SOO_Attch 1_JQR_Coverage.xlsx
XLSX spreadsheet 15 KB Posted
- Attached to
- 92 COS Network Defense Range (NDR) Training Event Federal contract opportunity
- Solicitation number
- FA8773-20-Q-0023
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NDR_QA_Spreadsheet.xlsx | XLSX spreadsheet | |
| 92 NDR Combined Synopsis Solicitation - FA877320Q0023.pdf | ||
| Attch 2 - 92 NDR Addendum to 522121 Instructions to Offerors.docx | DOCX document | |
| Attch 3-92 NDR Addendum to 522122 Eval Factors.docx | DOCX document | |
| Attch 4 - 92 NDR QA Speadsheet.xlsx | XLSX spreadsheet | |
| Attch 1 - 92 NDR SOO.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1
| UNCLASSIFIED//FOR OFFICIAL USE ONLY | ||||
| Crew Position | Task | Subtask | Description | |
| NA - Network Analyst | ||||
| Senior | 3.1 - Network Architecture Analysis - Given a compromised enterprise network environment with multiple sensors, a network map, and policies, the individual must complete each task with no assistance | 3.1.1 | Develop an analytic to identify anomalous traffic between hosts that should not communicate or communicating in unusual ways. | |
| 3.1.2 | Generate a report that outlines the attack surface of key terrain and networking devices that support it. | |||
| 3.1.3 | Develop an analytic to identify network traffic that |
deviates from established policies.
| 3.1.4 | Analyze network traffic and ensure that it conforms to approved documentation for the network (Ports, Protocols, and Services). | |||
| 3.1.5 | Explain the differences between a network mirror port and a network tap | |||
| 3.5 - Given a SIEM ingesting traffic from multiple network sensors and an intelligence report with network IOCs, the individual must complete the following tasks. | 3.5.1 | Query the database for network IOCs | ||
| 3.5.2 | Build visualizations and dashboards to display requested network data. | |||
| 3.5.3 | Create alerts in the SIEM for network IOCs | |||
| 3.5.4 | Generate reports in the SIEM for network baseline analysis | |||
| 3.5.5 | Generate reports in the SIEM for network baseline anomalies | |||
| HA, L - Host Analyst, Linux | ||||
| Senior | 2.1 - Team Mission | 2.1.2 | Describe the process of integrating intelligence reporting into your mission | |
| 2.1.3 | Describe the process of developing analytics | |||
| 2.1.8 | Given a set of vulnerabilities found on mission, describe how you would prioritize the vulnerabilities for the mission owner | |||
| 3.6 - Detect and Identify Malicious Activity | 3.6.2 | Describe how to ensure log aggregation is configured properly by others and conduct statistical analysis. | ||
| 3.6.3 | Explain how to oversee the development of host-based IDS/IPS signatures ensuring all settings and signatures are maintained as directed, assisting network owner as required. | |||
| 3.6.4 | Describe the procedures or techniques required to verify and validate host-based IDS/IPS alerts. | |||
| 3.6.5 | Discuss how to analyze multiple memory captures to determine anomalous |
behavior and develop a detailed report including timeline of compromise.
| 3.6.6 | Describe how to take a finding of a compromise and develop a custom signature(s) and/or rule(s) to identify it throughout the network. | |||
| 3.7 - Identify Rootkit Presence | 3.7.1 | Describe analysis techniques that may help identify hidden processes, libraries, binaries, modules, and/or strange filesystem activity related to rootkit behavior. | ||
| 3.8 - Analyze Known/Suspected Malware | 3.8.2 | Describe how to discover the actions of a malicious script and be able to brief your findings | ||
| 3.9 - Perform System Forensic Analysis | 3.9.1 | Discuss the process of ensuring the capture of forensically sound memory and disk images are properly performed and stored. | ||
| 3.9.2 | Describe how to supervise and contribute to the forensic investigation of a memory image including documenting and reporting. | |||
| 3.9.3 | Describe how to perform disk forensics and how to create a detailed report to include timeline and possible signatures. | |||
| 3.10 - Apply Systems Analyst Tasks on Large Numbers Of Systems Simultaneously | 3.10.1 | Describe how to automate essential advanced tasks across an enterprise network relating to cyberspace operations. | ||
| 3.15 - Detect and Identify Malicious Activity | 3.15.1 | Develop the reporting and recording of discovered potentially malicious processes, libraries, and modules on a compromised system. | ||
| 3.15.2 | Evaluate that log aggregation is configured properly by team members and conduct statistical analysis across different datasets. | |||
| 3.15.3 | Develop host-based IDS/IPS signatures according to a mission plan, ensuring all settings and signatures are kept up to date. | |||
| 3.15.4 | Verify the validity of host-based IDS/IPS alerts. | |||
| 3.15.5 | Analyze multiple memory captures to determine anomalous behavior and develop a detailed report to include a timeline and root cause analysis. | |||
| 3.15.6 | Brief the team outlining key log entries/Event ID's to build a timeline of compromise. | |||
| 3.16 - Identify Rootkit Presence | 3.16.1 | Use analysis techniques to identify processes, libraries, modules, and other activity that have been hidden. Develop instructions to mitigate the threat of the discovered rootkit. | ||
| 3.17 - Analyze Known/Suspected Malware | 3.17.1 | Perform hasty reverse engineering of binary malicious applications. Brief others on how to mitigate the risk. | ||
| 3.18 - Perform System Forensic Analysis | 3.18.1 | Oversee the capturing and storing of forensically sound memory and disk images ensuring everyone follows best practices. | ||
| 3.18.2 | Lead the forensic investigation of a memory image. Ensure all carved files are analyzed and potential threats are documented and reported. | |||
