Course Overview:

TN-575: Open Source Network Security Monitoring teaches students how to deploy, build, and run an NSM operation using open source software and vendor-neutral tools. No network is bullet proof and when attackers access your network, this course will show you how to build a security net to detect, contain, and control the attacker. Sensitive data can be monitored and deep packet and deep attachment analysis can be achieved. As organizations stand up a Security Operations Center (SOC) the enterprise NSM is the key ingredient to that SOC. This course not only teaches how to implement an NSM technologically, but how to effectively monitor an enterprise operationally. You will learn how to architect an NSM solution: where to deploy your NSM platforms and how to size them, stand-alone or distributed, and integration into packet analysis, interpret evidence, and integrate threat intelligence from external sources to identify sophisticated attackers. A properly implemented NSM is integral to incident response and provides the responders timely information to react to the incident. TN-575: Open Source Network Security Monitoring is a lab intensive environment with a cyber range that gives each student in-depth knowledge and practical experience monitoring live systems to include: Cisco, Windows, Linux, IoT, and Firewalls.

Attendees to TN-575: Open Source Network Security Monitoring class will receive TechNow approved course materials and expert instruction.

This Course is taught utilizing Security Onion or RockNSM as specified by the customer.

Dates/Locations:

No Events

Duration: 5 Days

Course Objective:

The focus of this course is to present a suite of Open Source security products integrated into a highly functional and scalable Network Security Monitoring solution.

Prerequisites:

Students should have a basic understanding of networks, TCP/IP and standard protocols such as DNS, HTTP, etc. Some Linux knowledge/experience is recommended, but not required

Course Outline:

  • Network Security Monitoring (NSM) Methodology
  • High Bandwidth Packet Capture Challenges
  • Installation of Security Onion
    • Use Cases (analysis, lab, stand-alone, distributed)
    • Resource Requirements
  • Configuration
    • Setup Phase I – Network Configuration
    • Setup Phase 2 – Service Configuration
    • Evaluation Mode vs. Configuration Mode
    • Verifying Services
  • Security Onion Architecture
    • Configuration Files and Folders
    • Network Interfaces
    • Docker Environment
    • Security Onion Containers
  • Overview of Security Onion Analyst Tools
    • Kibana
    • CapME
    • CyberChef
    • Squert
    • Sguil
    • NetworkMiner
  • Quick Review of Wireshark and Packet Analysis
    • Display and Capture Filters
    • Analyze and Statistics Menu Options
    • Analysis for Signatures
  • Analyzing Alerts
    • Replaying Traffic
    • 3 Primary Interfaces:
      • Squert
      • Sguil
      • Kibana
    • Pivoting Between Interfaces
    • Pivoting to Full Packet Capture
  • Snort and Surricata
    • Rule Syntax and Construction
    • Implementing Custom Rules
    • Implementing Whitelists and Blacklists
  • Hunting
    • Using Kibana to Slice and Dice Logs
    • Hunting Workflow with Kibana
  • Bro
    • Introduction and Overview
      • Architecture, Commands
    • Understanding and Examining Bro Logs
      • Using AWK, sort, uniq, and bro-cut
    • Working with traces/PCAPs
    • Bro Scripts Overview
      • Loading and Using Scripts
    • Bro Frameworks Overview
      • Bro File Analysis Framework FAF
    • Using Bro scripts to carve out more than files
  • RockNSM ( * If Applicable)
    •  Kafka
      • Installation and Configuration
      • Kafka Messaging
      • Brokers
      • Integration with Bro and FSF
    • File Scanning Framework FSF
      • Custom YARA Signatures
      • JSON Trees
      • Sub-Object Recursion
      • Bro and Suricata Integration
  • Elastic Stack
    • Adding new data sources in Logstash
    • Enriching data with Logstash
    • Automating with Elastalert
    • Building new Kibana dashboards
  • Production Deployment
    • Advanced Setup
    • Master vs Sensor
    • Node Types – Master, Forward, Heavy, Storage
    • Command Line Setup with sosetup.conf
    • Architectural Recommendations
    • Sensor Placement
    • Hardening
    • Administration
    • Maintenance
  • Tuning
    • Using PulledPork to Disable Rules
    • BPF’s to Filter Traffic
    • Spinning up Additional Snort / Suricata / Bro Workers to Handle Higher Traffic Loads

Comments

Latest comments from students


 

Liked the class?  Then let everyone know!

