After you press "Request Registration" near the bottom of this form, within 30 seconds, status will be provided at the bottom of the form, you will also be contacted by phone for credit card information.

    Tech Now is pleased to have the opportunity to provide you training for "Windows Security Automation and Threat Hunting with PowerShell” at CheddarCon 2018!

    Scroll down to see the course description.

    First Name*

    Last Name*

    Your Email*

    Your Organization*

    Phone*

    Questions:

    After you press "Request Registration" on this form, within 30 seconds, status will be provided at the bottom of the form, you will also be contacted by phone for credit card information.

    Windows Security Automation and Threat Hunting with PowerShell Seminar

    Location: 400 W Wisconsin Ave, Milwaukee, WI 53203, USA

    Date: October 10, 2018 8:00am – 4:00pm

    Duration: 8 hours

    Audience: Cyber Security professionals and Windows administrators

    Attendees Environment: Laptops not required, but suggested to have better hands-on absorption of subject matter.

    Description:
    PowerShell is both a command-line shell and scripting language. Fight fires quickly using existing or custom PowerShell commands or scripts at the shell. PowerShell is made for Security Operations (SecOps) automation on Windows. This seminar does not require prior programming skills. The seminar focuses on PowerShell programming, giving a beginner skills to be productive in windows scripting to automate tasks and also remediate problems.

    Cyber Security is the objective of this seminar, and the PowerShell examples will demonstrate PowerShell capabilities that help lock down a Windows system and also report security status.

    Objectives:

    PowerShell Overview

    • Getting started running commands
    • Security cmdlets
    • Using and updating the built-in help
    • Execution policies
    • Fun tricks with the ISE graphical editor
    • Piping .NET and COM objects, not text
    • Using properties and methods of objects
    • Helping Linux admins feel more at home
    • Aliases, cmdlets, functions, modules, etc.

    PowerShell Utilities and Tips

    • Customizing your profile script
    • PowerShell remote command execution
    • Security setting across the network
    • File copy via PowerShell remoting
    • Capturing the output of commands
    • Parsing text files and logs with regex patterns
    • Parsing Security Logs
    • Searching remote event logs
    • Mounting the registry as a drive
    • Security settings in the Registry
    • Exporting data to CSV, HTML and JSON files
    • Running scripts as scheduled jobs
    • Continued Security Compliance
    • Pushing out scripts through Group Policy
    • Importing modules and dot-sourcing functions
    • http://www.PowerShellGallery.com

    PowerShell Scripting

    • PowerShell Scripting to implement Security Practices
    • Writing your own functions to automate security status and settings
    • Passing arguments into your scripts
    • Function parameters and returning output
    • Flow control: if-then, foreach, that make security decisions
    • How to pipe data in/out of your scripts for security compliance and reporting

    Attendees to this seminar, Windows Security Automation and Threat Hunting with PowerShell, will receive TechNow approved course materials and expert instruction.[/wr_text][/wr_column][/wr_row]

    Course Overview:

    This course is very hands-on with respect to SP 800-53 controls as related to ICD-503, leveraging experience with DCD 6/3, and incorporating a broad array of technologies found in the field.  Assessors and Auditors have to face many technologies that are not part of the main stream.  TechNow has gone to great efforts to build a very broad, comprehensive, and complex lab to simulate many scenarios and architectures.  Technologies such as a network appliance that is not a typical infrastructure product, a radio/satellite communications device, or many other technologies that build up a weapon system.  Students learn how controls are integrated into many different devices and how they fit in the overall security architecture of monitoring, reporting, and compliance testing.

    Directly discussed are overlays for different requirements i.e.: tactical, medical, network type: JWICS, SIPR; IC or AF.  TechNow has developed a funnel concept to overlays to exemplify the encapsulation of a control within different requirements.  TechNow has over 15 years experience in Trusted Solaris/Trusted Extensions and labeled security.  Cross Domain overlays are presented that fits the work flow of an assesor.  PII overlays and any overlays that an organization uses and can be made available are also presented.  

    This course allows the student to leverage years of experience in DoD DCD 6/34 for transition to the Risk Management Framework (RMF) applied to the Intelligence Community as mandated by ICD 503.  Utilizing NIST SP 800-37 to establish a baseline of RMF knowledge, the student learns how to integrate the NIST pubs to provide cohesive information assurance architectures and compliance.  ICD 503 scorecard evaluations are integral in demonstrating a successful ICD 503 compliance program.  TechNow's ICD 503 course provides students with the skill to assess security programs and evaluate ICD 503 compliance to build an improvement and sustainable program for score consistency.  TechNow's instructors have unparralleled expertise in federal compliance initiatives, and we bring this expertise instructing students on the complete life cycle of RMF.

