locations:

No Events

Duration: 5 Days

Course Objectives:

  • Packages and namespaces
  • References and scoping
  • Manipulating complex data structures
  • Object-oriented programming
  • Writing and using modules
  • Testing PERL code
  • Contributing to CPAN

Prerequisites:

 

Comments

Latest comments from students


User: J Masters

Instructor comments: Instructor kept it interesting and brought a wealth of knowledge to the classroom environment. Kept a good pace and provided relevant examples.


 

Liked the class?  Then let everyone know!

Privacy Policy

Effective Date: August 1, 2026

TechNow, Inc. respects the privacy of our students and visitors to our website and is committed to protecting the information entrusted to us.

This Privacy Policy explains what information we collect, how we use it, how we protect it, and the circumstances under which it may be disclosed.

1. Information We Collect

We may collect information necessary to provide and administer our educational courses and related services.

This information may include:

  • Name
  • Mailing or billing address
  • Telephone or mobile phone number
  • Email address
  • Course enrollment information
  • Student account information
  • Course progress and quiz activity
  • Information necessary to process course registration and payment
  • Communications between the student and our organization concerning course administration

We collect only information that is reasonably necessary to operate our courses, administer student accounts, communicate with students, and provide related services.

2. How We Use Student Information

We use student information solely for legitimate business and educational purposes related to the delivery and administration of our courses.

This may include:

  • Registering students for courses
  • Creating and maintaining student accounts
  • Providing access to course materials and quizzes
  • Communicating course schedules and changes
  • Sending course reminders and administrative notifications
  • Communicating logistical information necessary for a course
  • Communicating urgent or emergency information related to the delivery of a course
  • Responding to student questions and requests
  • Administering payments and registrations
  • Maintaining records necessary to operate our business and educational programs
  • Providing technical support for our student platform
  • Protecting the security and integrity of our systems

3. No Sale or Marketing Use of Student Contact Information

We do not sell, rent, lease, or otherwise provide student telephone numbers, mobile phone numbers, email addresses, or other student contact information to third parties for their own marketing, advertising, lead generation, or sales purposes.

We do not use student contact information to conduct unrelated marketing campaigns.

We do not sell or exchange student contact information for leads, affiliate marketing, or other commercial marketing purposes.

Our communications with students are limited to information reasonably related to their enrollment, courses, student accounts, course logistics, and urgent or emergency matters associated with delivering a course.

4. SMS Text Messaging

Student SMS Notifications

We may use SMS text messaging to communicate with students who have student accounts associated with our courses.

We only take registrations over the phone and when asked for a preferred phone number you were asked: “Would you like to receive course-related text messages at this mobile number?”  This is to initiate automated communications.  Once logged into the TechNow Quiz Platform there is a button at the top of your dashboard “SMS: on“, with a mouse hover text tooltip of “You are currently enrolled to receive SMS notifications about your student account and courses. PRESS TO DISABLE SMS”.  If you press the button it becomes “SMS: off“, with a mouse hover text tooltip of “You are currently NOT enrolled to receive SMS notifications about your student account and courses. PRESS TO ENABLE SMS”.  Changes of “SMS: off” and “SMS:on” are logged as text messaging Opt-Out and Opt-in.

SMS messages are used for course-related and administrative communications, not marketing or promotional campaigns.  Most TechNow communications is through email, SMS is used for time critical and emergency communications.

Examples of SMS communications may include:

  • Student account notifications
  • Course enrollment or welcome notifications
  • Course reminders
  • Class schedule information
  • Schedule changes
  • Class cancellations
  • Location or logistical information
  • Instructor or course-related administrative notifications
  • Urgent or emergency information related to the delivery of a course
  • Other communications reasonably necessary to administer a student’s participation in a course

We do not use student SMS messaging to send advertising, promotional offers, sales messages, or unrelated marketing communications.

SMS Consent

Students who elect to receive SMS messages authorize TechNow, Inc. to send course-related and administrative text messages to the mobile telephone number provided by the student.

SMS consent is not a condition of purchasing or enrolling in a course.

