PWS v4.pdf
PDF 166 KB Posted
- Attached to
- Commercial Online Training Software Federal contract opportunity
- Solicitation number
- FA521521Q7001
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Response v2 FA521521Q7001.pdf | ||
| RFI Response FA521521Q7001.pdf | ||
| IT Training Software RFQ v2.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance of Work (PWS) For
Commercial Online Training Platform
1 BACKGROUND
1.1 The commercial training platform requested is to educate and qualify military and civilian personnel working in the 352d Cyberspace Operations Squadron (352 COS).
This platform shall train 50 members of 352 COS in cyberspace operation skillsets, cyber fundamentals, cyber security, cyber threats, malware analysis, advanced persistent threat (APT) toolkits, and ethical hacking. The 352 COS personnel using this training perform cyberspace operations and have an average of 2-6 years of hands-on experience. The platform license(s) will be delivered to 352 COS Scheduling Flight (352 COS/DOS) staff; to assign 352 COS members within 1 year from service start date. Individual 352 COS members to receive a training platform management license(s) shall be selected by 352 COS/DOS staff after contract award to best meet the needs of the unit’s mission and schedule.
2 OBJECTIVES
2.1 352 COS seeks an online training platform that utilizes gaming progress mechanics and scaffolded learning to train in the topics described in Section 1.1, the topics in Attachment 1, and the NICE Framework Objectives listed in Attachment 2.
3 SCOPE
3.1 The contractor shall provide individual, group, site, or enterprise training platform licenses to support 50 simultaneous users based on the objectives mentioned in 2.1. The costs of services, features, support, and supplemental resources and material will be included within the purchases of each license. There is no intent for custom labs not provided to other customers. For the purpose of this document, “online training platform” shall mean a web-based, browser-accessible environment containing written training material and guided, interactive labs enabled by virtual machines (VMs), accessible to the student, to provide hands-on experience with foundational, intermediate, and advanced offensive, defensive, detective, and analytical technologies covering the cybersecurity topics described throughout this document.
4 REQUIREMENTS AND PERFORMANCE STANDARDS
4.1 Commercial Online Training Platform (mentioned above):
4.2.1 The customer shall reserve the right to transfer licenses/user accounts to different individuals in the event of deployment, permanent change of station/assignment, change in work role, or 1 month or longer temporary duty.
4.2.1.1 The contractor shall archive the previous owner’s profile
4.2.2 All training and training environments provided by the contractor shall be accessible online from commercial and DoD networks, including the
AFNET.
4.2.2.1 Online access shall be accessible via a web browser without installation of additional software, virtual private networks, or browser extensions.
4.2.3 The contractor shall provide all training lab materials, to be available within the online virtual machine, so there is no need to download content, tools, and/or data externally.
4.2.4 The contractor shall provide timely support for platform technical issues within 1 business day, and lab/training scenario specific support within 3 business days by scenario developers or content experts.
4.2.5 The contractor shall provide NIST/NICE training tracks and the capability for the administrator/management role to create custom training tracks tailored for our members.
4.2.6 The gamified online training platform shall provide integrated reporting capabilities which provide training overview, showing progression and performance results of each user account.
4.2.6.1 The contractor shall provide Student Skills and Strengths visuals which depict the rating of skills undertaken for each member
4.2.7 The contractor shall provide training content of external website links cached on the training platform with live links available, if applicable
4.2.8 The contractor shall provide an availability of 98% uptime, or provide credit in the form of license extensions to offset the loss of use for availability less than 98%
4.2.9 The contractor shall designate a process by which the customer can request specific scenarios for incorporation into the lab training environment.
4.2.10 The contractor shall provide quarterly reports of their internal roadmap of new labs and conduct quarterly sessions with government stakeholders to collect feedback for consideration in future lab requirements, not to direct custom lab creation.
4.2.11 The gamified online training platform shall provide new challenges at the rate of standard licensing release not to be fewer than 6 challenges, labs, scenarios or other instruction tool per month.
4.2.11.1 Over a quarter, over 50% (based on the 18 minimum) of added content of should map to Analyze, Collect and Operate, Investigate and Securely Provision NICE Categories
4.2.10.2 At least 1 lab per quarter should map to a recent Cyber Vulnerability and Exposure (CVE) or Advanced Persistent Threat (APT)
4.2.10.3 Labs should be mapped to the MITRE ATT&CK Matrix where relevant.
4.2.10.4 New labs will cover a variety of difficulty levels from foundational skillsets and technologies to advanced techniques, methodologies, and threats.
5 DELIVERABLES
Deliverable PWS Ref.
Delivery Date
Training License(s) 3.1 License(s) shall be delivered within 10 calendar days of contract award.
