New path and certification for beginners (25% OFF Silver Annual Plan - for a limited time only) Learn More

tranquility1412

Earned a new badge!

Badge Icon

Packet carver

For completing the Working with IDS/IPS module

3626

Users earned this badge

0.18%

Users have this badge

Completed on 13 Apr 2025

Working with IDS/IPS

This module offers an in-depth exploration of Suricata, Snort, and Zeek, covering both rule development and intrusion detection. We'll guide you through signature-based and analytics-based rule development, and you'll learn to tackle encrypted traffic. The module features numerous hands-on examples, focusing on the detection of prevalent malware such as PowerShell Empire, Covenant, Sliver, Cerber, Dridex, Ursnif, and Patchwork. We also dive into detecting attacking techniques like DNS exfiltration, TLS/HTTP Exfiltration, PsExec lateral movement, and beaconing through IDS/IPS.