Applied_Cyber_Operations_Training_TTL_28_Jan_2016.xlsx

XLSX spreadsheet 164 KB Posted

Attached to
Applied Cyber Operations Training Federal contract opportunity
Solicitation number
FA8773-16-Q-8001
Issued by
Department of the Air Force Space Command

About this file

Applied Cyber Operations Training (ACOT) Task Training List

View the file

Other files for this federal contract opportunity

Other files attached to Applied Cyber Operations Training, newest first.
File Type Posted
ACOT_Questions__4.docx DOCX document
AFMAN36-2236_(12_Nov_2003).pdf PDF
ACOT_Questions__3.docx DOCX document
ACOT_Questions__2.docx DOCX document
252-209-7999.pdf PDF
ACOT_Questions__1.docx DOCX document
FAR_52.212-3(b).docx DOCX document
ACOT_Performance_Work_Statement_28_Jan_16.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Definitions

1. Knowledge/Performance Standards.
SUBJECT KNOWLEDGE LEVELSACan identify basic facts and terms about the subject. (FACTS)
BCan identify relationship of basic facts and state general principles about the subject. (PRINCIPLES)
CCan analyze facts and principles and draw conclusions about the subject. (ANALYSIS)
DCan evaluate conditions and make proper decisions about the subject. (EVALUATIONS)
TASK PERFORMANCE LEVELS1Can do simple parts of the task. Needs to be told or shown how to do most of the task
2Can do most parts of the task. Needs help only on the hardest part
3Can do all parts of the task. Needs only a spot check of completed work
4Can do the complete task quickly and accurately. Can tell or show how to do the task
TASK KNOWLEDGE LEVELSaCan name parts, tools and simple facts about the task
bCan determine step-by-step procedures for doing the task
cCan identify why and when the task must be done and why each step is needed
dCan predict, isolate and resolve problems about the task

Tasks

1.2BASIC NETWORK ARCHITECTURE
1.2.1Transmission mediumsB
1.2.2Server FunctionsB
1.8PROTOCOLS and PACKET CAPTURES
1.8.18Demonstrate ability to break-out NetBIOSD
1.8.19Demonstrate ability to break-out SSLD
1.8.20Demonstrate ability to break-out RPCD
Demonstrate ability to break-out Server Message Block (SMB)
2.2File System Structure
2.2.6List the characteristics of local and domain user accountsC
2.2.7Describe Windows security issuesC
2.3Identify Windows Registry concepts & keys
2.5Operating System Functions
2.6Windows Command Line
2.6.1Master System Administration from the Windows command lineD
2.6.2Windows PowerShellD
2.6.3Windows Management InstructionD
3*NIX (e.g., UNIX, LINUX)
6.1NETWORK SECURITY
6.1.1Discuss access control concepts (e.g. Access Control List)B
6.1.2Define the principles and methods of authenticationB
6.1.3Provide an overview of the various threats to web securityD
6.1.4B
6.1.5List and Identify recognized industry standards and recommendations that address information and network securityB
6.1.6Recognize the reasons for implementing Network SecurityB
6.1.7D
6.1.8Overview the general categories of network security threats (e.g. DoS, password, man-in-the-middle)D
6.1.9Identify the vulnerabilities of various network protocols (e.g. TCP, SNMP, UDP, SMTP, FTP)D
6.1.10D