6 PLACE OF PERFORMANCE
6.1 Training will be conducted online from commercial networks and the Air Force Networks (AFNET).
7 PERIOD OF PERFORMANCE
7.1 The desired PoP is 1 year of service from contract award
7.1.1 The training platform licenses shall be delivered within 10 calendar days of contract award.
7.1.2 Contractor shall coordinate with customer no later than 2 business days after date of contract.
7.1.3 Contractor shall provide license(s) that provide training for 1 year.
8 CONTACT INFORMATION
8.1 The customer POC is Capt Mackenzie Cross mackenzie.cross.1@us.af.mil (preferred), 808-312-5459
(alternate), M-F 0800-1600 HST.
mailto:mackenzie.cross.1@us.af.mil
Attachment 1 - Training Objectives and Outlines
• Cyber Fundamentals o Terminology o OS Fundamentals o Network Fundamentals
• End User/Server Exploitation o Windows o Unix o Significant Operating System (OS) Update Milestones
Features, Indicators, Artifacts o OS Exploitation Playgrounds
• Infrastructure (Networking Device) Exploitation o Cisco o Palo Alto o Network Device Exploitation Playground
• Internet of Things Exploitation o SOHO devices o Home Routers o Home Appliances o SCADA
• Reverse Engineering o Malware Analysis o Protection Bypass o Reach back/C2 investigation
• Exploit Development o Windows/Unix o Stack and Heap Overflows o Gadget Development o Bypassing Kernel Protections
• Scripting/Programming o Bash o Python o Powershell o VBS
• Windows Domain Administration o Domain Controllers o Domain Services Overview
Active Directory
LDAP
o Administration Powershell
• Version Change Overview
WMIC/WINRS
• Obfuscation, Evasion o Tunneling o Encoding o Masquerading
DNS tunnels HTTPS tunnels o Pivoting IP tables SOCKS proxy Portproxy o Anti-Virus Evasion Techniques
• Post Exploitation o Privilege Escalation o Persistence o Information Gathering/Transporting
Automation
• Implant Development o C2 mechanisms o Hiding
• Tech Writing
• Advanced Persistent Threat (APT) Studies o Tool Exercises o RE Environments
• Infrastructure Hacking o Enumeration o Banner grabbing o DNS enumeration o SMTP o Zone transfer o HTTP parameters o Nmap o Nessus o Bespoke scanning script creation o SSL Cipher Enum o Scapy o Testssl o BloodHound
• Credential Cracking o Brute-force o Password spraying o Credential Stuffing o Mimikatz o Lazagne password dumping o JTR, custom password lists o WEP cracking o WPA cracking o Service Exploitation o SNMP o SMB o Responder o Kerberoasting o LDAP o FTP o Printer o Domain Controllers o Privilege Escalation o Service Weaknesses - Linux o Routing Modifications - Linux o Linux configuration errors o Vulnerable Service paths - Windows o Service Permissions - Windows o DLL hijacking o Container security o NFS permission weaknesses o Applocker bypassing
• Web Application Hacking o Directory traversal o Page source code review o Brute forcing o Cross-Site request forgery o Command execution o Unrestricted file upload o File inclusion vulnerabilities o Cross-site scripting - reflected, filter evasion and stored o Server side includes o SQL Injection
• Hidden data
• UNION Queries
• Enumeration
• Filter Evasion
• String Concatenation
• Boolean Based blind injection
• Time Based Blind injection
• File Download
• UNION queries
• SQLMap
• Threat intelligence: Offensive labs based on latest CVEs such examples include vulnerabilities on o Citrix o Docker o Kubernetes o Aviatrix VPN o Windows UAC bypassing o rConfig o Sudo command o SMB protocol o LibreOffice o Exim server o Bluekeep o Winrar o Windows API o Adobe o Apache o Chrome o Internet Explorer
• Red Team: Many red team environments including full windows domains spun up with multiple machines o Pivoting o Privilege escalation o C2 frameworks such as PoshC2 o Modbus protocol hacking
Attachment 2 – NICE Framework Training Objectives
• All-Source Analysis (Analyze)
• Cyber Defense Analysis (Protect & Defend)
• Cyber Defense Infrastructure Support (Protect & Defend)
• Cyber Investigation (Investigate)
• Cyber Operational Planning (Collect & Operate)
• Cyber Operations (Collect & Operate)
• Data Administration (Operate & Maintain)
• Digital Forensics (Investigate)
• Executive Cyber Leadership (Oversee & Govern)
• Exploitation Analysis (Analyze)
• Knowledge Management (Operate & Maintain)
• Language Analysis (Analyze)
• Legal Advice and Advocacy (Oversee & Govern)
• Risk Management (Securely Provision)
• Software Development (Securely Provision)
• Strategic Planning and Policy (Oversee & Govern)
• Systems Analysis (Operate & Maintain)
• Systems Architecture (Securely Provision)
• Systems Development (Securely Provision)
• Targets (Analyze)
• Technology R&D (Securely Provision)
• Test and Evaluation (Securely Provision)
• Threat Analysis (Analyze)
• Training; Education and Awareness (Oversee & Govern)
• Vulnerability Assessment and Management (Protect & Defend)
| Performance of Work (PWS) |
| Commercial Online Training Platform |
File details come from the government source that posted it. Updated .