Eisenhower JA 2025_11_Redacted.pdf

PDF 623 KB Posted

Attached to
USCyS AOC-A Federal contract opportunity
Solicitation number
W9124925CA004
Issued by
Department of the Army Materiel Command Mission and Installation Contracting Command Fort Eustis

About this file

This document is a Justification and Approval (J&A) for a sole source contract to SANS Innovation Center for providing cyber training and certification courses to the U.S. Army Cyber School (USACyS). The requirement is for two iterations of eight SANS courses (SEC560, SEC542, SEC580, SEC565, SEC599, SEC660, FOR508, SEC699) and six GIAC certifications (GPEN, GWAPT, GDAT, GCFA, GXPN, GRTP) with two practice tests for each certification over a 12-month base period from January 14, 2025 to January 13, 2026, with an option for a 6-month extension through July 13, 2026.

The sole source justification is based on SANS Innovation Center being the exclusive provider of SANS training and GIAC certifications, as validated through market research and a sources sought notice posted October 31, 2024 that received four responses but determined only SANS could meet the requirements. This procurement is a follow-on to contract W91249-24-C-0012 awarded July 18, 2024. The requirement stems from a USCYBERCOM mandate for USACyS to establish and execute an Advanced Cyber Operations-Academics (AOC-A) functional course. The contract will be awarded as a firm-fixed-price commercial item acquisition under FAR 13.5 simplified procedures.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Control No: MICC 2025-11

JUSTIFICATION REVIEW DOCUMENT

FAR 13.5 SIMPLIFIED PROCEDURES FOR CERTAIN COMMERCIAL ITEMS

SOLE SOURCE JUSTIFICATION AND APPROVAL

Program/Equipment: The U.S. Army Cyber School (USACyS) has a recurring requirement to procure SANS Innovation Center’s Global Information Assurance Certification (GIAC) prep course curriculum and certification to establish, administer, and execute an Advanced Cyber Operations -Academics (AOC-A) functional course.

Authority: Simplified Procedures for Certain Commercial Items, Title 41 U.S.C. 1901 as implemented by FAR 13.5.

Amount:

Contracting Officer: Ashley Scott Contracting Officer Email: ashley.t.scott3.civ@army.mil

DSN: 780-9208

Date: 30 OCT 24

Reviews: I have reviewed this justification and find it adequate to support sole source.

FAR 13.5 Simplified Procedures for Certain Commercial Items

Sole Source Justification and Approval

1. Contracting Activity: U.S. Army Mission and Installation Contracting Command (MICC)-Fort Eisenhower, 271 Heritage Park Lane, Bldg. 35200, Fort Eisenhower, GA 30905.

2. Description of Action: U.S. Army Cyber School (USACyS) requests a firm-fixed-price contract with SANS Innovation Center, located at 11200 Rockville Pike, Suite 200 North Bethesda, MD 20852, for the listed Global Information Assurance Certification (GIAC) certifications and SANS prep course curriculum. The Government projects fiscal year 2025 award for January 2025 and FY25 Operations and Maintenance, Army (OMA) funds will be used. This requirement is subject to availability of funds due to the Government is currently operating under a continuing resolution.

An acquisition plan is not required because this procurement does not meet the threshold at Defense Federal Acquisition Regulation Supplement 207.103(d)(i)(B).

This action is a follow-on to contract W91249-24-C-0012. That contract was not competed under authority Simplified Procedures for Certain Commercial Items, Title 41 U.S.C. 1901 as implemented by FAR 13.5 Exclusive Licensing Agreements.

3. Description of Services: SANS Innovation Center will provide two iterations of eight SANS courses (SEC560, SEC542, SEC580, SEC565, SEC599, SEC660, FOR508, SEC699), six GIACs (GPEN, GWAPT, GDAT, GCFA, GXPN, and GRTP), and two practice tests for each GIAC over the base performance period of 12 months. In addition, SANS Innovation Center will provide instruction and certification opportunities for all classes in the 500 and 600 series as requested to account for future changes to AOC-A training requirements. If FAR Clause 52.217-8 is executed for an additional 6 months of performance, then SANS Innovation Center will provide eight SANS courses (SEC560, SEC542, SEC580, SEC565, SEC599, SEC660, FOR508, SEC699), six GIACs (GPEN, GWAPT, GDAT, GCFA, GXPN, and GRTP), and two practice tests for each GIAC during this 6-month period.

