Applied_Cyber_Operations_Training_TTL_28_Jan_2016.xlsx
XLSX spreadsheet 164 KB Posted
- Attached to
- Applied Cyber Operations Training Federal contract opportunity
- Solicitation number
- FA8773-16-Q-8001
About this file
Applied Cyber Operations Training (ACOT) Task Training List
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| ACOT_Questions__4.docx | DOCX document | |
| AFMAN36-2236_(12_Nov_2003).pdf | ||
| ACOT_Questions__3.docx | DOCX document | |
| ACOT_Questions__2.docx | DOCX document | |
| 252-209-7999.pdf | ||
| ACOT_Questions__1.docx | DOCX document | |
| FAR_52.212-3(b).docx | DOCX document | |
| ACOT_Performance_Work_Statement_28_Jan_16.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Definitions
| 1. Knowledge/Performance Standards. | ||
| SUBJECT KNOWLEDGE LEVELS | A | Can identify basic facts and terms about the subject. (FACTS) |
| B | Can identify relationship of basic facts and state general principles about the subject. (PRINCIPLES) | |
| C | Can analyze facts and principles and draw conclusions about the subject. (ANALYSIS) | |
| D | Can evaluate conditions and make proper decisions about the subject. (EVALUATIONS) |
| TASK PERFORMANCE LEVELS | 1 | Can do simple parts of the task. Needs to be told or shown how to do most of the task |
| 2 | Can do most parts of the task. Needs help only on the hardest part | |
| 3 | Can do all parts of the task. Needs only a spot check of completed work | |
| 4 | Can do the complete task quickly and accurately. Can tell or show how to do the task |
| TASK KNOWLEDGE LEVELS | a | Can name parts, tools and simple facts about the task |
| b | Can determine step-by-step procedures for doing the task | |
| c | Can identify why and when the task must be done and why each step is needed | |
| d | Can predict, isolate and resolve problems about the task |
Tasks
| 1.2 | BASIC NETWORK ARCHITECTURE | |
| 1.2.1 | Transmission mediums | B |
| 1.2.2 | Server Functions | B |
| 1.8 | PROTOCOLS and PACKET CAPTURES | |
| 1.8.18 | Demonstrate ability to break-out NetBIOS | D |
| 1.8.19 | Demonstrate ability to break-out SSL | D |
| 1.8.20 | Demonstrate ability to break-out RPC | D |
| Demonstrate ability to break-out Server Message Block (SMB) | ||
| 2.2 | File System Structure | |
| 2.2.6 | List the characteristics of local and domain user accounts | C |
| 2.2.7 | Describe Windows security issues | C |
| 2.3 | Identify Windows Registry concepts & keys | |
| 2.5 | Operating System Functions | |
| 2.6 | Windows Command Line | |
| 2.6.1 | Master System Administration from the Windows command line | D |
| 2.6.2 | Windows PowerShell | D |
| 2.6.3 | Windows Management Instruction | D |
| 3 | *NIX (e.g., UNIX, LINUX) | |
| 6.1 | NETWORK SECURITY | |
| 6.1.1 | Discuss access control concepts (e.g. Access Control List) | B |
| 6.1.2 | Define the principles and methods of authentication | B |
| 6.1.3 | Provide an overview of the various threats to web security | D |
| 6.1.4 | B | |
| 6.1.5 | List and Identify recognized industry standards and recommendations that address information and network security | B |
| 6.1.6 | Recognize the reasons for implementing Network Security | B |
| 6.1.7 | D | |
| 6.1.8 | Overview the general categories of network security threats (e.g. DoS, password, man-in-the-middle) | D |
| 6.1.9 | Identify the vulnerabilities of various network protocols (e.g. TCP, SNMP, UDP, SMTP, FTP) | D |
| 6.1.10 | D | |
| 6.1.11 | Identify relationship between vulnerabilities and exploits | D |
| 6.1.12 | Identify techniques used to evade intrusion detection systems | D |
| 6.1.13 | Describe the basic operation of network security devices (e.g. firewalls, proxy servers, mail relays etc.) | D |
| 6.1.14 | Describe basic concepts of NAT | D |
| 6.1.15 | Describe basic concepts of [default deny/allow by exception | B |
| 6.1.17 | Understand the threat of an attack from inside your network | D |
| 7 | REMOTE ACCESS |
Sheet3
| TASK NUMBER | TASK DESCRIPTION | AFCTP | Air Force Contract Class Requirement | |
| 1 | NETWORK FUNDAMENTALS AND PACKET ANALYSIS | |||
| 1.1 | Network Types | |||
| 1.1.1 | Purposes and Functions of Networking | A | B | |
| 1.1.2 | Physical and Logical Networks | A | B | |
| 1.1.3 | Purpose and Limitations of a Local Area Network (LAN) | A | B | |
| 1.1.4 | Purpose and Limitations of a Wide Area Network (WAN) | A | A | |
| 1.1.5 | Purpose and Limitations of a Metropolitan Area Network (MAN) | A | A | |