6.1.11Identify relationship between vulnerabilities and exploitsD
6.1.12Identify techniques used to evade intrusion detection systemsD
6.1.13Describe the basic operation of network security devices (e.g. firewalls, proxy servers, mail relays etc.)D
6.1.14Describe basic concepts of NATD
6.1.15Describe basic concepts of [default deny/allow by exceptionB
6.1.17Understand the threat of an attack from inside your networkD
7REMOTE ACCESS

Sheet3

TASK NUMBERTASK DESCRIPTIONAFCTPAir Force Contract Class Requirement
1NETWORK FUNDAMENTALS AND PACKET ANALYSIS
1.1Network Types
1.1.1Purposes and Functions of NetworkingAB
1.1.2Physical and Logical NetworksAB
1.1.3Purpose and Limitations of a Local Area Network (LAN)AB
1.1.4Purpose and Limitations of a Wide Area Network (WAN)AA
1.1.5Purpose and Limitations of a Metropolitan Area Network (MAN)AA
1.1.6Purpose and Limitations of a Virtual Private Network (VPN)AA
1.1.7Purpose and Limitations of a Virtual Local Area Network (VLAN)AA
1.1.8Purpose and Limitations of a Personal Area Network (PAN)AA
1.1.9Purpose and Limitations of a Wireless LAN & MANAA
1.1.10Purpose and Limitations of a Peer-to-Peer networkAB
1.1.11Purpose and Limitations of a Client-Server networkAB
1.2Network Topologies
1.2.1Bus topologyAA
1.2.2Star topologyAA
1.2.3Tree topologyAA
1.2.4Ring topologyAA
1.2.5Mesh topologyAA
1.2.6Hybrid topologyAA
1.2.7Token Ring topologyAA
1.3Network Devices
1.3.1Functions and Limitations of a hubBC
1.3.2Functions and Limitations of a switchBC
1.3.3Functions and Limitations of a bridgeBC
1.3.4Functions and Limitations of a routerBC
1.3.5Functions and Limitations of a firewallBC
1.3.6Characteristics and Features of Network Intrusion Detection and Intrusion Prevention Systems (IDS / IPS)BC
1.3.7Functions and Limitations of a proxy serverBC
1.3.8Functions and Limitations at each layer (router, CPU, switch, hub, etc)BC
1.4Networking Models
1.4.1Open Systems Iinterconnect (OSI) LayersBC
1.4.2Telecommunications Protocol (TCP) LayersBC
1.4.3Functions Associated at each layerBC
1.4.4Major Protocols used at each layerBC
1.4.5Principles of protocols and layered architecturesBC
1.4.6Connection-oriented protocols (TCP)BC
1.4.7Connectionless protocols (UDP)BC
1.5TCP/IP (Telecommunications Protocol / Internet Protocol)
1.5.1Characteristics of TCP/IPBB
1.5.2Telecommunications Protocol (TCP)BB
1.5.3Connection-oriented protocols and data transportBB
1.5.4Fundamentals of IPv4 addressingBB
1.5.5IPv4 header fieldsB2b
1.5.6Hierarchical addressing schemeBB
1.5.7Flat address schemesBB
1.5.8Hierarchical address schemesBB
1.5.9Fundamentals of IPv6 addressingAB
1.5.10IPv6 header fieldsA2b
1.5.11MAC addressingBB
1.5.12CSMA/CDBB
1.5.13CSMA/CA,BB
1.5.14Token PassingBB
1.5.15802.2 LLC header fields2b2b
1.5.16802.3 frame fields2b2b
1.5.17802.3 with SNAP header fields2b2b
1.5.18Static IP addressingBB
1.5.19Dynamic IP addressingBB
1.5.20Network Address Translation (NAT) addressingBB
1.5.21Network address classesBB
1.5.22Classful addressingBB
1.5.23Classless addressingBB
1.5.24Network IDs and broadcast addressesBB
1.5.25TCP 3-way handshakeBB
1.5.26TCP 4-way handshakeBB
1.5.27TCP Sequence and Acknowledgement numbers2b2b