Message frequency varies depending on course enrollment, account activity, and circumstances requiring course-related communication. Message and data rates may apply.

Opting Out of SMS Messages

Students may disable SMS notifications through the SMS settings available within their student dashboard.

Students may also reply STOP to an SMS message to request that SMS messaging be discontinued.

After an SMS opt-out request is received, our platforms prevent additional SMS messages from being sent to that telephone number.

A student may request assistance regarding SMS messaging by replying HELP where supported or by contacting us using the contact information provided on our website.

Disabling SMS notifications does not prevent a student from accessing their student account or participating in a course. Students who disable SMS may still receive important information through other available communication methods when necessary.

SMS Information Is Not Sold or Shared for Marketing

We do not sell, rent, or share mobile telephone numbers or SMS consent information with third parties for their own marketing or advertising purposes.

SMS consent information is used solely for administering our student communication program and providing the course-related communications described in this Privacy Policy.

5. TechNow Does NOT Share Information With Service Providers

Unlike most companies, TechNow does not use third-party service providers  to operate our business, we are a SELF HOSTED company.

For example, we internally self host:

  • Website
  • Student-platform
  • Email
  • Information technology and security
  • Database and infrastructure services

TechNow interacts with a Bank for Payment Processing and with a trusted SMS provider for SMS delivery.   A student’s mobile telephone number and message information may be transmitted through our trusted SMS service provider solely to deliver the requested or authorized course-related communication.

6. Course Platform Information

Students may receive an account on our course and quiz platform.

Information associated with a student account may include:

  • Login credentials
  • Course enrollment
  • Quiz and assessment activity
  • Course progress
  • Account settings
  • Communication preferences
  • SMS preferences

This information is used to provide and administer the student’s courses and account.

7. Payment Information

When payment is required for a course, payment information may be processed through a third-party payment processor.

We do not retain payment-card information on our student quiz platform unless specifically stated otherwise.

Payment processors may collect and process payment information according to their own privacy policies and security practices.

8. Cookies and Technical Information

Our website and student platform may use cookies, session information, logs, and similar technical mechanisms necessary to:

  • Maintain authenticated sessions
  • Keep students logged into their accounts
  • Provide website and application functionality
  • Maintain security
  • Detect and prevent unauthorized access
  • Diagnose technical problems
  • Improve the reliability of our services

We do not use student contact information for third-party advertising or behavioral marketing.

9. Information Security

We take reasonable administrative, technical, and organizational measures to protect student information against unauthorized access, alteration, disclosure, or destruction.

No method of storing or transmitting information over the Internet can be guaranteed to be completely secure. We therefore cannot guarantee absolute security of information.

10. Retention of Information

We retain student information for as long as reasonably necessary to provide our services, administer courses and student accounts, maintain appropriate business records, comply with legal or regulatory obligations, resolve disputes, and protect our rights and systems.

When information is no longer reasonably necessary for these purposes, we may securely delete or otherwise dispose of it.

11. Children’s Privacy

Our courses and services are intended for the individuals described by our course enrollment requirements. We do not knowingly collect personal information from children in violation of applicable law.

If you believe that a child has provided personal information to us without appropriate authorization, please contact us.

12. Third-Party Websites

Our website may contain links to websites or services operated by third parties.

We are not responsible for the privacy practices, content, or security of third-party websites. We encourage users to review the privacy policies of those websites before providing personal information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, business practices, or legal requirements.

When we make changes, we will update the Effective Date shown at the beginning of this Privacy Policy.