| 1.1.6 | Purpose and Limitations of a Virtual Private Network (VPN) | A | A | |
| 1.1.7 | Purpose and Limitations of a Virtual Local Area Network (VLAN) | A | A | |
| 1.1.8 | Purpose and Limitations of a Personal Area Network (PAN) | A | A | |
| 1.1.9 | Purpose and Limitations of a Wireless LAN & MAN | A | A | |
| 1.1.10 | Purpose and Limitations of a Peer-to-Peer network | A | B | |
| 1.1.11 | Purpose and Limitations of a Client-Server network | A | B | |
| 1.2 | Network Topologies | |||
| 1.2.1 | Bus topology | A | A | |
| 1.2.2 | Star topology | A | A | |
| 1.2.3 | Tree topology | A | A | |
| 1.2.4 | Ring topology | A | A | |
| 1.2.5 | Mesh topology | A | A | |
| 1.2.6 | Hybrid topology | A | A | |
| 1.2.7 | Token Ring topology | A | A | |
| 1.3 | Network Devices | |||
| 1.3.1 | Functions and Limitations of a hub | B | C | |
| 1.3.2 | Functions and Limitations of a switch | B | C | |
| 1.3.3 | Functions and Limitations of a bridge | B | C | |
| 1.3.4 | Functions and Limitations of a router | B | C | |
| 1.3.5 | Functions and Limitations of a firewall | B | C | |
| 1.3.6 | Characteristics and Features of Network Intrusion Detection and Intrusion Prevention Systems (IDS / IPS) | B | C | |
| 1.3.7 | Functions and Limitations of a proxy server | B | C | |
| 1.3.8 | Functions and Limitations at each layer (router, CPU, switch, hub, etc) | B | C | |
| 1.4 | Networking Models | |||
| 1.4.1 | Open Systems Iinterconnect (OSI) Layers | B | C | |
| 1.4.2 | Telecommunications Protocol (TCP) Layers | B | C | |
| 1.4.3 | Functions Associated at each layer | B | C | |
| 1.4.4 | Major Protocols used at each layer | B | C | |
| 1.4.5 | Principles of protocols and layered architectures | B | C | |
| 1.4.6 | Connection-oriented protocols (TCP) | B | C | |
| 1.4.7 | Connectionless protocols (UDP) | B | C | |
| 1.5 | TCP/IP (Telecommunications Protocol / Internet Protocol) | |||
| 1.5.1 | Characteristics of TCP/IP | B | B | |
| 1.5.2 | Telecommunications Protocol (TCP) | B | B | |
| 1.5.3 | Connection-oriented protocols and data transport | B | B | |
| 1.5.4 | Fundamentals of IPv4 addressing | B | B | |
| 1.5.5 | IPv4 header fields | B | 2b | |
| 1.5.6 | Hierarchical addressing scheme | B | B | |
| 1.5.7 | Flat address schemes | B | B | |
| 1.5.8 | Hierarchical address schemes | B | B | |
| 1.5.9 | Fundamentals of IPv6 addressing | A | B | |
| 1.5.10 | IPv6 header fields | A | 2b | |
| 1.5.11 | MAC addressing | B | B | |
| 1.5.12 | CSMA/CD | B | B | |
| 1.5.13 | CSMA/CA, | B | B | |
| 1.5.14 | Token Passing | B | B | |
| 1.5.15 | 802.2 LLC header fields | 2b | 2b | |
| 1.5.16 | 802.3 frame fields | 2b | 2b | |
| 1.5.17 | 802.3 with SNAP header fields | 2b | 2b | |
| 1.5.18 | Static IP addressing | B | B | |
| 1.5.19 | Dynamic IP addressing | B | B | |
| 1.5.20 | Network Address Translation (NAT) addressing | B | B | |
| 1.5.21 | Network address classes | B | B | |
| 1.5.22 | Classful addressing | B | B | |
| 1.5.23 | Classless addressing | B | B | |
| 1.5.24 | Network IDs and broadcast addresses | B | B | |
| 1.5.25 | TCP 3-way handshake | B | B | |
| 1.5.26 | TCP 4-way handshake | B | B | |
| 1.5.27 | TCP Sequence and Acknowledgement numbers | 2b | 2b | |
| 1.5.28 | Transmissions sequence numbers | 2b | 2b | |
| 1.5.29 | TCP header Fields | 2b | 2b | |
| 1.5.30 | User Datagram Protocol (UDP) | B | B | |
| 1.5.31 | UDP header Fields | B | 2b | |
| 1.5.32 | Encapsulation | B | B | |
| 1.5.33 | Fragmentation | A | B | |
| 1.5.34 | Reassembly | B | B | |
| 1.5.35 | Packet Tracing through a network | A | C | |
| 1.5.36 | Ethernet frame headers in hexidecimal | 2b | 3c | |
| 1.5.37 | TCP headers in hexidecimal | 2b | 3c | |
| 1.5.38 | UDP headers in hexidecimal | 2b | 3c | |
| 1.6 | Ports, Protocols and Services | |||
| 1.6.1 | Services and Protocols with ports | B | B | |
| 1.6.2 | Address Resolution Protocol (ARP) | B | B | |
| 1.6.3 | ARP packets | B | 2c | |
| 1.6.4 | Internet Control Message Protocol (ICMP) | B | C | |
| 1.6.5 | ICMP packets | B | 2c | |
| 1.6.6 | ICMP Messages and Codes | B | C | |
| 1.6.7 | Windows ICMP messages | B | 3c | |
| 1.6.8 | Unix ICMP messages | B | 3c | |
| 1.6.9 | Operating System (OS) fingerprinting from ICMP messages | B | 3c | |
| 1.6.10 | Ping | B | C | |
| 1.6.11 | Traceroute | B | C | |
| 1.6.12 | Traceroute/Tracert using hexidecimal dump | B | 2c | |
| 1.6.13 | Windows traceroutes | B | 3c | |