1.5.28Transmissions sequence numbers2b2b
1.5.29TCP header Fields2b2b
1.5.30User Datagram Protocol (UDP)BB
1.5.31UDP header FieldsB2b
1.5.32EncapsulationBB
1.5.33FragmentationAB
1.5.34ReassemblyBB
1.5.35Packet Tracing through a networkAC
1.5.36Ethernet frame headers in hexidecimal2b3c
1.5.37TCP headers in hexidecimal2b3c
1.5.38UDP headers in hexidecimal2b3c
1.6Ports, Protocols and Services
1.6.1Services and Protocols with portsBB
1.6.2Address Resolution Protocol (ARP)BB
1.6.3ARP packetsB2c
1.6.4Internet Control Message Protocol (ICMP)BC
1.6.5ICMP packetsB2c
1.6.6ICMP Messages and CodesBC
1.6.7Windows ICMP messagesB3c
1.6.8Unix ICMP messagesB3c
1.6.9Operating System (OS) fingerprinting from ICMP messagesB3c
1.6.10PingBC
1.6.11TracerouteBC
1.6.12Traceroute/Tracert using hexidecimal dumpB2c
1.6.13Windows traceroutesB3c
1.6.14*nix traceroutesB3c
1.6.15Latency issues (undersea cable, Satellite transmissions, etc)AB
1.6.16Internet Group Management Protocol (IGMP) messagesB
1.6.17File Transfer Protocol (FTP) trafficB2c
1.6.18Trivial File Transfer Protocol (TFTP) trafficB2c
1.6.19TelnetBB
1.6.20Telnet traffic Analysis3c
1.6.21Secure Shell (SSH)BB
1.6.22SSH traffic Analysis1a2b
1.6.23Simple Mail Transfer Protocol (SMTP)AB
1.6.24SMTP packets AnalysisA2b
1.6.25Post Office Protocol (POP)AB
1.6.26Internet Message Access Protocol (IMAP)AB
1.6.27Simple Network Management Protocol (SNMP)AC
1.6.28Domain Name Service (DNS)BC
1.6.29DNS resolution (Identify Zone Transfers, DNS Name Queries) Process Mapping2b3c
1.6.30Dynamic Host Configuration Protocol (DHCP)BC
1.6.31DHCP process diagram2b3c
1.6.32Hypertext Transfer Protocol (HTTP)BC
1.6.33HTTP request mapping and diagram1a3c
1.6.34Hypertext Transfer Protocol over Secure Socket Layer (HTTPS)1a3c
1.7Number Conversions (Convert each of the following Into another type)
1.7.1Whole Numbers2b2b
1.7.2Binary Numbers2b2b
1.7.3Hexadecimal Numbers2b2b
1.7.4Big EndianB2b
1.7.5Little EndianB2b
1.7.6Network Subnetting2b2b
2NETWORK FORENSICS
2.1Packet sniffingBB
2.2IP spoofing attacksBB
2.3ability to use Wireshark tool2b2b
2.4ability to use tcpdump2b2b
2.5Analyze, decode, and decipher, and malicious traffic2b2b
2.6ICMP RedirectionB
2.7Host Discovery Scanning technique prediction through packet captures2b2b
2.8Vulnerability Scanning technique recognition through packet captures2b2b
2.9MAC Spoofing techniquesA2b
2.10Executables and files carving from packet captures using various command line tools2b2b
2.11Characteristics of network attacks through packet captures2b2b
2.12Berkley Packet Filters2b2b
3WINDOWS OPERATOR FUNDAMENTALS
3.1Windows History
3.1.1History and evolution of Windows through Windows 8/2012 serverBA
3.2System Architecture
3.2.1User modeBB
3.2.2Kernel modeBB
3.2.3Core Windows system files both pre Windows Vista and post Windows Vista
3.2.3.1ntdll.dllBB
3.2.3.2Boot.iniBB
3.2.3.3NtdetectBB
3.2.3.4Ntoskrnl.exeBB
3.2.3.5Hal.dllBB
3.2.3.6Smss.exeBC
3.2.3.7Win32k.sysBB
3.2.3.8Csrss.exeBC
3.2.3.9Winlogon.exeBC
3.2.3.10Services.exeBC
3.2.3.11Kernel32.dllBB
3.2.3.12advapi32.dllBB
3.2.3.13User32.dllBB
3.2.3.14Gdi32.dllBB
3.2.4Architecture differences between 32 bit and 64 bit versions of Windows