14. Contact Us

If you have questions about this Privacy Policy, your personal information, or our SMS messaging practices, please contact us:

TechNow Inc.
14117 Jones Maltsberger Rd
San Antonio, TX 53578
210 733-1093
technow-training@technow.com
technow.com

Effective Date: August 1, 2026

in   

CCFE Core Competencies

  • Procedures and Legal Issues
  • Computer Fundamentals
  • Partitioning Schemes
  • Data Recovery
  • Windows File Systems
  • Windows Artifacts
  • Report writing (Presentation of Finding)
  • Procedures and Legal issues
  1. Knowledge of search and subjection and rules for evidence as applicable to computer forensics.
  2. Ability to explain the on-scene action taken for evidence preservation.
  3. Ability to maintain and document an environment consolidating the computer forensics.
  • Computer Fundamentals
  1. Understand BIOS
  2. Computer hardware
  3. Understanding of numbering system (Binary, hexadecimal, bits, bytes).
  4. Knowledge of sectors, clusters, files.
  5. Understanding of logical and physical files.
  6. Understanding of logical and physical drives.
  • Partitioning schemes
  1. Identification of current partitioning schemes.
  2. Understanding of primary and extended partition.
  3. Knowledge of partitioning schemes and structures and system used by it.
  4. Knowledge of GUID and its application.
  • Windows file system
  1. Understanding of concepts of files.
  2. Understanding of FAT tables, root directory, subdirectory along with how they store data.
  3. Identification, examination, analyzation of NTFS master file table.
  4. Understanding of $MFT structure and how they store data.
  5. Understanding of Standard information, Filename, and data attributes.
  • Data Recovery
  1. Ability to validate forensic hardware, software, examination procedures.
  2. Email headers understanding.
  3. Ability to generate and validate forensically sterile media.
  4. Ability to generate and validate a forensic image of media.
  5. Understand hashing and hash sets.
  6. Understand file headers.
  7. Ability to extract file metadata from common file types.
  8. Understanding of file fragmentation.
  9. Ability to extract component files from compound files.
  10. Knowledge of encrypted files and strategies for recovery.
  11. Knowledge of Internet browser artifacts.
  12. Knowledge of search strategies for examining electronic
  • Windows Artifacts
  1. Understanding the purpose and structure of component files that create the windows registry.
  2. Identify and capability to extract the relevant data from the dead registry.
  3. Understand the importance of restore points and volume shadow copy services.
  4. Knowledge of the locations of common Windows artifacts.
  5. Ability to analyze recycle bin.
  6. Ability to analyze link files.
  7. Analyzing of logs
  8. Extract and view windows logs
  9. Ability to locate, mount and examine VHD files.
  10. Understand the Windows swap and hibernation files.
  • Report Writing (Presentation of findings)
  1. Ability to conclude things strongly based on examination observations.
  2. Able to report findings using industry standard technically accurate terminologies.
  3. Ability to explain the complex things in simple and easy terms so that non-technical people can understand clearly.
  4. Be able to consider legal boundaries when undertaking a forensic examination

Course Overview:

This course is designed for professionals that are expected to do malware analysis. A skills focus enables the student to better absorb the subject matter and perform successfully on the job.   This is not death by power point. The course is aligned with information assurance operators and executing hands-on labs. Lecture and labs walk the student through the knowledge required to truly understand the mechanics Reverse Engineering Malware.

Attendees to TN-999: Reverse Engineering Malware will receive TechNow approved course materials and expert instruction.

Date/Locations:

No Events

Duration: 5 days

Course Objectives:

  • Toolkit and Lab Assembly
  • Malware Code and Behavioral Analysis Fundamentals
  • Malicious Static and Dynamic Code Analysis
  • Collecting/Probing System and Network Activities
  • Analysis of Malicious Document Files
  • Analyzing Protected Executables
  • Analyzing Web-Based Malware
  • DLL Construction and API Hooking
  • Common Windows Malware Characteristics in x86 Assembly
  • Unpacking Protected Malware
  • In-Depth Analysis of Malicious Browser Scripts, Flash Programs and Office
  • In-Depth Analysis of Malicious Executables
  • Windows x86 Assembly Code Concepts for Revers-Engineering Memory Forensics for Rootkit Analysis

Prerequisites:

  • Strong understanding of core systems and network concepts
  • Exposure to programming and assembly concepts
  • Comfortable with command line access

Comments

Latest comments from students



User: marcus.osullivan

Instructor comments: Good stuff. I like the beginning half where there was help from an additional instructor to facilitate fixing computer errors that inevitably popped up.

Facilities comments: The baby deer were neat! I like the resort.


Liked the class?  Then let everyone know!