| Section | Weight | Objectives |
| Topic 1: Active Asset and Network Analysis | 28% | - Windows-based analysis
- 1. Registry, networking, file system, processes, services, volatile memory, Active Directory tools
- Indicators of compromise
- 1. Suspicious accounts, registry changes, malicious software, abnormal bandwidth usage, rogue hardware, failed logins, unauthorized sessions
- Linux-based analysis
- 1. Network utilities, file system tools, process analysis, memory analysis, session management
- Malware analysis
- 1. Sandboxing, threat intelligence resources, reverse engineering tools, malware scanners
|
| Topic 2: Passive Data-Driven Analysis | 27% | - Log analysis
- 1. Log analytics tools, Linux tools, Windows tools, scripting, SIEM correlation
- Regular expressions and log parsing
- 1. Search techniques, operators, special operators, meaningful data extraction
- Data sources
- 1. Network logs, host logs, application logs, vulnerability testing data
|
| Topic 3: Threat Landscape | 25% | - Threat actors and threat profiles
- 1. Threat actors, motives, intent, attack vectors, and qualitative risk
- Threat research and preparation
- 1. Threat intelligence, vulnerability databases, security advisories, trend analysis, targeted assets
- Attack tools and techniques
- 1. Footprinting, scanning, enumeration, exploitation, password attacks, wireless attacks, social engineering, man-in-the-middle, malware, denial-of-service
- Post-exploitation tools and tactics
- 1. Command and control, data exfiltration, pivoting, lateral movement, persistence, keylogging, anti-forensics, covering tracks
- Social engineering
- 1. Phishing variants, delivery methods, shoulder surfing, tailgating, fake portals, malicious websites
|
| Topic 4: Incident Response Lifecycle | 20% | - Incident response process
- 1. Preparation, identification, containment, eradication, recovery, post-incident activities
- Mitigation methods and devices
- 1. System hardening, patching, DNS filtering, application whitelisting, firewalls, WAFs, proxies, servers, virtual machines
- Incident response preparation
- 1. Planning, training, communication methods, policies, procedures, escalation processes
- Forensic analysis concepts
- 1. Authorization, chain of custody, evidence preservation, legal defensibility, law enforcement involvement
|