3.2.4.1C:\Windows\SysWOW64 vs C:\Windows\System32BB
3.2.4.2HKLM\SOFTWARE\Wow6432NodeBB
3.2.4.3C:\Program Files" vs "C:\Program Files (x86)BB
3.2.5Windows File Protection (WFP)/Windows Resource Protection (WRP)B
3.2.6Security Identifiers (SIDs), Access Tokens and Access ControlBB
3.3Windows Boot Process
3.3.1Windows Kernel 5.x boot processBB
3.3.2Windows Kernel 6.x boot processBB
3.3.3BitLocker boot processBB
3.3.4Master Boot Record (MBR)BB
3.3.5ntldrBB
3.3.6ntdetectBB
3.3.7boot.iniBB
3.3.8BootmgrBB
3.3.9winload.exeBB
3.3.10Boot Configuration Data (BCD)BB
3.3.11Windows 8 rootkit countermeasuresA
3.3.12Windows 8 bootkit countermeasuresA
3.4Windows File System Structure
3.4.1File system basics
3.4.1.1DOS partition table data structureBB
3.4.1.2Extended partitionsBB
3.4.1.3Volume Boot Record (VBR)BB
3.4.1.4Data allocationBB
3.4.1.5Slack spaceBB
3.4.1.6BitLocker drive encryptionBB
3.4.2File Allocation Table (FAT) structure
3.4.2.1FAT 32BB
3.4.2.2FAT32 boot sector data structureBB
3.4.2.3FAT32 metadataBB
3.4.2.4FAT32 timestampsBB
3.4.2.5Mount FAT32 file system images using command line tool - mmlsB2b
3.4.3New Technology File System (NTFS)
3.4.3.1Master File Table (MFT)BB
3.4.3.2Resident attribute structureBB
3.4.3.3Non-resident attribute structureBB
3.4.3.4Standard file attributesBB
3.4.3.5MFT extraction from NTFS image using command line tool - icatB2b
3.4.3.6file deletion from NTFS systemsBB
3.4.3.7recovery from NTFS systemsBB
3.4.4Encrypting File System (EFS) securityBB
3.4.5MAC timestamp changes in regards to copying and moving files and foldersB3c
3.5Windows Registry
3.5.1Windows Registry Components2b3c
3.5.2Windows Registry Hierarchy2bB
3.5.3HKEY_Classes_RootBB
3.5.4HKEY_Current_User2bB
3.5.5HKEY_Local_Machine2bB
3.5.6HKEY_LOCAL_MACHINE\SystemBB
3.5.7HKEY_LOCAL_MACHINE\HardwareBB
3.5.8HKEY_LOCAL_MACHINE\SoftwareBB
3.5.9HKEY_LOCAL_MACHINE\SAMBB
3.5.10HKEY_LOCAL_MACHINE\SecurityBB
3.5.11HKEY_UsersBB
3.5.12HKEY_Current_ConfigBB
3.5.13Key registry values manipulation for malicious means.BB
3.5.14Key registry values manipulation for defensive means.BB
3.5.15ntuser.dat2bB
3.5.16UserAssist key2bB
3.6Windows File System Artifacts
3.6.1Directory structure (2000 vs XP vs Vista vs 7+)
3.6.1.1Web browser artifacts (IE, Firefox, Chrome) storageBB
3.6.1.2Windows junctionsB
3.6.1.3Cookies and temporary internet files storageBB
3.6.1.4History foldersBB
3.6.1.5Windows volume shadow copyBB
3.6.1.6VSSADMINBB
3.6.1.7Recycle Bin composition
3.6.1.7.1INFO2 recordsBB
3.6.1.7.2$MFT recordsBB
3.6.1.7.3File deletionBB
3.6.1.7.4File restorationBB
3.6.2Windows Event Logs
3.6.2.1System logs2b2b
3.6.2.2Security logs2b2b
3.6.2.3Application logs2b2b
3.6.3Prefetch files
3.6.3.1Prefetch file disection (using open source tools)2b3c
3.6.3.2deleted prefetch files recovery2b3c
3.6.3.3Prefetch registry informationBB
3.7Windows Process Execution
3.7.1User modeBB
3.7.2Kernal ModeBB
3.7.3Windows subsystemBB
3.7.4ProcessesBB
3.7.5ThreadsBB
3.7.6MemoryBB
3.7.7PagingBB
3.7.8Windows APIBB
3.7.9Windows dll loadingBB
3.7.1032bit process execution on 64bit versions of WindowsBB
3.7.1164bit process execution on 64bit versions of WindowsBB
3.7.12Import Address Table (IAT)BB