| 1.6.14 | *nix traceroutes | B | 3c | |
| 1.6.15 | Latency issues (undersea cable, Satellite transmissions, etc) | A | B | |
| 1.6.16 | Internet Group Management Protocol (IGMP) messages | B | ||
| 1.6.17 | File Transfer Protocol (FTP) traffic | B | 2c | |
| 1.6.18 | Trivial File Transfer Protocol (TFTP) traffic | B | 2c | |
| 1.6.19 | Telnet | B | B | |
| 1.6.20 | Telnet traffic Analysis | 3c | ||
| 1.6.21 | Secure Shell (SSH) | B | B | |
| 1.6.22 | SSH traffic Analysis | 1a | 2b | |
| 1.6.23 | Simple Mail Transfer Protocol (SMTP) | A | B | |
| 1.6.24 | SMTP packets Analysis | A | 2b | |
| 1.6.25 | Post Office Protocol (POP) | A | B | |
| 1.6.26 | Internet Message Access Protocol (IMAP) | A | B | |
| 1.6.27 | Simple Network Management Protocol (SNMP) | A | C | |
| 1.6.28 | Domain Name Service (DNS) | B | C | |
| 1.6.29 | DNS resolution (Identify Zone Transfers, DNS Name Queries) Process Mapping | 2b | 3c | |
| 1.6.30 | Dynamic Host Configuration Protocol (DHCP) | B | C | |
| 1.6.31 | DHCP process diagram | 2b | 3c | |
| 1.6.32 | Hypertext Transfer Protocol (HTTP) | B | C | |
| 1.6.33 | HTTP request mapping and diagram | 1a | 3c | |
| 1.6.34 | Hypertext Transfer Protocol over Secure Socket Layer (HTTPS) | 1a | 3c | |
| 1.7 | Number Conversions (Convert each of the following Into another type) | |||
| 1.7.1 | Whole Numbers | 2b | 2b | |
| 1.7.2 | Binary Numbers | 2b | 2b | |
| 1.7.3 | Hexadecimal Numbers | 2b | 2b | |
| 1.7.4 | Big Endian | B | 2b | |
| 1.7.5 | Little Endian | B | 2b | |
| 1.7.6 | Network Subnetting | 2b | 2b | |
| 2 | NETWORK FORENSICS | |||
| 2.1 | Packet sniffing | B | B | |
| 2.2 | IP spoofing attacks | B | B | |
| 2.3 | ability to use Wireshark tool | 2b | 2b | |
| 2.4 | ability to use tcpdump | 2b | 2b | |
| 2.5 | Analyze, decode, and decipher, and malicious traffic | 2b | 2b | |
| 2.6 | ICMP Redirection | B | ||
| 2.7 | Host Discovery Scanning technique prediction through packet captures | 2b | 2b | |
| 2.8 | Vulnerability Scanning technique recognition through packet captures | 2b | 2b | |
| 2.9 | MAC Spoofing techniques | A | 2b | |
| 2.10 | Executables and files carving from packet captures using various command line tools | 2b | 2b | |
| 2.11 | Characteristics of network attacks through packet captures | 2b | 2b | |
| 2.12 | Berkley Packet Filters | 2b | 2b | |
| 3 | WINDOWS OPERATOR FUNDAMENTALS | |||
| 3.1 | Windows History | |||
| 3.1.1 | History and evolution of Windows through Windows 8/2012 server | B | A | |
| 3.2 | System Architecture | |||
| 3.2.1 | User mode | B | B | |
| 3.2.2 | Kernel mode | B | B | |
| 3.2.3 | Core Windows system files both pre Windows Vista and post Windows Vista | |||
| 3.2.3.1 | ntdll.dll | B | B | |
| 3.2.3.2 | Boot.ini | B | B | |
| 3.2.3.3 | Ntdetect | B | B | |
| 3.2.3.4 | Ntoskrnl.exe | B | B | |
| 3.2.3.5 | Hal.dll | B | B | |
| 3.2.3.6 | Smss.exe | B | C | |
| 3.2.3.7 | Win32k.sys | B | B | |
| 3.2.3.8 | Csrss.exe | B | C | |
| 3.2.3.9 | Winlogon.exe | B | C | |
| 3.2.3.10 | Services.exe | B | C | |
| 3.2.3.11 | Kernel32.dll | B | B | |
| 3.2.3.12 | advapi32.dll | B | B | |
| 3.2.3.13 | User32.dll | B | B | |
| 3.2.3.14 | Gdi32.dll | B | B | |
| 3.2.4 | Architecture differences between 32 bit and 64 bit versions of Windows | |||
| 3.2.4.1 | C:\Windows\SysWOW64 vs C:\Windows\System32 | B | B | |
| 3.2.4.2 | HKLM\SOFTWARE\Wow6432Node | B | B | |
| 3.2.4.3 | C:\Program Files" vs "C:\Program Files (x86) | B | B | |
| 3.2.5 | Windows File Protection (WFP)/Windows Resource Protection (WRP) | B | ||
| 3.2.6 | Security Identifiers (SIDs), Access Tokens and Access Control | B | B | |
| 3.3 | Windows Boot Process | |||
| 3.3.1 | Windows Kernel 5.x boot process | B | B | |
| 3.3.2 | Windows Kernel 6.x boot process | B | B | |
| 3.3.3 | BitLocker boot process | B | B | |
| 3.3.4 | Master Boot Record (MBR) | B | B | |
| 3.3.5 | ntldr | B | B | |
| 3.3.6 | ntdetect | B | B | |
| 3.3.7 | boot.ini | B | B | |
| 3.3.8 | Bootmgr | B | B | |
| 3.3.9 | winload.exe | B | B | |
| 3.3.10 | Boot Configuration Data (BCD) | B | B | |
| 3.3.11 | Windows 8 rootkit countermeasures | A | ||
| 3.3.12 | Windows 8 bootkit countermeasures | A | ||
| 3.4 | Windows File System Structure | |||
| 3.4.1 | File system basics | |||
| 3.4.1.1 | DOS partition table data structure | B | B | |
| 3.4.1.2 | Extended partitions | B | B | |
| 3.4.1.3 | Volume Boot Record (VBR) | B | B | |
| 3.4.1.4 | Data allocation | B | B | |