Course Overview:

What a great course that is slightly misnamed!  This course may be labeled Security Essentials, but covers much of the subject matter of CISSP!  This course does more than just cover the basics.  TechNow takes the time to give the student hands on labs to exemplify an objective.  Security Essentials Prep Training Course sets the foundation for your security career and sets the expectation of comprehension with more detail than Security+ and more on par with CISSP.

This course provides students skills to take courses that prepare for higher level certifications.

Attendees to TN-929: Security Essentials  Training Course will receive TechNow approved course materials and expert instruction.

Date/Locations:

No Events

Duration: 9 days

Course Objectives:

  • 802.11 Suite of Protocols
  • Access Control Theory
  • Alternate Network Mapping Techniques
  • Authentication and Password Management
  • Contingency Planning
  • Crypto Concepts
  • Crypto Fundamentals
  • Defense-in-Depth
  • DNS
  • Firewall Subversion
  • Firewalls
  • HIDS Overview
  • Honeypots
  • ICMP
  • IDS Overview
  • Incident Handling Fundamentals
  • Information Warfare
  • Introduction to OPSEC
  • IP Packets
  • IPS Overview
  • IPv6
  • Legal Aspects of Incident Handling
  • Linux/Unix Configuration Fundamentals
  • Linux/Unix Logging and Log Management
  • Linux/Unix OS Security Tools and Utilities
  • Linux/Unix Overview
  • Linux/Unix Patch Management
  • Linux/Unix Process and Service Management
  • Mitnick-Shimomura
  • Network Addressing
  • Network Design
  • Network Hardware
  • Network Mapping and Scanning
  • Network Plumbing
  • Network Protocol
  • NIDS
  • OverviewPhysical Security
  • Policy Framework
  • Protecting Data at Rest
  • Public Key Infrastructure
  • PKI
  • Reading Packets
  • Risk Management
  • Safety Threats
  • Securing Windows Server Services
  • Steganography
  • OverviewTCPUDP
  • Virtual Machines
  • Virtual Private Networks VPNs
  • Viruses and Malicious Code
  • VoIP
  • Vulnerability Management Overview
  • Vulnerability Scanning
  • Web Application Security
  • Windows Auditing
  • Windows Automation and Configuration
  • Windows Family of Products
  • Windows Network Security Overview
  • Windows Permissions & User Rights
  • Windows Security Templates & Group Policy
  • Windows Service Packs, Hotfixes and Backups
  • Windows Workgroups, Active Directory and Group Policy Overview
  • Wireless Overview

Prerequisites:

 

Comments

Latest comments from students


User: sjsmith2262

Instructor comments: without question, Dave Askey knows his material!!! great instructor that gave a personalized approach.

Facilities comments: class was taught in a hotel reception area, very nice, quiet and convenient for all people


User: synistry

Instructor comments: Dave was great! (as always). Wealth of knowledge and a master at customizing course content to match the education level of his students. The class kept entirely in pace with where we were at as a group overall on a day to day basis.

Facilities comments: Facilities were overall really nice. The only complaint is that the hotel / conference center had us move rooms on one occasion, and kicked us out early on two others. I would assume this is due to the last minute location change, so I don't think there is anything anyone could have done better in the situation.


Liked the class?  Then let everyone know!

Privacy Policy

Effective Date: August 1, 2026

TechNow, Inc. respects the privacy of our students and visitors to our website and is committed to protecting the information entrusted to us.

