Launching HTB CWEE: Certified Web Exploitation Expert Learn More

CyberTankWGU

Earned a new badge!

Badge Icon

Packet carver

For completing the Working with IDS/IPS module

754

Users earned this badge

0.05%

Users have this badge

Completed on 30 Nov 2023

Working with IDS/IPS

This module offers an in-depth exploration of Suricata, Snort, and Zeek, covering both rule development and intrusion detection. We'll guide you through signature-based and analytics-based rule development, and you'll learn to tackle encrypted traffic. The module features numerous hands-on examples, focusing on the detection of prevalent malware such as PowerShell Empire, Covenant, Sliver, Cerber, Dridex, Ursnif, and Patchwork. We also dive into detecting attacking techniques like DNS exfiltration, TLS/HTTP Exfiltration, PsExec lateral movement, and beaconing through IDS/IPS.