| 3.4.1.5 | Slack space | B | B | |
| 3.4.1.6 | BitLocker drive encryption | B | B | |
| 3.4.2 | File Allocation Table (FAT) structure | |||
| 3.4.2.1 | FAT 32 | B | B | |
| 3.4.2.2 | FAT32 boot sector data structure | B | B | |
| 3.4.2.3 | FAT32 metadata | B | B | |
| 3.4.2.4 | FAT32 timestamps | B | B | |
| 3.4.2.5 | Mount FAT32 file system images using command line tool - mmls | B | 2b | |
| 3.4.3 | New Technology File System (NTFS) | |||
| 3.4.3.1 | Master File Table (MFT) | B | B | |
| 3.4.3.2 | Resident attribute structure | B | B | |
| 3.4.3.3 | Non-resident attribute structure | B | B | |
| 3.4.3.4 | Standard file attributes | B | B | |
| 3.4.3.5 | MFT extraction from NTFS image using command line tool - icat | B | 2b | |
| 3.4.3.6 | file deletion from NTFS systems | B | B | |
| 3.4.3.7 | recovery from NTFS systems | B | B | |
| 3.4.4 | Encrypting File System (EFS) security | B | B | |
| 3.4.5 | MAC timestamp changes in regards to copying and moving files and folders | B | 3c | |
| 3.5 | Windows Registry | |||
| 3.5.1 | Windows Registry Components | 2b | 3c | |
| 3.5.2 | Windows Registry Hierarchy | 2b | B | |
| 3.5.3 | HKEY_Classes_Root | B | B | |
| 3.5.4 | HKEY_Current_User | 2b | B | |
| 3.5.5 | HKEY_Local_Machine | 2b | B | |
| 3.5.6 | HKEY_LOCAL_MACHINE\System | B | B | |
| 3.5.7 | HKEY_LOCAL_MACHINE\Hardware | B | B | |
| 3.5.8 | HKEY_LOCAL_MACHINE\Software | B | B | |
| 3.5.9 | HKEY_LOCAL_MACHINE\SAM | B | B | |
| 3.5.10 | HKEY_LOCAL_MACHINE\Security | B | B | |
| 3.5.11 | HKEY_Users | B | B | |
| 3.5.12 | HKEY_Current_Config | B | B | |
| 3.5.13 | Key registry values manipulation for malicious means. | B | B | |
| 3.5.14 | Key registry values manipulation for defensive means. | B | B | |
| 3.5.15 | ntuser.dat | 2b | B | |
| 3.5.16 | UserAssist key | 2b | B | |
| 3.6 | Windows File System Artifacts | |||
| 3.6.1 | Directory structure (2000 vs XP vs Vista vs 7+) | |||
| 3.6.1.1 | Web browser artifacts (IE, Firefox, Chrome) storage | B | B | |
| 3.6.1.2 | Windows junctions | B | ||
| 3.6.1.3 | Cookies and temporary internet files storage | B | B | |
| 3.6.1.4 | History folders | B | B | |
| 3.6.1.5 | Windows volume shadow copy | B | B | |
| 3.6.1.6 | VSSADMIN | B | B | |
| 3.6.1.7 | Recycle Bin composition | |||
| 3.6.1.7.1 | INFO2 records | B | B | |
| 3.6.1.7.2 | $MFT records | B | B | |
| 3.6.1.7.3 | File deletion | B | B | |
| 3.6.1.7.4 | File restoration | B | B | |
| 3.6.2 | Windows Event Logs | |||
| 3.6.2.1 | System logs | 2b | 2b | |
| 3.6.2.2 | Security logs | 2b | 2b | |
| 3.6.2.3 | Application logs | 2b | 2b | |
| 3.6.3 | Prefetch files | |||
| 3.6.3.1 | Prefetch file disection (using open source tools) | 2b | 3c | |
| 3.6.3.2 | deleted prefetch files recovery | 2b | 3c | |
| 3.6.3.3 | Prefetch registry information | B | B | |
| 3.7 | Windows Process Execution | |||
| 3.7.1 | User mode | B | B | |
| 3.7.2 | Kernal Mode | B | B | |
| 3.7.3 | Windows subsystem | B | B | |
| 3.7.4 | Processes | B | B | |
| 3.7.5 | Threads | B | B | |
| 3.7.6 | Memory | B | B | |
| 3.7.7 | Paging | B | B | |
| 3.7.8 | Windows API | B | B | |
| 3.7.9 | Windows dll loading | B | B | |
| 3.7.10 | 32bit process execution on 64bit versions of Windows | B | B | |
| 3.7.11 | 64bit process execution on 64bit versions of Windows | B | B | |
| 3.7.12 | Import Address Table (IAT) | B | B | |
| 3.7.13 | Relative Virtual Addresses (RVA) | B | B | |
| 3.8 | Windows Networking | |||
| 3.8.1 | Windows\System32 | B | B | |
| 3.8.2 | Windows\System32\drivers | B | B | |
| 3.8.3 | Windows\System32\drivers\etc\hosts (cover all key files) | B | B | |
| 3.8.4 | IP address addition via GUI | 2b | 3c | |
| 3.8.5 | Manually add a route | 2b | 3c | |
| 3.8.6 | local user accounts | 2b | 3c | |
| 3.8.7 | domain user accounts | 2b | 3c | |
| 3.8.8 | Windows security issues | |||
| 3.8.8.1 | LAN Manager (LM) | B | B | |
| 3.8.8.2 | NT LAN Manager (NTLM) | B | B | |
| 3.8.8.3 | NT LAN Manager version 2 (NTLMv2) | B | B | |
| 3.8.8.4 | LM with respect to password security | B | B | |
| 3.8.8.5 | NTLM with respect to password security | B | B | |
| 3.8.8.6 | NTLMv2 with respect to password security | B | B | |
| 3.8.8.7 | User Account Control (UAC) | B | B | |
| 3.8.8.8 | Kerberos in a Windows domain environment | B | B | |
| 3.8.8.9 | Kerberos Key Distribution Center (KDC) | B | B | |
| 3.8.8.10 | Authentication Service (AS) function of the KDC | B | B | |