Technical Salient Characteristics for each Course are listed below a Learning Outcome (LO) / Terminal Learning Objective (TLO) and the Enabling Learning Objectives (ELOs) support activities associated to each LO/TLO.

a. Course: SEC 560 - Enterprise Penetration Testing Certification: GIAC Penetration Tester (GPEN) Learning Outcome/TLO: Learn how to plan, prepare, and execute a penetration test in a modern enterprise.

Perform detailed reconnaissance to aid in social engineering, phishing, and making well-informed attack decisions

Scan target networks using best-of-breed tools to identify systems and targets that other tools and techniques may have missed

Perform safe and effective password guessing to gain initial access to the target environment, or to move deeper into the network

Exploit target systems in multiple ways to gain access and measure real business risk

Execute extensive post-exploitation to move further into the network

Use privilege escalation techniques to elevate access on Windows or Linux systems, or the Microsoft Windows domain

Perform internal reconnaissance and situational awareness tasks to identify additional targets and attack paths

Execute lateral movement and pivoting to further extend access to the organization and identify risks missed by surface scans

Crack passwords using modern tools and techniques to extend or escalate access

Use multiple Command and Control (C2, C&C) frameworks to manage and pillage compromised hosts

Attack the Microsoft Windows domain used by most organizations

Execute multiple Kerberos attacks, including Kerberoasting, Golden Ticket, and Silver Ticket attacks

Conduct Azure reconnaissance

Execute Azure Active Directory (AD) password spray attacks

Execute commands in Azure using compromised credentials

Develop and deliver high-quality reports

b. Course: SEC 542 - Web App Penetration Testing and Ethical Hacking

Certification: GIAC Web Application Penetration Tester (GWAPT) Learning Outcome/TLO: Understand common web application flaws, as well as how to identify and exploit them with the intent of demonstrating the potential business impact.

Apply OWASP's methodology to your web application penetration tests to ensure they are consistent, reproducible, rigorous, and under quality control

Analyze the results from automated web testing tools to validate findings, determine their business impact, and eliminate false positives

Manually discover key web application flaws

Use Python to create testing and exploitation scripts during a penetration test

Discover and exploit SQL Injection flaws to determine true risk to the victim organization

Understand and exploit insecure deserialization vulnerabilities with ysoserial and similar tools

Create configurations and test payloads within other web attacks

Fuzz potential inputs for injection attacks with ZAP, BurP'S Intruder and ffuf

Explain the impact of exploitation of web application flaws

Analyze traffic between the client and the server application using tools such as the Zed Attack Proxy and BurpSuite Pro to find security issues within the client-side application code Manually discover and exploit Cross-Site Request Forgery (CSRF) attacks

Manually discover and exploit Server-Side Request Forgery (SSRF) attacks

Use the Browser Exploitation Framework (BeEF) to hook victim browsers, attack client software and the network, and evaluate the potential impact that XSS flaws have within an application

Use the Nuclei tool to perform scans of target web sites/servers

Perform two complete web penetration tests, one during the five sections of course instruction, and the other during the Capture the Flag exercise

c. Course: SEC 580 - Metasploit for Enterprise Penetration Testing

Certification: None Learning Outcome/TLO: Learn how to apply the capabilities of the Metasploit Framework in a comprehensive penetration testing and vulnerability assessment regimen, and according to a thorough methodology for performing effective tests.

Guided Overview of Metasploit's Architecture and Components

Deep Dive into the Msfconsole Interface, including Logging and Session Manipulation

Careful and Effective Exploitation

The Ultimate Payload: The Metasploit Meterpreter In-Depth

Metasploit's Integration into a Professional Testing Methodology

Automation with Meterpreter Scripts to Achieve More in Less Time with Consistency

Using Metasploit as a Recon Tool

Using Auxiliary Modules to Enhance your Testing

Ultra-Stealthy Techniques for Bypassing Anti-Virus Tools

Client-Side Attacks - Using One-Liners instead of Executables

Port and Vulnerability Scanning with Metasploit, Including Integration with Nmap, Nessus, and Qualys

Capturing SMB Credentials and Metasploit's awesome PowerShell integration

Merciless Pivoting: Routing Through Exploited Systems

Exposing Metasploit's Routing Using SOCKS Proxies

Privilege Escalation Attacks

Metasploit's Integration with Other Tools

Making the Most of Windows Payloads

Advanced Pillaging - Gathering Useful Data from Compromised Machines

Evading Countermeasures to Mimic Sophisticated Attackers

Scripting Up the Meterpreter to Customize Your Own Attacks

Persisting Inside an Environment

Carefully Examining Your Attack's Forensic Artifacts

Integration with CrackMapExec, a Stand-alone Testing Tool

Command and Control via Third-Party Infrastructure

d. Course: SEC 565 - Red Team Operations and Adversary Emulation

Certification: GIAC Red Team Professional Certification (GRTP) Learning Outcome/TLO: Learn how to plan and execute end-to-end Red Teaming engagements that leverage adversary emulation, including the skills to organize a Red Team, consume threat intelligence to map against adversary tactics, techniques, and procedures (TTPs), emulate those TTPs, report and analyze the results of the Red Team engagement, and ultimately improve the overall security posture of the organization.