This Privacy Policy explains what information we collect, how we use it, how we protect it, and the circumstances under which it may be disclosed.

1. Information We Collect

We may collect information necessary to provide and administer our educational courses and related services.

This information may include:

  • Name
  • Mailing or billing address
  • Telephone or mobile phone number
  • Email address
  • Course enrollment information
  • Student account information
  • Course progress and quiz activity
  • Information necessary to process course registration and payment
  • Communications between the student and our organization concerning course administration

We collect only information that is reasonably necessary to operate our courses, administer student accounts, communicate with students, and provide related services.

2. How We Use Student Information

We use student information solely for legitimate business and educational purposes related to the delivery and administration of our courses.

This may include:

  • Registering students for courses
  • Creating and maintaining student accounts
  • Providing access to course materials and quizzes
  • Communicating course schedules and changes
  • Sending course reminders and administrative notifications
  • Communicating logistical information necessary for a course
  • Communicating urgent or emergency information related to the delivery of a course
  • Responding to student questions and requests
  • Administering payments and registrations
  • Maintaining records necessary to operate our business and educational programs
  • Providing technical support for our student platform
  • Protecting the security and integrity of our systems

3. No Sale or Marketing Use of Student Contact Information

We do not sell, rent, lease, or otherwise provide student telephone numbers, mobile phone numbers, email addresses, or other student contact information to third parties for their own marketing, advertising, lead generation, or sales purposes.

We do not use student contact information to conduct unrelated marketing campaigns.

We do not sell or exchange student contact information for leads, affiliate marketing, or other commercial marketing purposes.

Our communications with students are limited to information reasonably related to their enrollment, courses, student accounts, course logistics, and urgent or emergency matters associated with delivering a course.

4. SMS Text Messaging

Student SMS Notifications

We may use SMS text messaging to communicate with students who have student accounts associated with our courses.

We only take registrations over the phone and when asked for a preferred phone number you were asked: “Would you like to receive course-related text messages at this mobile number?”  This is to initiate automated communications.  Once logged into the TechNow Quiz Platform there is a button at the top of your dashboard “SMS: on“, with a mouse hover text tooltip of “You are currently enrolled to receive SMS notifications about your student account and courses. PRESS TO DISABLE SMS”.  If you press the button it becomes “SMS: off“, with a mouse hover text tooltip of “You are currently NOT enrolled to receive SMS notifications about your student account and courses. PRESS TO ENABLE SMS”.  Changes of “SMS: off” and “SMS:on” are logged as text messaging Opt-Out and Opt-in.

SMS messages are used for course-related and administrative communications, not marketing or promotional campaigns.  Most TechNow communications is through email, SMS is used for time critical and emergency communications.

Examples of SMS communications may include:

  • Student account notifications
  • Course enrollment or welcome notifications
  • Course reminders
  • Class schedule information
  • Schedule changes
  • Class cancellations
  • Location or logistical information
  • Instructor or course-related administrative notifications
  • Urgent or emergency information related to the delivery of a course
  • Other communications reasonably necessary to administer a student’s participation in a course

We do not use student SMS messaging to send advertising, promotional offers, sales messages, or unrelated marketing communications.

SMS Consent

Students who elect to receive SMS messages authorize TechNow, Inc. to send course-related and administrative text messages to the mobile telephone number provided by the student.

SMS consent is not a condition of purchasing or enrolling in a course.

Message frequency varies depending on course enrollment, account activity, and circumstances requiring course-related communication. Message and data rates may apply.

Opting Out of SMS Messages

Students may disable SMS notifications through the SMS settings available within their student dashboard.

Students may also reply STOP to an SMS message to request that SMS messaging be discontinued.

After an SMS opt-out request is received, our platforms prevent additional SMS messages from being sent to that telephone number.

A student may request assistance regarding SMS messaging by replying HELP where supported or by contacting us using the contact information provided on our website.