| 3.8.8.11 | Ticket-Granting Service (TGS) function of the KDC | B | B | |
| 3.8.8.12 | the Kerberos Ticket Exchange process | B | B | |
| 3.8.8.13 | Kerberos authentication process when a domain user logs into a computer using a domain account. | B | B | |
| 3.8.8.14 | the authentication process when a non-domain user logs into a computer using a local account. | B | B | |
| 3.8.9 | Windows Specific Services | B | B | |
| 3.8.10 | Windows sockets and named pipes | B | B | |
| 3.8.11 | Process Interrogation | |||
| 3.8.11.1 | ports associated with a given process | B | 3c | |
| 3.8.11.2 | files handles associated with a given process | 2b | 3c | |
| 3.8.11.3 | identify strings in an executable/binary | 2b | 3c | |
| 3.9 | Windows Command Line | |||
| 3.9.1 | Windows 32-bit cmd shell | B | B | |
| 3.9.2 | Environment Variables | B | B | |
| 3.9.3 | Windows system information commands | |||
| 3.9.3.1 | whoami | 2b | 3c | |
| 3.9.3.2 | hostname | 2b | 3c | |
| 3.9.3.3 | ver | 2b | 3c | |
| 3.9.3.4 | driveryquery | 2b | 3c | |
| 3.9.3.5 | systeminfo | 2b | 3c | |
| 3.9.3.6 | doskey | 3c | ||
| 3.9.3.7 | date | 2b | 3c | |
| 3.9.3.8 | auditpol | 2b | 3c | |
| 3.9.4 | Windows file system functions using the following commands | |||
| 3.9.4.1 | cd | 2b | 3c | |
| 3.9.4.2 | mkdir | 2b | 3c | |
| 3.9.4.3 | type | 2b | 3c | |
| 3.9.4.4 | move | 2b | 3c | |
| 3.9.4.5 | rename | 2b | 3c | |
| 3.9.4.6 | chdir | 2b | 3c | |
| 3.9.4.7 | del | 2b | 3c | |
| 3.9.4.8 | rmdir | 2b | 3c | |
| 3.9.4.9 | dir | 2b | 3c | |
| 3.9.4.10 | tree | 2b | 3c | |
| 3.9.4.11 | where | 2b | 3c | |
| 3.9.4.12 | find | 2b | 3c | |
| 3.9.4.13 | findstr | 2b | 3c | |
| 3.9.4.14 | copy | 2b | 3c | |
| 3.9.4.15 | xcopy | 3c | ||
| 3.9.4.16 | attrib | 2b | 3c | |
| 3.9.4.17 | assoc | 2b | 3c | |
| 3.9.4.18 | sort | 2b | 3c | |
| 3.9.4.19 | echo | 2b | 3c | |
| 3.9.4.20 | shutdown | 2b | 3c | |
| 3.9.4.21 | reg | 2b | 3c | |
| 3.9.5 | Windows chaining commands | 2b | 3c | |
| 3.9.6 | Windows batch scripts | 1a | 3c | |
| 3.9.7 | Windows tasks using the command line | 2b | 3c | |
| 3.9.8 | hard disk configuration and maintenance using the following Windows commands | |||
| 3.9.8.1 | label | 1a | ||
| 3.9.8.2 | format | 1a | ||
| 3.9.8.3 | mountvol | 1a | ||
| 3.9.8.4 | fsutil | 2b | 3c | |
| 3.9.8.5 | chkdsk | 1a | ||
| 3.9.8.6 | defrag | 1a | ||
| 3.9.8.7 | cipher | 2b | 2b | |
| 3.9.9 | Windows commands that manage permissions | 2b | ||
| 3.9.9.1 | cacls | 2b | 2b | |
| 3.9.9.2 | icacls | 2b | 2b | |
| 3.9.10 | network and service-related functions using the following Windows commands | 2b | ||
| 3.9.10.1 | ipconfig | 2b | 3c | |
| 3.9.10.2 | getmac | 3c | ||
| 3.9.10.3 | ping | 2b | 3c | |
| 3.9.10.4 | tracert | 2b | 3c | |
| 3.9.10.5 | pathping | 1b | ||
| 3.9.10.6 | netstat | 2b | 3c | |
| 3.9.10.7 | netsh | 2b | 3c | |
| 3.9.10.8 | netsh diag | 2b | 3c | |
| 3.9.10.9 | netsh interface | 2b | 3c | |
| 3.9.10.10 | netsh firewall | 2b | 3c | |
| 3.9.10.11 | netsh advfirewall | 2b | 3c | |
| 3.9.10.12 | netsh show | 2b | 3c | |
| 3.9.10.13 | netsh set | 2b | 3c | |
| 3.9.10.14 | net | 2b | 3c | |
| 3.9.10.15 | net accounts | 2b | 3c | |
| 3.9.10.16 | net config | 2b | 3c | |
| 3.9.10.17 | net group | 2b | 3c | |
| 3.9.10.18 | net localgroup | 2b | 3c | |
| 3.9.10.19 | net start | 2b | 3c | |
| 3.9.10.20 | net stop | 2b | 3c | |
| 3.9.10.21 | net pause | 2b | 2b | |
| 3.9.10.22 | net share | 2b | 3c | |
| 3.9.10.23 | net session | 2b | 3c | |
| 3.9.10.24 | net time | 2b | 3c | |
| 3.9.10.25 | net user | 2b | 2b | |
| 3.9.10.26 | net view | 2b | 3c | |
| 3.9.10.27 | net use | 2b | 3c | |
| 3.9.10.31 | nbtstat | 2b | 3c | |
| 3.9.10.32 | sc | 2b | 3c | |
| 3.9.10.33 | tasklist | 2b | 3c | |
| 3.9.11 | external, Windows command line tools | |||
| 3.9.11.1 | psloggedon | 2b | 2b | |
| 3.9.11.2 | psinfo | 2b | 2b | ` |
| 3.9.11.3 | fport | 2b | ||
| 3.9.11.4 | pslist | 2b | 2b | |
| 3.9.11.5 | handle | 2b | 2b | |
| 3.9.11.6 | ntlast | 2b | ||
| 3.9.11.7 | psloglist | 2b | 2b | |
| 3.9.11.8 | regdmp | 2b | ||
| 3.9.11.9 | psfile | 2b | ||
| 3.9.11.10 | process explorer | 2b | 2b | |
| 3.9.11.11 | logonsessions | 2b | 2b | |
| 3.9.12 | Windows Management Instrumentation (WMI) | |||
| 3.9.12.1 | WMI from the command line | 2b | 2b | |
| 3.9.12.2 | WMIC interface commands | 2b | 2b | |
| 3.9.12.2.1 | wmic startup | 2b | 2b | |
| 3.9.12.2.2 | wmic service list | 2b | 2b | |
| 3.9.12.2.3 | wmic process list | 2b | 2b | |