3.7.13Relative Virtual Addresses (RVA)BB
3.8Windows Networking
3.8.1Windows\System32BB
3.8.2Windows\System32\driversBB
3.8.3Windows\System32\drivers\etc\hosts (cover all key files)BB
3.8.4IP address addition via GUI2b3c
3.8.5Manually add a route2b3c
3.8.6local user accounts2b3c
3.8.7domain user accounts2b3c
3.8.8Windows security issues
3.8.8.1LAN Manager (LM)BB
3.8.8.2NT LAN Manager (NTLM)BB
3.8.8.3NT LAN Manager version 2 (NTLMv2)BB
3.8.8.4LM with respect to password securityBB
3.8.8.5NTLM with respect to password securityBB
3.8.8.6NTLMv2 with respect to password securityBB
3.8.8.7User Account Control (UAC)BB
3.8.8.8Kerberos in a Windows domain environmentBB
3.8.8.9Kerberos Key Distribution Center (KDC)BB
3.8.8.10Authentication Service (AS) function of the KDCBB
3.8.8.11Ticket-Granting Service (TGS) function of the KDCBB
3.8.8.12the Kerberos Ticket Exchange processBB
3.8.8.13Kerberos authentication process when a domain user logs into a computer using a domain account.BB
3.8.8.14the authentication process when a non-domain user logs into a computer using a local account.BB
3.8.9Windows Specific ServicesBB
3.8.10Windows sockets and named pipesBB
3.8.11Process Interrogation
3.8.11.1ports associated with a given processB3c
3.8.11.2files handles associated with a given process2b3c
3.8.11.3identify strings in an executable/binary2b3c
3.9Windows Command Line
3.9.1Windows 32-bit cmd shellBB
3.9.2Environment VariablesBB
3.9.3Windows system information commands
3.9.3.1whoami2b3c
3.9.3.2hostname2b3c
3.9.3.3ver2b3c
3.9.3.4driveryquery2b3c
3.9.3.5systeminfo2b3c
3.9.3.6doskey3c
3.9.3.7date2b3c
3.9.3.8auditpol2b3c
3.9.4Windows file system functions using the following commands
3.9.4.1cd2b3c
3.9.4.2mkdir2b3c
3.9.4.3type2b3c
3.9.4.4move2b3c
3.9.4.5rename2b3c
3.9.4.6chdir2b3c
3.9.4.7del2b3c
3.9.4.8rmdir2b3c
3.9.4.9dir2b3c
3.9.4.10tree2b3c
3.9.4.11where2b3c
3.9.4.12find2b3c
3.9.4.13findstr2b3c
3.9.4.14copy2b3c
3.9.4.15xcopy3c
3.9.4.16attrib2b3c
3.9.4.17assoc2b3c
3.9.4.18sort2b3c
3.9.4.19echo2b3c
3.9.4.20shutdown2b3c
3.9.4.21reg2b3c
3.9.5Windows chaining commands2b3c
3.9.6Windows batch scripts1a3c
3.9.7Windows tasks using the command line2b3c
3.9.8hard disk configuration and maintenance using the following Windows commands
3.9.8.1label1a
3.9.8.2format1a
3.9.8.3mountvol1a
3.9.8.4fsutil2b3c
3.9.8.5chkdsk1a
3.9.8.6defrag1a
3.9.8.7cipher2b2b
3.9.9Windows commands that manage permissions2b
3.9.9.1cacls2b2b
3.9.9.2icacls2b2b
3.9.10network and service-related functions using the following Windows commands2b
3.9.10.1ipconfig2b3c
3.9.10.2getmac3c
3.9.10.3ping2b3c
3.9.10.4tracert2b3c
3.9.10.5pathping1b
3.9.10.6netstat2b3c
3.9.10.7netsh2b3c
3.9.10.8netsh diag2b3c
3.9.10.9netsh interface2b3c
3.9.10.10netsh firewall2b3c
3.9.10.11netsh advfirewall2b3c
3.9.10.12netsh show2b3c
3.9.10.13netsh set2b3c
3.9.10.14net2b3c
3.9.10.15net accounts2b3c
3.9.10.16net config2b3c
3.9.10.17net group2b3c
3.9.10.18net localgroup2b3c
3.9.10.19net start2b3c
3.9.10.20net stop2b3c
3.9.10.21net pause2b2b
3.9.10.22net share2b3c
3.9.10.23net session2b3c
3.9.10.24net time2b3c
3.9.10.25net user2b2b
3.9.10.26net view2b3c
3.9.10.27net use2b3c
3.9.10.31nbtstat2b3c
3.9.10.32sc2b3c
