JQR_Coverage.xlsx

XLSX spreadsheet 15 KB Posted

Attached to
834 COS Network Defense Range (NDR) Training Event Federal contract opportunity
Solicitation number
FA877320Q0037
Issued by
Department of the Air Force Space Command

View the file

Other files for this federal contract opportunity

Other files attached to 834 COS Network Defense Range (NDR) Training Event, newest first.
File Type Posted
1 - RFQ 834 NDR Training Event.pdf PDF
Single Source Justification_834 NDR_redacted.pdf PDF
ATTACH 1 SOO_834_Network Defense Range Event.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sheet1

UNCLASSIFIED//FOR OFFICIAL USE ONLY
Crew PositionTaskSubtaskDescription
NA - Network Analyst
Senior3.1 - Network Architecture Analysis - Given a compromised enterprise network environment with multiple sensors, a network map, and policies, the individual must complete each task with no assistance3.1.1Develop an analytic to identify anomalous traffic between hosts that should not communicate or communicating in unusual ways.
3.1.2Generate a report that outlines the attack surface of key terrain and networking devices that support it.
3.1.3Develop an analytic to identify network traffic that

deviates from established policies.

3.1.4Analyze network traffic and ensure that it conforms to approved documentation for the network (Ports, Protocols, and Services).
3.1.5Explain the differences between a network mirror port and a network tap
3.5 - Given a SIEM ingesting traffic from multiple network sensors and an intelligence report with network IOCs, the individual must complete the following tasks.3.5.1Query the database for network IOCs
3.5.2Build visualizations and dashboards to display requested network data.
3.5.3Create alerts in the SIEM for network IOCs
3.5.4Generate reports in the SIEM for network baseline analysis
3.5.5Generate reports in the SIEM for network baseline anomalies
HA, L - Host Analyst, Linux
Senior2.1 - Team Mission2.1.2Describe the process of integrating intelligence reporting into your mission
2.1.3Describe the process of developing analytics
2.1.8Given a set of vulnerabilities found on mission, describe how you would prioritize the vulnerabilities for the mission owner
3.6 - Detect and Identify Malicious Activity3.6.2Describe how to ensure log aggregation is configured properly by others and conduct statistical analysis.
3.6.3Explain how to oversee the development of host-based IDS/IPS signatures ensuring all settings and signatures are maintained as directed, assisting network owner as required.
3.6.4Describe the procedures or techniques required to verify and validate host-based IDS/IPS alerts.
3.6.5Discuss how to analyze multiple memory captures to determine anomalous

behavior and develop a detailed report including timeline of compromise.