| 3.9.12.2.4 | WMI Quick Fix Engineering | 2b | 2b | |
| 3.9.12.2.5 | wmic share list | 2b | ||
| 3.9.12.2.6 | wmic sysaccount list | 2b | ||
| 3.9.12.2.7 | wmic group list | 2b | ||
| 3.9.12.2.8 | wmic useraccount | 2b | ||
| 3.9.12.2.9 | wmic volume list | 2b | ||
| 3.9.12.2.10 | wmic os list | 2b | ||
| 3.9.12.2.11 | wmic nteventlog | 2b | 2b | |
| 3.9.12.2.12 | create a process using WMI | 2b | 2b | |
| 3.9.12.2.13 | wmic printer | 2b | ||
| 3.9.12.3 | WMI commands remotely | |||
| 3.9.12.3.1 | wmic share list | 2b | ||
| 3.9.12.3.2 | wmic sysaccount list | 2b | ||
| 3.9.12.3.3 | wmic group list | 2b | ||
| 3.9.12.3.4 | wmic useraccount | 2b | ||
| 3.9.12.3.5 | wmic volume list brief | 2b | ||
| 3.9.13 | Windows PowerShell | |||
| 3.9.13.1 | PowerShell command line | 2b | 2b | |
| 3.9.13.2 | PowerShell noninteractive sessions | 2b | 2b | |
| 3.9.13.3 | PowerShell CMDLETS | 2b | 2b | |
| 3.9.13.4 | PowerShell services Identification and control | 2b | 2b | |
| 3.9.13.5 | PowerShell ProcessList Extraction | 2b | 2b | |
| 3.9.13.6 | PowerShell ProcessInfo Extraction | 2b | 2b | |
| 3.9.13.7 | PowerShell loaded dll identification | 2b | 2b | |
| 3.9.13.8 | PowerShell start and stop processes | 2b | 2b | |
| 3.9.13.9 | PowerShell file system | 2b | 2b | |
| 3.9.13.10 | Powershell drive structure | 2b | 2b | |
| 3.9.13.11 | PowerShell Directory Walks | 2b | 2b | |
| 3.9.13.12 | PowerShell file and directory creation | 2b | 2b | |
| 3.9.13.13 | PowerShell share management | 2b | 2b | |
| 3.9.13.14 | PowerShell Windows registry navication | 2b | 2b | |
| 3.9.13.15 | PowerShell event log viewing | 2b | 2b | |
| 3.9.13.16 | PowerShell event log clearing | 2b | 2b | |
| 3.9.13.17 | Windows PowerShell remote use | 2b | 2b | |
| 4 | LINUX/UNIX OPERATOR FUNDAMENTALS | |||
| 4.1 | basic concepts of *NIX | |||
| 4.1.1 | *nix systems history | B | B | |
| 4.1.2 | major *nix families | A | A | |
| 4.1.3 | kernel space and user space | B | B | |
| 4.1.4 | user space | B | B | |
| 4.1.5 | major methods of updating Linux distributions | B | B | |
| 4.2 | Boot Process | |||
| 4.2.1 | Hardware Boot | B | B | |
| 4.2.2 | Peripherals | A | A | |
| 4.2.3 | Boot Device | B | B | |
| 4.2.4 | OS Loader | B | B | |
| 4.2.5 | LILO Loader (Linux) | B | B | |
| 4.2.6 | Grand Unified Bootloader (GRUB) | B | B | |
| 4.2.7 | Kernel purpose | B | B | |
| 4.2.8 | Device Detection | B | B | |
| 4.2.9 | Driver Initialization process | B | B | |
| 4.2.10 | filesystem mounting | B | B | |
| 4.2.11 | /sbin/init | 2b | B | |
| 4.2.12 | /var/log/dmesg | B | B | |
| 4.2.13 | Init process | 2b | 3c | |
| 4.2.14 | run levels | 2b | 3c | |
| 4.2.15 | start-up scripts location (e.g. /etc/rc.d, /etc/init.d, /etc/inittab, etc) | |||
| 4.2.15.1 | /etc/rc.d/rc.sysinit contents | 2b | 3c | |
| 4.2.15.2 | /etc/rc.d/rc contents | 2b | 3c | |
| 4.2.15.3 | /etc/rc.d/rc.local contents | 2b | 3c | |
| 4.2.15.4 | /etc/rc.d/init.d/service contents | B | B | |
| 4.2.16 | Service Management Facility (SMF) on Solaris operating systems | B | ||
| 4.2.17 | systemd service management on linux operating systems | B | B | |
| 4.2.18 | shell initialization process (getty/sshd) | B | B | |
| 4.3 | File Structure | |||
| 4.3.1 | /bin | B | B | |
| 4.3.2 | /sbin | B | B | |
| 4.3.3 | /boot | B | B | |
| 4.3.4 | /dev | B | B | |
| 4.3.5 | /usr | B | B | |
| 4.3.6 | /svr | B | B | |
| 4.3.7 | /etc | B | B | |
| 4.3.8 | /var | B | B | |
| 4.3.9 | /lib | B | B | |
| 4.3.10 | /opt | B | B | |
| 4.3.11 | /media | B | B | |
| 4.3.12 | /mnt | B | B | |
| 4.3.13 | /tmp | B | B | |
| 4.3.14 | /core "crash dump file" | B | ||
| 4.3.15 | bash_history | 2b | 2b | |
| 4.4 | Networking | |||
| 4.4.1 | configure /etc/sysconfig/network | B | 3c | |
| 4.4.2 | configure /etc/rc.d/init.d/network | B | 3c | |
| 4.4.3 | configure /etc/sysconfig/network-scripts/ifcfg-eth0 | B | 3c | |
| 4.4.4 | /etc/sysconfig/network-scripts/route-eth0 | 2b | 3c | |
| 4.4.5 | /etc/sysconfig/network-scripts/eth0.route | 2b | 3c | |
| 4.4.6 | /etc/hosts configuration | 2b | 2b | |
| 4.4.7 | /etc/resolv.conf configuration | 2b | 2b | |
| 4.4.8 | /etc/inetd.conf configuration | 2b | 2b | |
| 4.4.9 | /etc/xinetd.conf configuration | 2b | 2b | |
| 4.4.10 | DHCP server configuration | B | B | |
| 4.4.11 | Process Interrogation | 2b | 3c | |
| 4.4.11.1 | ports associated with a given process | 2b | 3c | |
| 4.4.11.2 | files handles associated with a given process | 2b | 3c | |
