SCA HUN200-1-Homework-Lessons Learned From APT1

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 7

SecureSet Academy

Lessons Learned from APT1


Version: 2019-12-30
Table of Contents
Environment Setup 2
Abstract 2
Conceptual Review 2
Purpose 2
Pre & Post conditions of lab 2
System Requirements & Configuration 3
System Requirements 3
Network Requirements 3
Software Requirements 3
Data Requirements 3
Credentials 3
Procedure – Detailed Lab Steps 4
Lessons Learned from APT1 4
Advanced Lab 5
Lab “Tear-down” 5
Questions/Responses 5
Appendix 6
Lab Assistance 6
Terminology 6
References 6
Environment Setup
N/A

Abstract
This lab will be a written paper on analyzing and learning the lessons from APT1, as per the
lecture, the published Mandiant report, and other cited sources.

Conceptual Review
Understanding what happened with APT1 will aid in equipping the next generation of Hunt
Analysts with what to look for in terms of indicators of compromise.

Purpose
Gain a deeper understanding of APT1 tactics, techniques and procedures (TTPs).

Pre & Post conditions of lab


N/A
System Requirements & Configuration
System Requirements
A Windows or MacOS host machine and a document processor.

Network Requirements
Ability to upload document to Canvas for submission.

Software Requirements
N/A

Data Requirements
N/A

Credentials
Client credentials student initially setup.
Procedure – Detailed Lab Steps

Lessons Learned from APT1

Use the lab template provided for writing this paper. Here are some questions to consider

when writing your paper:

 What are the tactics, techniques and procedures (TTPs) deployed by APT1?
 Based on knowing these TTPs, how would one leverage the OODA Loop to be
proactive against APT1?
 What would be the first thing you do when you are hired onto a company as a Hunt
Analyst? Why did you choose this first thing?
Advanced Lab
N/A

Lab “Tear-down”
N/A

Questions/Responses
Student: Please record anything that was unclear about this lab.
Appendix
Lab Assistance
N/A

Terminology
N/A

References
N/A

You might also like