3.9.10.33tasklist2b3c
3.9.11external, Windows command line tools
3.9.11.1psloggedon2b2b
3.9.11.2psinfo2b2b`
3.9.11.3fport2b
3.9.11.4pslist2b2b
3.9.11.5handle2b2b
3.9.11.6ntlast2b
3.9.11.7psloglist2b2b
3.9.11.8regdmp2b
3.9.11.9psfile2b
3.9.11.10process explorer2b2b
3.9.11.11logonsessions2b2b
3.9.12Windows Management Instrumentation (WMI)
3.9.12.1WMI from the command line2b2b
3.9.12.2WMIC interface commands2b2b
3.9.12.2.1wmic startup2b2b
3.9.12.2.2wmic service list2b2b
3.9.12.2.3wmic process list2b2b
3.9.12.2.4WMI Quick Fix Engineering2b2b
3.9.12.2.5wmic share list2b
3.9.12.2.6wmic sysaccount list2b
3.9.12.2.7wmic group list2b
3.9.12.2.8wmic useraccount2b
3.9.12.2.9wmic volume list2b
3.9.12.2.10wmic os list2b
3.9.12.2.11wmic nteventlog2b2b
3.9.12.2.12create a process using WMI2b2b
3.9.12.2.13wmic printer2b
3.9.12.3WMI commands remotely
3.9.12.3.1wmic share list2b
3.9.12.3.2wmic sysaccount list2b
3.9.12.3.3wmic group list2b
3.9.12.3.4wmic useraccount2b
3.9.12.3.5wmic volume list brief2b
3.9.13Windows PowerShell
3.9.13.1PowerShell command line2b2b
3.9.13.2PowerShell noninteractive sessions2b2b
3.9.13.3PowerShell CMDLETS2b2b
3.9.13.4PowerShell services Identification and control2b2b
3.9.13.5PowerShell ProcessList Extraction2b2b
3.9.13.6PowerShell ProcessInfo Extraction2b2b
3.9.13.7PowerShell loaded dll identification2b2b
3.9.13.8PowerShell start and stop processes2b2b
3.9.13.9PowerShell file system2b2b
3.9.13.10Powershell drive structure2b2b
3.9.13.11PowerShell Directory Walks2b2b
3.9.13.12PowerShell file and directory creation2b2b
3.9.13.13PowerShell share management2b2b
3.9.13.14PowerShell Windows registry navication2b2b
3.9.13.15PowerShell event log viewing2b2b
3.9.13.16PowerShell event log clearing2b2b
3.9.13.17Windows PowerShell remote use2b2b
4LINUX/UNIX OPERATOR FUNDAMENTALS
4.1basic concepts of *NIX
4.1.1*nix systems historyBB
4.1.2major *nix familiesAA
4.1.3kernel space and user spaceBB
4.1.4user spaceBB
4.1.5major methods of updating Linux distributionsBB
4.2Boot Process
4.2.1Hardware BootBB
4.2.2PeripheralsAA
4.2.3Boot DeviceBB
4.2.4OS LoaderBB
4.2.5LILO Loader (Linux)BB
4.2.6Grand Unified Bootloader (GRUB)BB
4.2.7Kernel purposeBB
4.2.8Device DetectionBB
4.2.9Driver Initialization processBB
4.2.10filesystem mountingBB
4.2.11/sbin/init2bB
4.2.12/var/log/dmesgBB
4.2.13Init process2b3c
4.2.14run levels2b3c
4.2.15start-up scripts location (e.g. /etc/rc.d, /etc/init.d, /etc/inittab, etc)
4.2.15.1/etc/rc.d/rc.sysinit contents2b3c
4.2.15.2/etc/rc.d/rc contents2b3c
4.2.15.3/etc/rc.d/rc.local contents2b3c
4.2.15.4/etc/rc.d/init.d/service contentsBB
4.2.16Service Management Facility (SMF) on Solaris operating systemsB
4.2.17systemd service management on linux operating systemsBB
4.2.18shell initialization process (getty/sshd)BB
4.3File Structure
4.3.1/binBB
4.3.2/sbinBB
4.3.3/bootBB
4.3.4/devBB
4.3.5/usrBB
4.3.6/svrBB
4.3.7/etcBB
4.3.8/varBB
4.3.9/libBB
4.3.10/optBB
4.3.11/mediaBB
4.3.12/mntBB
4.3.13/tmpBB
4.3.14/core "crash dump file"B
4.3.15bash_history2b2b
4.4Networking
4.4.1configure /etc/sysconfig/networkB3c
4.4.2configure /etc/rc.d/init.d/networkB3c
4.4.3configure /etc/sysconfig/network-scripts/ifcfg-eth0B3c