| 4.4.11.3 | strings in an executable/binary | 2b | 3c | |
| 4.5 | Authentication | |||
| 4.5.1 | /etc/passwd configuration | 2b | 2b | |
| 4.5.2 | /etc/shadow configuration | 2b | 2b | |
| 4.6 | Users | |||
| 4.6.1 | User addition | 2b | 3c | |
| 4.6.2 | User deletion | 2b | 3c | |
| 4.7 | Command Line | |||
| 4.7.1 | basic Unix commands and various switches | |||
| 4.7.1.1 | ifconfig | 2b | 3c | |
| 4.7.1.2 | uname | 2b | 3c | |
| 4.7.1.3 | ps | 2b | 3c | |
| 4.7.1.4 | cat | 2b | 3c | |
| 4.7.1.5 | touch | 2b | 3c | |
| 4.7.1.6 | netstat | 2b | 3c | |
| 4.7.1.7 | chmod | 2b | 3c | |
| 4.7.1.8 | chown | 2b | 3c | |
| 4.7.1.9 | chgrp | 2b | 3c | |
| 4.7.1.10 | passwd | 2b | 3c | |
| 4.7.1.11 | echo | 2b | 3c | |
| 4.7.1.12 | cd | 2b | 3c | |
| 4.7.1.13 | pwd | 2b | 3c | |
| 4.7.1.14 | rm | 2b | 3c | |
| 4.7.1.15 | ls | 2b | 3c | |
| 4.7.1.16 | mkdir | 2b | 3c | |
| 4.7.1.17 | lsmod | 2b | 3c | |
| 4.7.1.18 | dmesg | 2b | 3c | |
| 4.7.1.19 | iptables | 2b | 3c | |
| 4.7.1.20 | sestatus/getenforce | 2b | 3c | |
| 4.7.1.21 | su | 2b | 3c | |
| 4.7.1.22 | ping | 2b | 3c | |
| 4.7.1.23 | grep/egrep | 2b | 3c | |
| 4.7.1.24 | sed | 1a | 2b | |
| 4.7.1.25 | awk | 1a | 2b | |
| 4.7.1.26 | head | 2b | 3c | |
| 4.7.1.27 | tail | 2b | 3c | |
| 4.7.1.28 | cut | 1a | 2b | |
| 4.7.1.29 | less | 2b | 3c | |
| 4.7.1.30 | watch | 1a | 2b | |
| 4.7.1.31 | wc | 2b | 3c | |
| 4.7.1.32 | unset | 2b | ||
| 4.7.2 | Vi Editor to edit files | 2b | 3c | |
| 4.8 | Bash Scripting | |||
| 4.8.1 | Regular expressions | B | 3c | |
| 4.8.2 | Functions | B | 3c | |
| 4.8.3 | Variables | B | 3c | |
| 4.9 | Logging and Accounting | |||
| 4.9.1 | Syslog | B | A | |
| 4.9.2 | Utmpx | B | 1a | |
| 4.9.3 | Wtmpx | B | 1a | |
| 4.9.4 | Solaris kernel auditing | 2b | ||
| 4.9.5 | System accounting | B | 2b | |
| 4.9.6 | Process accounting | B | 2b | |
| 4.9.7 | MAC timestamp changes in regards to copying and moving files and folders | B | 2b | |
| 4.10 | *nix Process Execution | |||
| 4.10.1 | file permissions with regards to a user running a process | B | B | |
| 4.10.2 | daemon | B | B | |
| 4.10.3 | cron/crontabs | 2b | 2b | |
| 4.10.4 | cron job creation | 2b | 2b | |
| 4.10.5 | foreground process | 2b | 2b | |
| 4.10.6 | background process | 2b | 2b | |
| 4.10.7 | shared libraries | B | B | |
| 4.10.8 | LD_PRELOAD variable | B | ||
| 5 | DIGITAL MEDIA FORENSICS | |||
| 5.1 | Forensic Methodology and Application | 2b | A | |
| 5.1.1 | local device profile | 2b | 2b | |
| 5.1.2 | remote device profile | 2b | 2b | |
| 5.1.3 | Hash analysis | 2b | A | |
| 5.1.4 | File Signature analysis | 2b | 2b | |
| 5.1.5 | keyword searching | 2b | 2b | |
| 5.1.6 | GREP expressions | 2b | 2b | |
| 5.1.7 | Advanced timeline analysis | 2b | 3c | |
| 5.1.8 | Windows file system and Registry artifacts | 2b | 3c | |
| 5.1.9 | incident response using the Windows command line | 2b | 2b | |
| 5.1.10 | Anti-Forensics techniques | 2b | A | |
| 5.1.11 | Steganalysis | 2b | A | |
| 5.1.12 | data hiding techniques | 2b | 1a | |
| 5.2 | Cryptography | |||
| 5.2.1 | block ciphers | B | B | |
| 5.2.2 | stream ciphers | B | B | |
| 5.2.3 | encryption | B | B | |
| 5.2.4 | encoding | B | B | |
| 5.2.5 | symmetric key algorithms | B | B | |
| 5.2.6 | asymmetric key algorithms | B | B | |
| 5.2.7 | PKI | B | B | |
| 5.2.8 | PGP | B | B | |
| 5.2.9 | TLS/SSL | B | B | |
| 5.2.10 | ROT13 | B | A | |
| 5.3 | deleted partition recovery | B | A | |
| 6 | REVERSE ENGINEERING MALWARE | |||
| 6.1 | malicious code analysis | 2b | 2b | |
| 6.2 | malware analysis | 2b | 2b | |
| 6.3 | assembly language | B | B | |
| 6.4 | register sets | B | B | |
| 6.5 | data types | B | B | |
| 6.6 | memory formats | B | B | |
| 6.7 | instruction formats | B | B | |
| 6.8 | program execution | B | B | |
| 6.9 | Code analysis fundamentals | B | B | |
| 6.10 | patching executables | B | B | |
| 6.11 | Windows registry hierarchy | 2b | 3c | |
| 6.12 | Windows registry track changes | 2b | 3c | |
| 6.13 | malicious packet tracing through the network | B | 2b | |
| 6.14 | anomalous event prediction in network traffic | 1a | ||
| 6.15 | defensive techniques in malware | B | 2b | |
| 6.16 | unpack packed code | 2b | 2b | |
| 6.17 | subverting virtual machine and debugger detection | A | B | |
| 6.18 | evolution of a botnet | A | A | |
| 6.19 | evolution of a rootkit | B | B | |
| 6.20 | evolution of a dll injection | 2b | 2b | |
