MITRE ATT&CK Training Course
MITRE ATT&CK is a framework of tactics and techniques used to classify attacks and assess an organisation's risk. ATT&CK raises awareness of an organisation's security posture, identifying gaps in defences and prioritising risks.
This instructor-led, live training (online or on-site) is designed for information systems analysts who wish to use MITRE ATT&CK to reduce the risk of a security compromise.
By the end of this training, participants will be able to:
- Set up the necessary development environment to begin implementing MITRE ATT&CK.
- Classify how attackers interact with systems.
- Document adversary behaviours within systems.
- Track attacks, decipher patterns, and evaluate existing defence tools.
Course Format
- Interactive lectures and discussions.
- Abundant exercises and practical practice.
- Hands-on implementation in a live lab environment.
Course Customisation Options
- To request a customised version of this course, please contact us to arrange.
Course Outline
Introduction
What is Malware?
- Types of malware
- The evolution of malware
Overview of Malware Attacks
- Propagating
- Non-propagating
ATT&CK Matrices
- Enterprise ATT&CK
- Pre-ATT&CK
- Mobile ATT&CK
MITRE ATT&CK
- 11 tactics
- Techniques
- Procedures
Preparing the Development Environment
- Setting up a version control repository (GitHub)
- Downloading a project that hosts a data-based to-do list system
- Installing and configuring ATT&CK Navigator
Monitoring a Compromised System (WMI)
- Deploying command-line scripts to conduct a lateral attack
- Using ATT&CK Navigator to identify the compromise
- Assessing the compromise through the ATT&CK framework
- Performing process monitoring
- Documenting and patching gaps in the defence architecture
Monitoring a Compromised System (EternalBlue)
- Deploying command-line scripts to conduct a lateral attack
- Using ATT&CK Navigator to identify the compromise
- Assessing the compromise through the ATT&CK framework
- Performing process monitoring
- Documenting and patching gaps in the defence architecture
Summary and Conclusion
Requirements
- A foundational understanding of information systems security
Audience
- Information systems analysts
Open Training Courses require 5+ participants.
MITRE ATT&CK Training Course - Booking
MITRE ATT&CK Training Course - Enquiry
MITRE ATT&CK - Consultancy Enquiry
Testimonials (2)
- Understanding that ATT&CK creates a map that makes it easy to see, where an organization is protected and where the vulnerable areas are. Then to identify the security gaps that are most significant from a risk perspective. - Learn that each technique comes with a list of mitigations and detections that incident response teams can employ to detect and defend. - Learn about the various sources and communities for deriving Defensive Recommendations.
CHU YAN LEE - PacificLight Power Pte Ltd
Course - MITRE ATT&CK
All is excellent
Manar Abu Talib - Dubai Electronic Security Center
Course - MITRE ATT&CK
Provisional Upcoming Courses (Require 5+ participants)
Related Courses
AI-Powered Cybersecurity: Threat Detection & Response
21 HoursThis instructor-led, live training in New Zealand (online or onsite) is aimed at beginner-level cybersecurity professionals who wish to learn how to leverage AI for improved threat detection and response capabilities.
By the end of this training, participants will be able to:
- Understand AI applications in cybersecurity.
- Implement AI algorithms for threat detection.
- Automate incident response with AI tools.
- Integrate AI into existing cybersecurity infrastructure.
AI-Powered Cybersecurity: Advanced Threat Detection & Response
28 HoursThis instructor-led, live training in New Zealand (online or onsite) is aimed at intermediate-level to advanced-level cybersecurity professionals who wish to elevate their skills in AI-driven threat detection and incident response.
By the end of this training, participants will be able to:
- Implement advanced AI algorithms for real-time threat detection.
- Customise AI models for specific cybersecurity challenges.
- Develop automation workflows for threat response.
- Secure AI-driven security tools against adversarial attacks.
Blue Team Fundamentals: Security Operations and Analysis
21 HoursThis instructor-led, live training in New Zealand (online or on-site) is designed for intermediate-level IT security professionals who want to develop their skills in security monitoring, analysis, and response.
By the end of this training, participants will be able to:
- Understand the role of a Blue Team in cybersecurity operations.
- Use SIEM tools for security monitoring and log analysis.
- Detect, analyse, and respond to security incidents.
- Perform network traffic analysis and gather threat intelligence.
- Apply best practices in Security Operations Centre (SOC) workflows.
Bug Bounty Hunting
21 HoursBug bounty hunting is the practice of identifying security vulnerabilities in software, websites, or systems and responsibly reporting them in exchange for rewards or recognition.