3.6.6Describe how to take a finding of a compromise and develop a custom signature(s) and/or rule(s) to identify it throughout the network.
3.7 - Identify Rootkit Presence3.7.1Describe analysis techniques that may help identify hidden processes, libraries, binaries, modules, and/or strange filesystem activity related to rootkit behavior.
3.8 - Analyze Known/Suspected Malware3.8.2Describe how to discover the actions of a malicious script and be able to brief your findings
3.9 - Perform System Forensic Analysis3.9.1Discuss the process of ensuring the capture of forensically sound memory and disk images are properly performed and stored.
3.9.2Describe how to supervise and contribute to the forensic investigation of a memory image including documenting and reporting.
3.9.3Describe how to perform disk forensics and how to create a detailed report to include timeline and possible signatures.
3.10 - Apply Systems Analyst Tasks on Large Numbers Of Systems Simultaneously3.10.1Describe how to automate essential advanced tasks across an enterprise network relating to cyberspace operations.
3.15 - Detect and Identify Malicious Activity3.15.1Develop the reporting and recording of discovered potentially malicious processes, libraries, and modules on a compromised system.
3.15.2Evaluate that log aggregation is configured properly by team members and conduct statistical analysis across different datasets.
3.15.3Develop host-based IDS/IPS signatures according to a mission plan, ensuring all settings and signatures are kept up to date.
3.15.4Verify the validity of host-based IDS/IPS alerts.
3.15.5Analyze multiple memory captures to determine anomalous behavior and develop a detailed report to include a timeline and root cause analysis.
3.15.6Brief the team outlining key log entries/Event ID's to build a timeline of compromise.
3.16 - Identify Rootkit Presence3.16.1Use analysis techniques to identify processes, libraries, modules, and other activity that have been hidden. Develop instructions to mitigate the threat of the discovered rootkit.
3.17 - Analyze Known/Suspected Malware3.17.1Perform hasty reverse engineering of binary malicious applications. Brief others on how to mitigate the risk.
3.18 - Perform System Forensic Analysis3.18.1Oversee the capturing and storing of forensically sound memory and disk images ensuring everyone follows best practices.
3.18.2Lead the forensic investigation of a memory image. Ensure all carved files are analyzed and potential threats are documented and reported.
3.18.3Perform proper disk forensics and create a detailed report to include timeline and possible signatures.
3.19 - Apply Systems Analyst Tasks on Large Numbers of Systems Simultaneously3.19.1Create a script that automates an essential advanced task across a given network with the minimum requirements outlined in the answer key.
HA, W - Host Analyst, Windows
Senior3.7 - Implement Auditing of System Events for Threat Detection3.7.1Explain how to identify key log entries/Event ID's as indicators of compromise, use a Security information and event management (SIEM) platform to correlate indicators of compromise, and develop dashboards to better visualize data.
3.8 - Detect and Identify Malicious Activity3.8.1Explain how to analyze potentially malicious processes, libraries, and modules on all systems in a complex domain
3.8.2Explain how to oversee the monitoring of active directory for the creation of accounts that are unauthorized and potential threats
3.8.3Explain how to oversee the auditing of a complex Enterprise Network.
3.8.4Explain how to configure, forward, and statically analyze logs from all workstations in an enterprise environment.
3.8.5Explain how to oversee the development of host-based IDS/IPS signatures and settings.
3.8.6Explain how to oversee the tuning of host-based IDS/IPS alerts in order to evaluate their severity while eliminating false positives.
3.8.7Given an enterprise domain, explain how to use host volatile data to compare active processes, libraries, and modules against databases of known advanced malware.
3.9 - Identify Rootkit Presence3.9.1Explain how to utilize tools and analysis techniques to identify processes, libraries, modules, and other activity that have been obfuscated and might indicate the presence of a more advanced rootkit on endpoints.
3.10 - Analyze Known/Suspected Malware3.10.1Explain reverse engineering concepts of binary applications while demonstrating knowledge of the underlying code.
3.10.2Describe how to conduct static code analysis to determine what an advanced script is doing.
3.11 - Perform System Forensic Analysis3.11.1Given an enterprise domain, explain how to capture forensically sound memory and disk images across multiple systems and perform trend and outlier analysis.
3.11.2Given an enterprise domain, explain how to identify potentially malicious processes, connections, libraries, and other malicious code/activity from a memory image and perform trend and outlier analysis.
3.11.3Given an enterprise domain, describe the process of conducting disk forenscis on multiple images and perform trend and outlier analysis.
3.12 - Apply Systems Analyst Tasks on Large Numbers of Systems Simultaneously3.12.1Describe how to automate more advanced and repetitive tasks on remote workstations within a domain.
3.16 - Evaluate Customer Security Policy Posture3.16.1Identify security posture shortcomings in policy and training and assess customer security posture across a complex enterprise network.
3.16.2Review organizational policies and documentation for appropriate use and user privileges.
3.18 - Implement Auditing of System Events for Threat Detection3.18.1Identify key log entries/Event ID's as indicators of compromise, use a SIEM to correlate indicators of compromise and develop dashboards to better visualize data for an enterprise network.
3.19 - Detect and Identify Malicious Activity3.19.1Analyze potentially malicious processes, libraries, and modules on all systems in the domain to find advanced malware.
3.19.2Given an enterprise level domain controller, monitor active directory for creation of unauthorized/potentially malicious accounts.
3.19.3Given an enterprise domain, configure, forward, and statically analyze logs from allworkstations to perform outlier analysis.
3.19.4Given an enterprise domain, develop host-based IDS/IPS signatures and settings and facilitate change management
3.19.5Given an enterprise domain, tune host-based IDS/IPS alerts and evaluate their severity while eliminating false positives.
3.19.6Given an enterprise domain, use host volatile data to compare active processes, libraries, and modules against databases of known good/bad to find advanced malware.
3.20 - Identify Rootkit Presence3.20.1Given a Windows host, utilize tools and analysis techniques to identify processes, libraries, modules, and other activity that have been obfuscated and might indicate the presence of an advanced rootkit.
3.21 - Analyze Known/Suspected Malware3.21.1Perform hasty reverse engineering of advanced malware in order to develop IOC’s and recommend remedial actions.
3.21.2Given an advanced malicious script, conduct static code analysis to determine what the script is doing.
3.22 - Perform System Forensic Analysis3.22.1Given an enterprise domain, capture forensically sound memory and disk images across a domain.
3.22.2Identify advanced malicious processes, connections, libraries, and other malicious code/activity from a memory image.
3.22.3Conduct disk forensics on multiple images from a domain and perform trend and outlier analysis.
3.23 - Apply Systems Analyst Tasks on Large Numbers of Systems Simultaneously3.23.1Given a list, automate advanced and repetitive tasks on remote workstations across an enterprise network.
UNCLASSIFIED//FOR OFFICIAL USE ONLY

File details come from the government source that posted it. Updated .