Use threat intelligence to study adversaries for emulation

Build an adversary emulation plan

Map actions to MITRE® ATT&CK™ to aid in communicating with the Blue Team

Establish resilient, advanced C2 infrastructure

Maintain operational security throughout an engagement

Leverage initial access to elevate and propagate through a network

Enumerate and attack Active Directory

Collect and exfiltrate sensitive data in a safe manner

Close an engagement, deliver value, and plan for retesting

e. Course: SEC 599 - Defeating Advanced Adversaries-Purple Team Tactics & Kill

Chain Defenses Certification: GIAC Defending Advanced Threats (GDAT) Learning Outcome/TLO: Learn security controls aimed at stopping, detecting, and responding to your adversaries through a purple team strategy.

Leveraging MITRE ATT&CK as a "common language" in the organization

Building your own Cuckoo sandbox solution to analyze payloads

Developing effective group policies to improve script execution (including PowerShell, Windows Script Host, VBA, HTA, etc.)

Highlighting key bypass strategies for script controls (Unmanaged Powershell, AMSI bypasses, etc.)

Stopping 0-day exploits using ExploitGuard and application whitelisting

Highlighting key bypass strategies in application whitelisting (focus on AppLocker)

Detecting and preventing malware persistence

Leveraging the Elastic stack as a central log analysis solution

Detecting and preventing lateral movement through Sysmon, Windows event monitoring, and group policies

Blocking and detecting command and control through network traffic analysis

Leveraging threat intelligence to improve your security posture

f. Course: SEC 660 - Advanced Penetration Testing, Exploit Writing, and Ethical

Hacking Certification: GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Learning Outcome/TLO: Learn how to model the abilities of an advanced attacker to find significant flaws in a target environment and demonstrate the business risk associated with these flaws.

Perform fuzz testing to enhance your company's SDL process

Exploit network devices and assess network application protocols

Escape from restricted environments on Linux and Windows

Test cryptographic implementations

Model the techniques used by attackers to perform 0-day vulnerability discovery and exploit development

Develop more accurate quantitative and qualitative risk assessments through validation

Demonstrate the needs and effects of leveraging modern exploit mitigation controls

Reverse-engineer vulnerable code to write custom exploits

Exploit routing protocol implementations such as OSPF

Bypass different types of NAC implementations

Exploit patch updates

Perform man-in-the-middle attacks to remove SSL

Perform IPv6 attacks

Exploit poor cryptographic implementations using CBC bit flipping attacks and hash length extension attacks

Hijack network booting environments

Exploit virtualization implementations

Write Python scripts to automate testing

Write fuzzers to trigger bugs in software

Reverse-engineer applications to locate code paths and identify potential exploitable bugs

Debug Linux applications

Debug Windows applications

Write exploits against buffer overflow vulnerabilities

Bypass exploit mitigations such as ASLR, DEP, stack canaries, SafeSEH, etc

Use ROP to bypass or disable security controls

g. Course: FOR 508 - Advanced Incident Response, Threat Hunting, and Digital

Forensics Certification: GIAC Certified Forensic Analyst (GCFA) Learning Outcome/TLO: Learn advanced skills to hunt, identify, counter, and recover from a wide range of threats within enterprise networks, including APT nation-state adversaries, organized crime syndicates, and hactivists.

Understand attacker tradecraft to perform compromise assessments

Detect how and when a breach occurred

Quickly identify compromised and infected systems

Perform damage assessments and determine what was read, stolen, or changed

Contain and remediate incidents of all types

Track adversaries and develop threat intelligence to scope a network

Hunt down additional breaches using knowledge of adversary techniques

Learn and master the tools, techniques, and procedures necessary to effectively hunt, detect, and contain a variety of adversaries and to remediate incidents

Detect and hunt unknown live, dormant, and custom malware in memory across multiple Windows systems in an enterprise environment

Hunt through and perform incident response across hundreds of unique systems simultaneously using PowerShell, Velociraptor, and the SIFT Workstation

Identify and track malware beaconing outbound to its command and control (C2) channel via memory forensics, registry analysis, and network connection residue