    More than a simple checklist, we instruct students not only how to validate essential security controls, programs, and metrics, but that they are operating effectively.  The student leaves the course knowing how to: identify gaps where controls, programs, or metrics are incomplete, missing or ineffective, and provide actionable findings and recommend remediation strategies.  Students learn to internalize NIST pubs to meaningul and effective IA guidelines and work with the Body of Evidence templates which include: Risk Assessment Report (RAR), Systems Security Plan (SSP), Security Assessment Report (SAR), and Plans of Action and Milestone (POAM).

    TechNow training materials are aligned with the most recent set of National Institute of Standards and Technology (NIST), Committee on National Security Systems (CNSS), and Office of the Director of National Intelligence (ODNI) policies standards, processes, policies and instructions to be addressed/explained include ICD 503, ICS 503-1, ICS 500-16, ICS 500-18, ICS 500-27, ICD 502, NIST SP 800-37, NIST SP 800-30, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-137, NIST SP 800-47, CNSSP 22, CNSSI 1253, and CNSSI 4009.

    A majority of time is spent on in-depth compliance review of NIST SP 800-53 controls.  Instruction discusses which method should be used to test and validate each security control and what evidence should be gathered.  This course is not theory or death by power point.  Real scenarios are presented as exercises.  A complete live cyber range simulating the IC is utilized for hands-on labs for techniques of validating and documenting compliance of NIST SP 800-53 controls as related to ICD 503.

    Date/Locations:

    No Events

    Duration: 5 days

    Course Objectives:

    • Establish a baseline of RMF knowledge
    • Validate essential security controls, programs, and metrics
    • DoD DCD 6/3 to ICD 503 Transition
    • Lab Environtment and the Cyber Range
    • Overlays: Tactical, Medical, Network type(JWICS, SIPR; IC or AF), Cross Domain, PII
    • Risk Assessment Report (RAR)
    • Systems Security Plan (SSP)
    • Security Assessment Report (SAR)
    • Plans of Action and Milestone (POAM)

    Prerequisites:

    Experience in the field of auditing and assesments.

    Comments

    Latest comments from students


    Liked the class?  Then let everyone know!

    Course Overview:

    Linux System Administration II course is for experienced administrators ready for advanced administration topics. This course provides students with hands-on experience working with more complex and integrated administration concepts, and builds upon the Part 1 course. Students will be instructed in essential  local Red Hat system administration skills including: Logical Volumes, Raid Management, and System Logging, SELinux and Virtual Machines.  The Linux System Administration II course will get you started in understanding network administration topics, including monitoring, routing, Firewall with iptables, and servers such as NFS, SAMBA, DNS, SMTP, HTTP, DHCP, and Kickstart.

    Attendees to RH-295: Linux System Administration II will receive TechNow approved course materials and expert instruction.

    Dates/Locations:

    No Events

    Duration: 5 days

    Course Objectives:

    • Managing Logical Volumes and RAID
    • Network Routing, Filtering and Monitoring
    • Configuring File Sharing Across Platforms
    • Configuring Internet Services
    • Configuring Security
    • Configuring System Messaging
    • Using Name Services
    • Configuring Name Service Clients
    • Configuring Kickstart
    • Virtualization with KVM
    • Troubleshooting Boot Process

    Prerequisites:

    Comments

    Latest comments from students


    Liked the class?  Then let everyone know!

    Course Overview:

    AWS System Operations begins with a one day  introduction to AWS products, services, and common solutions. It provides you with fundamentals to become more proficient in identifying AWS services so that you can make informed decisions about IT solutions based on your business requirements and get started working on AWS.

    The AWS course continues to flow with teaching those in a Systems Administrator or Developer Operations (DevOps) role how to create automatable and repeatable deployments of networks and systems on the AWS platform. The course covers the specific AWS features and tools related to configuration and deployment, as well as common techniques used throughout the industry for configuring and deploying systems.

    To continue to learn more about AWS, TechNow has the following course:

    CL-425: AWS Security Operations and Architecture 

    Attendees to CL-415: AWS System Operations will receive TechNow approved course materials and expert instruction.

    Duration: 5 Days

    Audience:
    This course is intended for:
    • System Administrators
    • Software Developers, especially those in a Developer Operations (DevOps) role

    DoD 8140: Not Mandated

    Course Prerequisites:
    We recommend that attendees of this course have the following prerequisites:
    • Background in either software development or systems administration
    • Some experience with maintaining operating systems at the command line (shell scripting in Linux environments, cmd or PowerShell in Windows)
    • Basic knowledge of networking protocols (TCP/IP, HTTP)

