Network Analyst
Network Baseline
Defines what normal network conditions and traffic looks like
Can be used to test for abnormal conditions, rapidly deploy new networks, and ensure network is working as designed
Cyber Threat Intelligence (CTI)
Network Artifacts
– Definition
– Examples
Network Triage
Sandbox
IDS
– Definition
– Examples
Intrusion Detection System
IPS
– Definition
– Examples
Intrusion Prevention System
SIEM
Security Info & Event Management
Network Source Data Types
– 3 Types
Full-Packet Capture
– Definition
– File formats
– Benefits
– Drawbacks
NetFlow
– Definition
– Benefits
– Drawbacks
Log Files
– Definition
– Benefits
– Drawbacks
Port Mirror (switch)
– Definition
– Benefits
– Drawbacks
Router Netflow Export
– Definition
– Benefits
– Drawbacks
Layer 7 Devices (Network data collection)
– Definition
– Examples
– Benefits
– Drawbacks
Tap
– Definition
– Benefits
– Drawbacks
Network-Based Processing Workflows
– List 6
Establish Baselines
– Goal
– Details
Ingest and Distill
– Goal
– Details
Reduce & Filter
– Goal
– Details
Analyze and Explore
– Goal
– Details
Extract Indicators & Objects
– Goal
– Details
Scope & Scale
– Goal
– Details