Determine how the breach occurred by identifying the root cause, the beachhead systems and initial attack mechanisms

Identify living off the land techniques, including malicious use of PowerShell and WMI

Target advanced adversary anti-forensics techniques like hidden and time-stomped malware, along with living off the land techniques used to move in the network and maintain an attacker's presence

Use memory analysis, incident response, and threat hunting tools in the SIFT Workstation to detect hidden processes, malware, attacker command lines, rootkits, network connections, and more

Track user and attacker activity second-by-second on the system you are analyzing through in-depth timeline and super-timeline analysis

Recover data cleared using anti-forensics techniques via Volume Shadow Copy/Restore Point analysis

Identify lateral movement and pivots within your enterprise across your endpoints, showing how attackers transition from system to system without detection

Understand how the attacker can acquire legitimate credentials - including domain administrator rights - even in a locked-down environment

Track data movement as attackers collect critical data and shift it to exfiltration collection points

Recover data cleared using anti-forensics techniques via Volume Shadow Copy and Restore Point analysis and artifact carving

Use collected data to perform effective remediation across the entire enterprise

Build advanced forensics skills to counter anti-forensics and data hiding from technical subjects

h. Course: SEC 699 - Purple Team Tactics-Adversary Emulation for Breach

Prevention & Detection Certification: None Learning Outcome/TLO: Learn how adversarial techniques can be emulated and detected.

A course section on typical automation strategies such as Ansible, Docker and Terraform. These can be used to deploy a full multi-domain enterprise environment for adversary emulation at the press of a button

Building a proper process, tooling, and planning for purple teaming

Building adversary emulation plans that mimic real-life threat actors such as APT-28, APT-34, and Turla in order to execute these plans using tools such as Covenant and Caldera forth by USCYBERCOM to meet their overall objective to establish, administer, and execute an Advanced Cyberspace Operations Course-Academics (AOC-A) Functional Course.

6. Efforts to Obtain Competition: The Contracting Officer shall publish the notices required by FAR 5.201. Accordingly, a sources sought notice was posted to SAM.GOV by MICC-Fort Eisenhower on 31 October 2024. The sources sought notice included a statement of salient characteristics, and detailed specifications of the requirement.

There were four (4) responses received from multiple vendors stating they could provide the requirement. However, the capability statement provided by SANS was the only vendor deemed technically capable by the requiring activity upon review. Market research consisted of internet research of vendors website, literature reviews, other professional resources and industry events.

In addition, pursuant to Title 48 CFR Part 19.705-2, as implemented by Federal

Acquisition Regulation FAR 19.705-2, the Contracting Officer must determine whether a proposed contractual action requires a subcontracting plan. For this requirement, the Contracting Officer has determined that there are no subcontracting possibilities and that no subcontracting plan is required. This determination shall include a detailed rationale and be placed in the contract file.

7. Actions to Increase Competition: No other competition is available. SANS Innovation Center is the sole provider of SANS training and Global Information Assurance Certification (“GIAC") certifications. A sole source letter was provided by SANS stating they have the exclusive right to produce official SANS Curriculum and deliver SANS training through SANS Certified Instructors. The USACyS continually researches sources of information to determine the availability of other providers of the GIAC certifications in a package along with commercially available training that could potentially meet the Government’s need in the open market.

8. Market Research: USACyS conducted research in September 2024 through internet inquiries and on the General Services Administration (GSA) Advantage web site to determine if required products are available through Federal Supply Schedules (FSS). The required products were not available through FSS. USCYBERCOM validated this requirement for the USACyS to deliver the AOC-A functional course to their military and civilian personnel. The specific identified SANS curriculum was approved after conducting extensive market research of multiple companies to provide specific modules to include the GIAC certifications. Results of the market research concluded that SANS is the only vendor that provides the core cyber related curriculum and GIAC certifications required to conduct training. This process was conducted in coordination with a partner agency and cannot be deviated from without the expressed direction of the USCYBERCOM J7. AOC-A consists of eight SANS Innovation Center courses and six corresponding GIAC certifications. A sources sought notice was posted by the Contracting Specialist at MICC-Fort Eisenhower to SAM.GOV on 31 October 2024 and a total of four (4) responses were received. The capabilities statements were reviewed by the Contracting Officer and the requiring activity. It was deemed that only

d. This mandate to establish, administer, and execute an Advanced Cyberspace

Operations Course-Academics (AOC-A) Functional Course was communicated from USCYBERCOM J-7 via signed course growth sponsorship memorandum.

File details come from the government source that posted it. Updated .