Disabling SMS notifications does not prevent a student from accessing their student account or participating in a course. Students who disable SMS may still receive important information through other available communication methods when necessary.

SMS Information Is Not Sold or Shared for Marketing

We do not sell, rent, or share mobile telephone numbers or SMS consent information with third parties for their own marketing or advertising purposes.

SMS consent information is used solely for administering our student communication program and providing the course-related communications described in this Privacy Policy.

5. TechNow Does NOT Share Information With Service Providers

Unlike most companies, TechNow does not use third-party service providers  to operate our business, we are a SELF HOSTED company.

For example, we internally self host:

  • Website
  • Student-platform
  • Email
  • Information technology and security
  • Database and infrastructure services

TechNow interacts with a Bank for Payment Processing and with a trusted SMS provider for SMS delivery.   A student’s mobile telephone number and message information may be transmitted through our trusted SMS service provider solely to deliver the requested or authorized course-related communication.

6. Course Platform Information

Students may receive an account on our course and quiz platform.

Information associated with a student account may include:

  • Login credentials
  • Course enrollment
  • Quiz and assessment activity
  • Course progress
  • Account settings
  • Communication preferences
  • SMS preferences

This information is used to provide and administer the student’s courses and account.

7. Payment Information

When payment is required for a course, payment information may be processed through a third-party payment processor.

We do not retain payment-card information on our student quiz platform unless specifically stated otherwise.

Payment processors may collect and process payment information according to their own privacy policies and security practices.

8. Cookies and Technical Information

Our website and student platform may use cookies, session information, logs, and similar technical mechanisms necessary to:

  • Maintain authenticated sessions
  • Keep students logged into their accounts
  • Provide website and application functionality
  • Maintain security
  • Detect and prevent unauthorized access
  • Diagnose technical problems
  • Improve the reliability of our services

We do not use student contact information for third-party advertising or behavioral marketing.

9. Information Security

We take reasonable administrative, technical, and organizational measures to protect student information against unauthorized access, alteration, disclosure, or destruction.

No method of storing or transmitting information over the Internet can be guaranteed to be completely secure. We therefore cannot guarantee absolute security of information.

10. Retention of Information

We retain student information for as long as reasonably necessary to provide our services, administer courses and student accounts, maintain appropriate business records, comply with legal or regulatory obligations, resolve disputes, and protect our rights and systems.

When information is no longer reasonably necessary for these purposes, we may securely delete or otherwise dispose of it.

11. Children’s Privacy

Our courses and services are intended for the individuals described by our course enrollment requirements. We do not knowingly collect personal information from children in violation of applicable law.

If you believe that a child has provided personal information to us without appropriate authorization, please contact us.

12. Third-Party Websites

Our website may contain links to websites or services operated by third parties.

We are not responsible for the privacy practices, content, or security of third-party websites. We encourage users to review the privacy policies of those websites before providing personal information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, business practices, or legal requirements.

When we make changes, we will update the Effective Date shown at the beginning of this Privacy Policy.

14. Contact Us

If you have questions about this Privacy Policy, your personal information, or our SMS messaging practices, please contact us:

TechNow Inc.
14117 Jones Maltsberger Rd
San Antonio, TX 53578
210 733-1093
technow-training@technow.com
technow.com

Effective Date: August 1, 2026

in   
 

Course Overview:

TechNow’s TN-911: Cyber Threat Intelligence (CTI) Analysis and 800-172 Updates Seminar, is a one day seminar that covers the objectives of TechNow’s TN-905: Cyber Threat Intelligence Analysis five day course in a one day seminar format plus some other security enhancements of 800-172.  Upon request, this seminar can be presented in multi-day format based upon the depth of knowledge required. The NIST PUB 800-172 security enhancement update to 800-171 regarding 03.11.1 Risk Assessment, introduces the security enhancements of a Threat Awareness Program, Threat Hunting, and Predictive Cyber Analytics.  TN-911 distills the TN-905 CTI five day course and aligns it to assessing compliance with 800-172.  For the seminar, selected course labs are converted to demos, and the important points and outcomes of topics are presented. The TN-911 CTI Seminar discusses the applicability of the 800-172 security enhancements to the organization being assessed, and how to think about the the appropriate strength of the controls related to the organizations criticality of the information and the risk involved for contracted work with the DoD.