This instructor-led, live training (available online or on-site) is designed for beginner-level security researchers, developers, and IT professionals who want to learn the fundamentals of ethical bug hunting and how to take part in bug bounty programmes.
By the end of this training, participants will be able to:
- Understand the core concepts of vulnerability discovery and bug bounty programmes.
- Use key tools such as Burp Suite and browser developer tools to test applications.
- Identify common web security flaws including XSS, SQLi, and CSRF.
- Submit clear, actionable vulnerability reports to bug bounty platforms.
Course Format
- Interactive lectures and discussions.
- Hands-on use of bug bounty tools in simulated testing environments.
- Guided exercises focused on discovering, exploiting, and reporting vulnerabilities.
Course Customisation Options
- To request a customised training session for this course based on your organisation's applications or testing requirements, please contact us to arrange.
Bug Bounty: Advanced Techniques and Automation
21 HoursBug Bounty: Advanced Techniques and Automation offers a deep dive into high-impact vulnerabilities, automation frameworks, reconnaissance techniques, and the tooling strategies employed by elite bug bounty hunters.
This instructor-led, live training (available online or on-site) is designed for intermediate to advanced-level security researchers, penetration testers, and bug bounty hunters who aim to automate their workflows, scale reconnaissance efforts, and uncover complex vulnerabilities across multiple targets.
By the end of this training, participants will be able to:
- Automate reconnaissance and scanning across multiple targets.
- Leverage cutting-edge tools and scripts used in bounty automation.
- Discover complex, logic-based vulnerabilities that go beyond standard scans.
- Build custom workflows for subdomain enumeration, fuzzing, and reporting.
Course Format
- Interactive lectures and discussions.
- Hands-on use of advanced tools and scripting for automation.
- Guided labs focused on real-world bounty workflows and advanced attack chains.
Course Customisation Options
- To request a customised training session tailored to your bounty targets, automation requirements, or internal security challenges, please contact us to arrange.
CHFI - Certified Digital Forensics Examiner
35 HoursThe Certified Digital Forensics Examiner vendor-neutral certification is designed to train cyber crime and fraud investigators, equipping students with skills in electronic discovery and advanced investigation techniques. This course is essential for anyone who may encounter digital evidence while conducting investigations.
The Certified Digital Forensics Examiner training teaches the methodology for conducting computer forensic examinations. Students will learn to apply forensically sound investigative techniques to evaluate a scene, collect and document all relevant information, interview appropriate personnel, maintain the chain of custody, and produce a comprehensive findings report.
The Certified Digital Forensics Examiner course will benefit organisations, individuals, government offices, and law enforcement agencies seeking to pursue litigation, establish proof of guilt, or implement corrective actions based on digital evidence.
Certified Incident Handler
21 HoursThe Certified Incident Handler course offers a structured approach to managing and responding to cybersecurity incidents effectively and efficiently.
This instructor-led, live training (available online or on-site) is designed for intermediate-level IT security professionals seeking to develop the tactical skills and knowledge required to plan, classify, contain, and manage security incidents.
By the end of this training, participants will be able to:
- Understand the incident response lifecycle and its phases.
- Execute procedures for incident detection, classification, and notification.
- Apply containment, eradication, and recovery strategies effectively.
- Develop post-incident reporting and continuous improvement plans.
Course Format
- Interactive lectures and discussions.
- Practical application of incident handling procedures in simulated scenarios.
- Guided exercises focused on detection, containment, and response workflows.
Course Customisation Options
- To request a customised training session tailored to your organisation's incident response procedures or tools, please contact us to arrange.
Mastering Continuous Threat Exposure Management (CTEM)
28 HoursThis instructor-led, live training in New Zealand (online or on-site) is designed for intermediate-level cybersecurity professionals who wish to implement CTEM within their organisations.
By the end of this training, participants will be able to:
- Understand the core principles and stages of CTEM.
- Identify and prioritise risks using CTEM methodologies.
- Integrate CTEM practices into existing security protocols.
- Utilise tools and technologies for continuous threat management.
- Develop strategies to validate and continually improve security measures.
Cyber Threat Intelligence
35 HoursThis instructor-led, live training in New Zealand (available online or on-site) is designed for advanced-level cybersecurity professionals who wish to gain a comprehensive understanding of Cyber Threat Intelligence and develop the skills needed to effectively manage and mitigate cyber threats.