4.4.4/etc/sysconfig/network-scripts/route-eth02b3c
4.4.5/etc/sysconfig/network-scripts/eth0.route2b3c
4.4.6/etc/hosts configuration2b2b
4.4.7/etc/resolv.conf configuration2b2b
4.4.8/etc/inetd.conf configuration2b2b
4.4.9/etc/xinetd.conf configuration2b2b
4.4.10DHCP server configurationBB
4.4.11Process Interrogation2b3c
4.4.11.1ports associated with a given process2b3c
4.4.11.2files handles associated with a given process2b3c
4.4.11.3strings in an executable/binary2b3c
4.5Authentication
4.5.1/etc/passwd configuration2b2b
4.5.2/etc/shadow configuration2b2b
4.6Users
4.6.1User addition2b3c
4.6.2User deletion2b3c
4.7Command Line
4.7.1basic Unix commands and various switches
4.7.1.1ifconfig2b3c
4.7.1.2uname2b3c
4.7.1.3ps2b3c
4.7.1.4cat2b3c
4.7.1.5touch2b3c
4.7.1.6netstat2b3c
4.7.1.7chmod2b3c
4.7.1.8chown2b3c
4.7.1.9chgrp2b3c
4.7.1.10passwd2b3c
4.7.1.11echo2b3c
4.7.1.12cd2b3c
4.7.1.13pwd2b3c
4.7.1.14rm2b3c
4.7.1.15ls2b3c
4.7.1.16mkdir2b3c
4.7.1.17lsmod2b3c
4.7.1.18dmesg2b3c
4.7.1.19iptables2b3c
4.7.1.20sestatus/getenforce2b3c
4.7.1.21su2b3c
4.7.1.22ping2b3c
4.7.1.23grep/egrep2b3c
4.7.1.24sed1a2b
4.7.1.25awk1a2b
4.7.1.26head2b3c
4.7.1.27tail2b3c
4.7.1.28cut1a2b
4.7.1.29less2b3c
4.7.1.30watch1a2b
4.7.1.31wc2b3c
4.7.1.32unset2b
4.7.2Vi Editor to edit files2b3c
4.8Bash Scripting
4.8.1Regular expressionsB3c
4.8.2FunctionsB3c
4.8.3VariablesB3c
4.9Logging and Accounting
4.9.1SyslogBA
4.9.2UtmpxB1a
4.9.3WtmpxB1a
4.9.4Solaris kernel auditing2b
4.9.5System accountingB2b
4.9.6Process accountingB2b
4.9.7MAC timestamp changes in regards to copying and moving files and foldersB2b
4.10*nix Process Execution
4.10.1file permissions with regards to a user running a processBB
4.10.2daemonBB
4.10.3cron/crontabs2b2b
4.10.4cron job creation2b2b
4.10.5foreground process2b2b
4.10.6background process2b2b
4.10.7shared librariesBB
4.10.8LD_PRELOAD variableB
5DIGITAL MEDIA FORENSICS
5.1Forensic Methodology and Application2bA
5.1.1local device profile2b2b
5.1.2remote device profile2b2b
5.1.3Hash analysis2bA
5.1.4File Signature analysis2b2b
5.1.5keyword searching2b2b
5.1.6GREP expressions2b2b
5.1.7Advanced timeline analysis2b3c
5.1.8Windows file system and Registry artifacts2b3c
5.1.9incident response using the Windows command line2b2b
5.1.10Anti-Forensics techniques2bA
5.1.11Steganalysis2bA
5.1.12data hiding techniques2b1a
5.2Cryptography
5.2.1block ciphersBB
5.2.2stream ciphersBB
5.2.3encryptionBB
5.2.4encodingBB
5.2.5symmetric key algorithmsBB
5.2.6asymmetric key algorithmsBB
5.2.7PKIBB
5.2.8PGPBB
5.2.9TLS/SSLBB
5.2.10ROT13BA
5.3deleted partition recoveryBA
6REVERSE ENGINEERING MALWARE
6.1malicious code analysis2b2b
6.2malware analysis2b2b
6.3assembly languageBB
6.4register setsBB
6.5data typesBB
6.6memory formatsBB
6.7instruction formatsBB
6.8program executionBB
6.9Code analysis fundamentalsBB
6.10patching executablesBB
6.11Windows registry hierarchy2b3c
6.12Windows registry track changes2b3c
6.13malicious packet tracing through the networkB2b
6.14anomalous event prediction in network traffic1a
6.15defensive techniques in malwareB2b
6.16unpack packed code2b2b
6.17subverting virtual machine and debugger detectionAB
6.18evolution of a botnetAA