TechNow’s TN-911: Cyber Threat Intelligence Analysis Seminar addresses significant changes that have been made to SP 800-172 in transitioning to Revision 3, regarding new enhanced security requirements based on (1) the latest threat intelligence and (2) empirical data from cyber-attacks.  With the intent of addressing CUI that may be associated with a critical program or a high value asset.

Those programs and assets are potential targets for advanced persistent threat (APT).  Cyber Threat Intelligence supports the required functions of NIST 800-172 of Penetration Resistant Architecture (PRA), Damage Limiting Operations (DLO) and Cyber Resiliency (CRS).

Regarding 800-172 This seminar includes:

  • 3.2.1E Awareness Training (rev 3 – Advanced Literacy and  Awareness Training)
  • 3.11.6E Supply Chain Risk Management SCRM (rev 3 withdrawn, moved to other controls)
  • 3.11.7E SCRM Planning (rev 3 withdrawn, moved to other controls)
  • 3.12.1E Penetration Testing
  • 800-172, 3.11 Risk Assessment
    • 03.11.01E Threat Awareness Program
    • 03.11.02E Threat Hunting
    • 03.11.03E Predictive Cyber Analytics.

TN-911 CTI Seminar directly discusses 3.11 topics:

    03.11.01E Threat Awareness Program:

    Share threat information, including threat events of 03.11.01E is specifically covered as:

  • Create Indicators of Compromise (IOCs) using STIX
  • Understand a solution for collecting, storing, distributing and sharing cyber security indicators and threats about cyber security incidents analysis and malware analysis.
  • How to assess an environment to validate:
    • Support for day-to-day operations to share structured threat information efficiently.
    • Confirming the presence of curated, frequently updated feeds, and the automation of enrichment   workflow
    • Contextualization of intelligence with internal data to prioritize alerts and improve detection
    • Updated threat hunting based upon inbound Threat Intelligence

    03.11.02E Threat Hunting:

    Introduction to Threat Hunting practices to effectively search for indicators of compromise and to detect, track, and disrupt threats that evade existing controls.

  • How to assess an environment to validate:
  • A formalized process is being followed for Threat Hunting
    • Phases of trigger (incident or CTI), SIEM utilization, and response
  • Integration of machine learning to provide proactive, automated, and scalable Threat Hunting
  • Leveraging threat intelligence for proactive threat hunting by querying historical logs for indicators of compromise (IOCs) from feeds to identify:
  •  Dormant threats
  •  Advance Persistent Threats (APT)

    03.11.03E Predictive Cyber Analytics

    Introduction leveraging data, machine learning, and real-time analysis with automation to anticipate threats before they occur.

  • How to assess an environment to validate:
    • Data aggregation from network logs, user activities, system logs, and external threat intelligence feeds into a centralized platform like a SIEM
  • Use of machine learning algorithms to identify patterns, uncover correlations, and spot anomalies in real-time
  • Integration with incident response workflows
  • Staff skill competency level and integration into Predictive Cyber Analytics to mitigate advanced adversarial techniques against machine learning such as:
    • Attacks of Evasion, Poisoning, and Model Tampering
    • Utilization of exercises or Red Teaming to validate practices and effectiveness of Predictive Cyber Analytics.