| 3.18.3 | Perform proper disk forensics and create a detailed report to include timeline and possible signatures. | |||
| 3.19 - Apply Systems Analyst Tasks on Large Numbers of Systems Simultaneously | 3.19.1 | Create a script that automates an essential advanced task across a given network with the minimum requirements outlined in the answer key. | ||
| HA, W - Host Analyst, Windows | ||||
| Senior | 3.7 - Implement Auditing of System Events for Threat Detection | 3.7.1 | Explain how to identify key log entries/Event ID's as indicators of compromise, use a Security information and event management (SIEM) platform to correlate indicators of compromise, and develop dashboards to better visualize data. | |
| 3.8 - Detect and Identify Malicious Activity | 3.8.1 | Explain how to analyze potentially malicious processes, libraries, and modules on all systems in a complex domain | ||
| 3.8.2 | Explain how to oversee the monitoring of active directory for the creation of accounts that are unauthorized and potential threats | |||
| 3.8.3 | Explain how to oversee the auditing of a complex Enterprise Network. | |||
| 3.8.4 | Explain how to configure, forward, and statically analyze logs from all workstations in an enterprise environment. | |||
| 3.8.5 | Explain how to oversee the development of host-based IDS/IPS signatures and settings. | |||
| 3.8.6 | Explain how to oversee the tuning of host-based IDS/IPS alerts in order to evaluate their severity while eliminating false positives. | |||
| 3.8.7 | Given an enterprise domain, explain how to use host volatile data to compare active processes, libraries, and modules against databases of known advanced malware. | |||
| 3.9 - Identify Rootkit Presence | 3.9.1 | Explain how to utilize tools and analysis techniques to identify processes, libraries, modules, and other activity that have been obfuscated and might indicate the presence of a more advanced rootkit on endpoints. | ||
| 3.10 - Analyze Known/Suspected Malware | 3.10.1 | Explain reverse engineering concepts of binary applications while demonstrating knowledge of the underlying code. | ||
| 3.10.2 | Describe how to conduct static code analysis to determine what an advanced script is doing. | |||
| 3.11 - Perform System Forensic Analysis | 3.11.1 | Given an enterprise domain, explain how to capture forensically sound memory and disk images across multiple systems and perform trend and outlier analysis. | ||
| 3.11.2 | Given an enterprise domain, explain how to identify potentially malicious processes, connections, libraries, and other malicious code/activity from a memory image and perform trend and outlier analysis. | |||
| 3.11.3 | Given an enterprise domain, describe the process of conducting disk forenscis on multiple images and perform trend and outlier analysis. | |||
| 3.12 - Apply Systems Analyst Tasks on Large Numbers of Systems Simultaneously | 3.12.1 | Describe how to automate more advanced and repetitive tasks on remote workstations within a domain. | ||
| 3.16 - Evaluate Customer Security Policy Posture | 3.16.1 | Identify security posture shortcomings in policy and training and assess customer security posture across a complex enterprise network. | ||
| 3.16.2 | Review organizational policies and documentation for appropriate use and user privileges. | |||
| 3.18 - Implement Auditing of System Events for Threat Detection | 3.18.1 | Identify key log entries/Event ID's as indicators of compromise, use a SIEM to correlate indicators of compromise and develop dashboards to better visualize data for an enterprise network. | ||
| 3.19 - Detect and Identify Malicious Activity | 3.19.1 | Analyze potentially malicious processes, libraries, and modules on all systems in the domain to find advanced malware. | ||
| 3.19.2 | Given an enterprise level domain controller, monitor active directory for creation of unauthorized/potentially malicious accounts. | |||
| 3.19.3 | Given an enterprise domain, configure, forward, and statically analyze logs from allworkstations to perform outlier analysis. | |||
| 3.19.4 | Given an enterprise domain, develop host-based IDS/IPS signatures and settings and facilitate change management | |||
| 3.19.5 | Given an enterprise domain, tune host-based IDS/IPS alerts and evaluate their severity while eliminating false positives. | |||
| 3.19.6 | Given an enterprise domain, use host volatile data to compare active processes, libraries, and modules against databases of known good/bad to find advanced malware. | |||
| 3.20 - Identify Rootkit Presence | 3.20.1 | Given a Windows host, utilize tools and analysis techniques to identify processes, libraries, modules, and other activity that have been obfuscated and might indicate the presence of an advanced rootkit. | ||
| 3.21 - Analyze Known/Suspected Malware | 3.21.1 | Perform hasty reverse engineering of advanced malware in order to develop IOC’s and recommend remedial actions. | ||
| 3.21.2 | Given an advanced malicious script, conduct static code analysis to determine what the script is doing. | |||
| 3.22 - Perform System Forensic Analysis | 3.22.1 | Given an enterprise domain, capture forensically sound memory and disk images across a domain. | ||
| 3.22.2 | Identify advanced malicious processes, connections, libraries, and other malicious code/activity from a memory image. | |||
| 3.22.3 | Conduct disk forensics on multiple images from a domain and perform trend and outlier analysis. | |||
| 3.23 - Apply Systems Analyst Tasks on Large Numbers of Systems Simultaneously | 3.23.1 | Given a list, automate advanced and repetitive tasks on remote workstations across an enterprise network. | ||
| UNCLASSIFIED//FOR OFFICIAL USE ONLY |
File details come from the government source that posted it. Updated .