6.19evolution of a rootkitBB
6.20evolution of a dll injection2b2b
6.21evolution of a browser-based attackBB
6.22stack overflowBB
6.23heap overflowBB
6.24format string vulnerabilityBB
6.25techniques OSs and compilers use to try to prevent exploits (DEP, canaries, etc)BB
6.26techniques hackers use to bypass anti-hacking techniques (ROP, SEH chaining, etc)BB
7MEMORY FORENSICS
7.1malware behavior in memory2bB
7.2driver IRP hooksAA
7.3physical memory acquisition from a Windows system2bB
7.4malicious processes in memory from a memory dump2bB
7.5malicious drivers in memory from a memory dumpBB
7.6injected DLLs from a memory dumpBB
7.7rogue drivers from a memory dumpBB
7.8hooking malware from a memory dumpBB
8COMPUTER NETWORK EXPLOITATION AND ATTACK
8.1hacker methodologyBB
8.2footprinting techniques2b3c
8.3scanning techniques2b3c
8.4fingerprinting techniques:2b3c
8.4.1Nmap2b3c
8.4.2Ping2b3c
8.4.3traceroute2b3c
8.5enumeration techniques:
8.5.1SMTP2b3c
8.5.2SNMP2b3c
8.5.2SMB2b3c
8.5.3HTTP2b3c
8.6Google Hacking techniques2b3c
8.7Email harvesting2b2b
8.8netcat
8.8.1Port scanning using netcat2b3c
8.8.2Banner grabbing using netcat2b3c
8.8.3File transfer using netcat2b3c
8.8.4Chat using netcat2b3c
8.8.5Port listening using netcat2b3c
8.8.6Backdoor installation using netcat2b3c
8.9File Transfers
8.9.1TFTP2b3c
8.9.2Binary Decode2b3c
8.9.3Internet Explorer2b3c
8.9.4Web Transfers2b3c
8.9.5FTP2b3c
8.10Remote Access methods2b3c
8.11Man-in-the-Middle Attack2b
8.12ARP spoofing Attack
8.12.1ARP packet modification and transfer2b
8.12.2filter creation and ARP Spoof2b
8.13Sniffer Attack2b
8.14Application-layer Attacks2b
8.15Rootkits2b
8.16Buffer Overflow (Heap vs Stack)2b2b
8.17DNS Spoofing2b
8.18DoS Attack against a Windows host and server2b
8.19virus purposeBB
8.20wormBB
8.21trojanBB
8.22payloads used for exploitation2b3c
8.23bind shells2b3c
8.24reverse shells2b3c
8.25shellcode2b3c
8.26packet captures and remote exploitation2b3c
8.27packet captures and client-side exploitation2b3c
8.28remote Operatings Systems vulnerabilities2b3c
8.29Windows command line enumeration2b3c
8.30exploits packet captures2b2b
8.31Anti-Virus software subversion2b2b
8.32Intrusion Detection Systems evasion2b2b
8.33anti-virus software disabling2b2b
8.34Tradecraft techniques2b2b
8.35post exploitation artifact clean-up (housekeeping)2b2b
8.36persistent access on a remote machine2b2b
8.37rootkits (Installation and maintenance)2b3c
8.38DLL Hijacking techniques2b
8.39tunnel (forward and reverse) the following traffic:
8.39.1SSH2b2b
8.39.2DNS2b
8.39.3ICMP2b
8.39.4SSL2b2b
8.39.5HTTP2b2b
8.39.6TCP Exploits and Payloads2b2b
8.40elevate user privileges2b3c
8.41"pass the hash" technique2b3c
8.42Network Attack tactics2b2b
8.43data collection techniques on a remote system2b2b
8.44keylogger installation and remote keystrokes collection2b2b
8.45packet sniffer installation and remote traffic collection2b2b
8.46Administrator credentials remote recovery2b3c
8.47Windows survey scripts for remote target analysis2b3c
8.48malware behavior remotely2b2b
8.49security risks associated with remote access methods2b2b

File details come from the government source that posted it. Updated .