    Course Objectives:
    This course is designed to teach you how to:
    • Understand basic data center design concepts.
    • Recognize terminology and concepts as they relate to the AWS platform and navigate the AWS Management Console.
    • Understand the foundational infrastructure services, including Amazon Virtual Private Cloud (VPC), Amazon Elastic Compute Cloud (EC2), Amazon Elastic Block Store (EBS), Amazon Simple Storage Service (S3), Auto Scaling, and Elastic Load Balancing (ELB).
    • Understand the security measures AWS provides and key concepts of AWS Identity and Access Management (IAM).
    • Understand AWS database services, including Amazon DynamoDB and Amazon Relational Database Service (RDS).
    • Understand AWS management tools, including Amazon CloudWatch and AWS Trusted Advisor.
    • Use standard AWS infrastructure features such as Amazon Virtual Private Cloud (VPC), Amazon Elastic Compute Cloud (EC2), Elastic Load Balancing, and Auto Scaling from the command line
    • Use AWS CloudFormation and other automation technologies to produce stacks of AWS resources that can be deployed in an automated, repeatable fashion
    • Build functioning virtual private networks with Amazon VPC from the ground up using the AWS Management Console
    • Deploy Amazon EC2 instances using command line calls and troubleshoot the most common problems with instances
    • Monitor the health of Amazon EC2 instances and other AWS services
    • Manage user identity, AWS permissions, and security in the cloud
    • Manage resource consumption in an AWS account using tools such as Amazon CloudWatch, tagging, and Trusted Advisor
    • Select and implement the best strategy for creating reusable Amazon EC2 instances
    • Configure a set of Amazon EC2 instances that launch behind a load balancer, with the system scaling up and down in response to demand
    • Edit and troubleshoot a basic AWS CloudFormation stack definition

    Dates/Locations:

    No Events

    Course Outline:

    Day 1

    • Introduction and History of AWS
    • AWS Infrastructure: Compute, Storage, and Networking
    • AWS Security, Identity, and Access Management
    • AWS Databases
    • AWS Management Tools

    Day 2
    • System Operations on AWS Overview
    • Networking in the Cloud
    • Computing in the Cloud
    Day 3
    • Storage and Archiving in the Cloud
    • Monitoring in the Cloud
    • Managing Resource Consumption in the Cloud
    Day 4
    • Configuration Management in the Cloud
    • Creating Scalable Deployments in the Cloud
    • Creating Automated and Repeatable Deployments
    Day 5
    Full Day Lab
    • Select the appropriate AWS service based on compute, data, or security requirements
    • Execute steps required to provision cloud resources for selected deployment
    • Identify and implement data protection, encryption, and capacity planning
    • Implement and manage security policies, access controls, and role
    • Implement Automation

     

    Next/Related Courses:

     

     

      

     

    Course Overview:  PA-242: Palo Alto Networks Firewall Manage Cyberthreats (EDU-231) Training Class is a two-day course that teaches students strategies in defense against cyberthreats.  Successful completion of this course enables administrators to better understand the threat landscape.  This is not a virtualized theoretical course.  This is hands-on, real world instruction, directly relevant to the DoD and Commercial implementations of Palo Alto Networks next-generation firewalls.

    Each student is issued a physical Palo Alto firewall and a Cisco layer 3 switch at their desk.  Real hardware per student for real experience and real skill development.  TechNow provides a very comprehensive client infrastructure that includes Windows, Linux, and multiple packet sniffer agents.

    The instructor for this course has been a lead in Unix kernel development to implement firewall and intrusion detection technologies.  Additionally, the instructor has taught several security appliance products and carries several SANS, ISC2, ISACA, Cisco, Unix, and Windows certifications.

    Attendees to the PA-242: Palo Alto Networks Firewall Manaage Cyberthreats  (EDU-231) Training Course will receive TechNow approved course materials and expert instruction.

    Dates/Locations:

    No Events

    Duration: 2 days

    Course Objectives:   Students attending this training course will gain an understanding of cyberthreats and their characteristics.  Students will learn how to manage cyberthreats using security policies, profiles, and signatures to protect their network against emerging threats.

    Day 1

    • Mod 1: Threat Landscape
      • Advanced Persistent
      • Threats
      • Data Breaches and Tactics
      • Threat Management
      • Strategies
    • Mod 2: Integrated
      • Approach to Threat
      • Protection
      • Integrated Approach to
      • Protection
      • Next-Generation Firewall
      • Advanced Endpoint
      • Protection
    • Mod 3: Network Visibility
      • Zero Trust Model
      • SSL Decryption
      • Decryption Policy
    • Mod 4: Reducing the Attack
      • Surf
      • ection

     

    Day 2

    • Mod 5: Handling Known
      • Threats
      • WildFire Analysis
      • Security Profiles
    • Mod 6: Handling Unknown
      • Traffic and Zero-Day Exploits
      • WildFire
      • Researching Threat Events
      • Identifying Unknown
      • Applications
    • Mod 7: Investigating
      • Breaches
      • Identify IOCs Using
      • App-Scope
      • Log Correlation
      • Finding Infected Host
    • Mod 8: Using Custom
      • Signatures
      • Creating Custom App-IDs
      • Threat Signatures

    A

    Prerequisites:

    • Students must complete the PA-213: Install, Configure, and Manage course
    • Understanding of network concepts, including routing, switching, and IP addressing
    • In-depth knowledge of port-based security and security technologies such as IPS, proxy, and content filtering

    This course is in no way associated with Palo Alto Networks, Inc.

    Comments

    Latest comments from students


    Like the class?  Then let everyone know!