By the end of this training, participants will be able to:
- Understand the fundamentals of Cyber Threat Intelligence (CTI).
- Analyse the current cyber threat landscape.
- Collect and process intelligence data.
- Perform advanced threat analysis.
- Leverage Threat Intelligence Platforms (TIPs) and automate threat intelligence processes.
Fundamentals of Corporate Cyber Warfare
14 HoursThis instructor-led, live training in New Zealand (online or on-site) explores the various facets of enterprise security, ranging from artificial intelligence to database protection. It also covers the latest tools, processes, and mindsets necessary to defend against attacks.
DeepSeek for Cybersecurity and Threat Detection
14 HoursThis instructor-led, live training in New Zealand (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to leverage DeepSeek for advanced threat detection and automation.
By the end of this training, participants will be able to:
- Utilise DeepSeek AI for real-time threat detection and analysis.
- Implement AI-driven anomaly detection techniques.
- Automate security monitoring and response using DeepSeek.
- Integrate DeepSeek into existing cybersecurity frameworks.
Duty Managers Cyber Resilience
14 HoursThis instructor-led, live training in New Zealand (online or on-site) is designed for intermediate-level duty managers and operational leaders who wish to develop robust cyber resilience strategies to safeguard their organisations against cyber threats.
By the end of this training, participants will be able to:
- Understand the fundamentals of cyber resilience and their relevance to duty management.
- Develop incident response plans to maintain operational continuity.
- Identify potential cyber threats and vulnerabilities within their environment.
- Implement security protocols to minimise risk exposure.
- Coordinate team responses during cyber incidents and recovery processes.
Junior Detection Engineer Essentials
21 HoursDetection engineering is the practice of designing, implementing, and refining methods to identify malicious behaviour across systems and networks.
This instructor-led, live training (online or on-site) is aimed at beginner-level cybersecurity practitioners who wish to gain practical skills in building and tuning security detections.
Upon completion of this training, participants will have the skills needed to:
- Develop effective detection rules and signatures using common security tools.
- Interpret logs and telemetry to identify suspicious behaviours.
- Apply threat intelligence to strengthen detection logic.
- Optimise alerts and reduce false positives within a SOC workflow.
Format of the Course
- Guided instruction with practical demonstrations.
- Scenario-driven exercises and hands-on analysis.
- Real-world detection building within an interactive lab environment.
Course Customisation Options
- If your organisation requires a tailored version of this programme, please contact us to discuss customisation options.
Open-Source EDR Fundamentals: Deployment, Detection & Response
14 HoursOpenEDR is an open-source endpoint detection and response platform that delivers continuous telemetry, detection, and analysis of adversarial activity across endpoints.
This instructor-led, live training (available online or on-site) is designed for beginner to intermediate-level IT and security professionals who aim to deploy, configure, and operate OpenEDR to effectively detect and respond to cyber threats.
Upon completing this training, participants will be able to:
- Deploy and configure OpenEDR agents and server components for telemetry collection.
- Carry out basic detection and monitoring using OpenEDR dashboards and event views.
- Analyse endpoint events to identify suspicious activity and potential threats.
- Integrate OpenEDR alerts into incident response workflows and reporting processes.
Course Format
- Interactive lectures and group discussions.
- Numerous exercises and hands-on practice sessions.
- Practical implementation within a live-lab environment.
Course Customisation Options
- To request a customised version of this training, please contact us to make arrangements.
Mastering Open-Source EDR & Mitre ATT&CK for Threat Hunting
21 HoursOpenEDR is an open-source endpoint detection and response platform that provides analytical detection with MITRE ATT&CK visibility for event correlation and root cause analysis of adversarial activity in real time.
This instructor-led, live training (available online or on-site) is designed for advanced-level SOC analysts, threat hunters, and incident responders who wish to design and operate threat-hunting programmes using OpenEDR and map detections to the MITRE ATT&CK framework.
By the end of this training, participants will be able to:
- Deploy and configure OpenEDR agents and server components for telemetry collection and analysis.
- Map observable endpoint telemetry to MITRE ATT&CK techniques and build detection logic accordingly.
- Design and execute threat-hunting workflows that leverage behavioural analytics and event correlation to identify adversarial activity.
- Integrate OpenEDR findings into incident response playbooks and perform root cause analysis.
Format of the Course
- Interactive lectures and discussions.
- Abundant exercises and practice opportunities.
- Hands-on implementation in a live-lab environment.
Course Customisation Options
- To request a customised training session for this course, please contact us to arrange.