    3.2.1E Awareness Training (rev 3 – Advanced Literacy and  Awareness Training)

  •       Validate that training addresses APT

    3.11.6E Supply Chain Risk Management SCRM (rev 3 withdrawn, moved to other controls)

      Validate cybersecurity supply chain risk management C-SCRM:

  • Cross-functional team responsible for supply chain risk management (SCRM) and C-SCRM
  • Validating standard risk management with respect to supply chain
    • FARM (Frame, Assess, Respond, and Monitor)
    • Tasks outlined in NIST Pub 800-161

    3.11.7E SCRM Planning (rev 3 withdrawn, moved to other controls)

  • This is discussed in topic 3.11.6E

    3.12.1E Penetration Testing

        Validate the organization is progressing through standardized Penetration Testing Protocols.

  • Evaluate Penetration Test reports for completeness and scope.

Attendees to TN-911: Cyber Threat Intelligence (CTI) Analysis and 800-172 Seminar will receive TechNow approved course materials and expert instruction.

Seminar Duration: 1 day (more upon request)

Seminar Objectives:

  • Learn to comprehend and develop complex scenarios
  • Identify and create intelligence requirements through practices such as threat modeling
  • Utilize threat modeling to drive intelligence handling and practices 
  • Breakdown tactical, operational, and strategic-level threat intelligence
  • Generate threat intelligence to detect, respond to, and defeat focused and targeted threats
  • How to collect adversary information creating better value CTI
  • How to filter and qualify external sources, mitigating low integrity intelligence
  • Create Indicators of Compromise (IOCs) in STIX
  • Move security maturity past IOCs into understanding and countering the behavioral tradecraft of threats
  • Breaking down threats mapped against their tradecraft to tweak IOCs
  • Establish structured analytical techniques to be successful in any security role
  • Learn and apply structured principles in support of CTI and how to communicate that to any security role.

Seminar Prerequisites:

 

Course Overview:

The Certified Information Security Manager (CISM) certification program is developed specifically for experienced information security managers & those who have information security management responsibilities. The CISM certification is for the individual who manages, designs, oversees and/or assesses an enterprise’s information security (IS). The CISM certification promotes international practices & provides executive management with assurance that those earning the designation have the required experience & knowledge to provide effective security management & consulting services. Individuals earning the CISM certification become part of an elite peer network, attaining a one-of-a-kind credential. The CISM job practice also defines a global job description for the information security manager & a method to measure existing staff or compare prospective new hires.

This course is designed to assist in your exam preparation for the CISM exam.

Attendees to TN-825: Certified Information Security Manager (CISM) Seminar will receive TechNow approved course materials and expert instruction.

Document Flow Chart iconsm

Dates/Locations:

Date/Time Event
08/17/2026 - 08/21/2026
08:00 -16:00
TN-825: Certified Information Security Manager (CISM) Seminar
TechNow, Inc, San Antonio TX
11/16/2026 - 11/20/2026
08:00 -16:00
TN-825: Certified Information Security Manager (CISM) Seminar
TechNow, Inc, San Antonio TX

Duration: 5 Days

Course Objectives:

  • Information Security Governance (24%)
  • Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives
  • Information Risk Management (30%)
  • Manage information risk to an acceptable level based on risk appetite to meet organizational goals and objectives
  • Information Security Program Development and Management (27%)
  • Develop and maintain an information security program that identifies, manages and protects the organization’s assets while aligning to information security strategy and business goals, thereby supporting an effective security posture
  • Information Security Incident Management (19%)
  • Plan, establish and manage the capability to detect, investigate, respond to and recover from information security incidents to minimize business impact

Prerequisites:

A minimum of five years of information security work experience, with a minimum of three years of information security management work experience in three or more of the job practice analysis areas.

Comments

Latest comments from students


User: tracycampbell

Instructor comments: Dave had great command of the class and the flow of information. The lessons seem relevant to the exam and the course material should assist greatly with passing. As a bonus, his breakdown of PKI helped with my current job requirements.

Facilities comments: The Home2Suites by Hilton was FANTASTIC!



Liked the class?  Then let everyone know!