| 6.21 | evolution of a browser-based attack | B | B | |
| 6.22 | stack overflow | B | B | |
| 6.23 | heap overflow | B | B | |
| 6.24 | format string vulnerability | B | B | |
| 6.25 | techniques OSs and compilers use to try to prevent exploits (DEP, canaries, etc) | B | B | |
| 6.26 | techniques hackers use to bypass anti-hacking techniques (ROP, SEH chaining, etc) | B | B | |
| 7 | MEMORY FORENSICS | |||
| 7.1 | malware behavior in memory | 2b | B | |
| 7.2 | driver IRP hooks | A | A | |
| 7.3 | physical memory acquisition from a Windows system | 2b | B | |
| 7.4 | malicious processes in memory from a memory dump | 2b | B | |
| 7.5 | malicious drivers in memory from a memory dump | B | B | |
| 7.6 | injected DLLs from a memory dump | B | B | |
| 7.7 | rogue drivers from a memory dump | B | B | |
| 7.8 | hooking malware from a memory dump | B | B | |
| 8 | COMPUTER NETWORK EXPLOITATION AND ATTACK | |||
| 8.1 | hacker methodology | B | B | |
| 8.2 | footprinting techniques | 2b | 3c | |
| 8.3 | scanning techniques | 2b | 3c | |
| 8.4 | fingerprinting techniques: | 2b | 3c | |
| 8.4.1 | Nmap | 2b | 3c | |
| 8.4.2 | Ping | 2b | 3c | |
| 8.4.3 | traceroute | 2b | 3c | |
| 8.5 | enumeration techniques: | |||
| 8.5.1 | SMTP | 2b | 3c | |
| 8.5.2 | SNMP | 2b | 3c | |
| 8.5.2 | SMB | 2b | 3c | |
| 8.5.3 | HTTP | 2b | 3c | |
| 8.6 | Google Hacking techniques | 2b | 3c | |
| 8.7 | Email harvesting | 2b | 2b | |
| 8.8 | netcat | |||
| 8.8.1 | Port scanning using netcat | 2b | 3c | |
| 8.8.2 | Banner grabbing using netcat | 2b | 3c | |
| 8.8.3 | File transfer using netcat | 2b | 3c | |
| 8.8.4 | Chat using netcat | 2b | 3c | |
| 8.8.5 | Port listening using netcat | 2b | 3c | |
| 8.8.6 | Backdoor installation using netcat | 2b | 3c | |
| 8.9 | File Transfers | |||
| 8.9.1 | TFTP | 2b | 3c | |
| 8.9.2 | Binary Decode | 2b | 3c | |
| 8.9.3 | Internet Explorer | 2b | 3c | |
| 8.9.4 | Web Transfers | 2b | 3c | |
| 8.9.5 | FTP | 2b | 3c | |
| 8.10 | Remote Access methods | 2b | 3c | |
| 8.11 | Man-in-the-Middle Attack | 2b | ||
| 8.12 | ARP spoofing Attack | |||
| 8.12.1 | ARP packet modification and transfer | 2b | ||
| 8.12.2 | filter creation and ARP Spoof | 2b | ||
| 8.13 | Sniffer Attack | 2b | ||
| 8.14 | Application-layer Attacks | 2b | ||
| 8.15 | Rootkits | 2b | ||
| 8.16 | Buffer Overflow (Heap vs Stack) | 2b | 2b | |
| 8.17 | DNS Spoofing | 2b | ||
| 8.18 | DoS Attack against a Windows host and server | 2b | ||
| 8.19 | virus purpose | B | B | |
| 8.20 | worm | B | B | |
| 8.21 | trojan | B | B | |
| 8.22 | payloads used for exploitation | 2b | 3c | |
| 8.23 | bind shells | 2b | 3c | |
| 8.24 | reverse shells | 2b | 3c | |
| 8.25 | shellcode | 2b | 3c | |
| 8.26 | packet captures and remote exploitation | 2b | 3c | |
| 8.27 | packet captures and client-side exploitation | 2b | 3c | |
| 8.28 | remote Operatings Systems vulnerabilities | 2b | 3c | |
| 8.29 | Windows command line enumeration | 2b | 3c | |
| 8.30 | exploits packet captures | 2b | 2b | |
| 8.31 | Anti-Virus software subversion | 2b | 2b | |
| 8.32 | Intrusion Detection Systems evasion | 2b | 2b | |
| 8.33 | anti-virus software disabling | 2b | 2b | |
| 8.34 | Tradecraft techniques | 2b | 2b | |
| 8.35 | post exploitation artifact clean-up (housekeeping) | 2b | 2b | |
| 8.36 | persistent access on a remote machine | 2b | 2b | |
| 8.37 | rootkits (Installation and maintenance) | 2b | 3c | |
| 8.38 | DLL Hijacking techniques | 2b | ||
| 8.39 | tunnel (forward and reverse) the following traffic: | |||
| 8.39.1 | SSH | 2b | 2b | |
| 8.39.2 | DNS | 2b | ||
| 8.39.3 | ICMP | 2b | ||
| 8.39.4 | SSL | 2b | 2b | |
| 8.39.5 | HTTP | 2b | 2b | |
| 8.39.6 | TCP Exploits and Payloads | 2b | 2b | |
| 8.40 | elevate user privileges | 2b | 3c | |
| 8.41 | "pass the hash" technique | 2b | 3c | |
| 8.42 | Network Attack tactics | 2b | 2b | |
| 8.43 | data collection techniques on a remote system | 2b | 2b | |
| 8.44 | keylogger installation and remote keystrokes collection | 2b | 2b | |
| 8.45 | packet sniffer installation and remote traffic collection | 2b | 2b | |
| 8.46 | Administrator credentials remote recovery | 2b | 3c | |
| 8.47 | Windows survey scripts for remote target analysis | 2b | 3c | |
| 8.48 | malware behavior remotely | 2b | 2b | |
| 8.49 | security risks associated with remote access methods | 2b | 2b |
File details come from the government source that posted it. Updated .