ICS515 will help you gain visibility and asset identification in your Industrial Control System (ICS)/ Operational Technology (OT) networks, monitor for and detect cyber threats, deconstruct ICS cyber attacks to extract lessons learned, perform incident response, and take an intelligence-driven approach to executing a world-leading ICS cybersecurity program to ensure safe and reliable operations. The course has gone through a significant update changing much of the content, most of the labs, and adding a day in course length. This Course Will Prepare You To ▐ Examine ICS networks and identify the assets and their data flows in order to understand the network information needed to identify advanced threats ▐ Use active defense concepts such as threat intelligence consumption, network security monitoring, malware analysis, and incident response to safeguard the ICS ▐ Build your own Programmable Logic Controller using the SANS ICS515 Student Kit, which you retain after the class ends ▐ Gain in-depth knowledge on ICS targeted threats and malware including STUXNET, HAVEX, BLACKENERGY2, CRASHOVERRIDE, TRISIS/TRITON, and EKANS ▐ Leverage technical tools such as Shodan, Wireshark, Zeek, Suricata, Volatility, FTK Imager, PDF analyzers, PLC programming software, and more ▐ Create indicators of compromise (IOCs) in YARA ▐ Take advantage of models such as the Sliding Scale of Cybersecurity, the Active Cyber Defense Cycle, the Collection Management Framework, and the ICS Cyber Kill Chain to extract information from threats and use it to encourage the long-term success of ICS network security Syllabus Summary SECTION 1: ICS Cyber Threat Intelligence SECTION 2: Visibility and Asset Identification SECTION 3: ICS Threat Detection SECTION 4: Incident Response SECTION 5: Threat and Environment Manipulation SECTION 6: Capstone Day, Under Attack! You Will Be Able To ▐ Analyze ICS-specific threats and take proper courses of action to defend the industrial control systems ▐ Establish collection, detection, and response strategies for your ICS networks ▐ Use proper procedures during ICS incident response ▐ Examine ICS networks and identify the assets and their data flows in order to understand the network information needed to identify advanced threats ▐ Use active defense concepts such as threat intelligence consumption, network security monitoring, malware analysis, and incident response to safeguard the ICS ▐ Build your own Programmable Logic Controller using the SANS ICS515 Student Kit, which you retain after the class ends ▐ Gain in-depth knowledge on ICS targeted threats and malware including STUXNET, HAVEX, BLACKENERGY2, CRASHOVERRIDE, TRISIS/ TRITON, FROSTYGOOP, EKANS, and PIPEDREAM ▐ Leverage technical tools such as Shodan, Wireshark, Zeek, Suricata, Volatility, FTK Imager, PDF analyzers, PLC programming software, and more ▐ Create indicators of compromise (IOCs) in YARA ▐ Take advantage of models such as the Sliding Scale of Cybersecurity, the Active Cyber Defense Cycle, the Collection Management Framework, and the ICS Cyber Kill Chain to extract information from threats and use it to encourage the long-term success of ICS network security Who Should Attend ▐ ICS incident response team leads and members ▐ ICS and operations technology security personnel ▐ IT security professionals ▐ Security Operations Center team leads and analysts ▐ ICS red team and penetration testers ▐ Active defenders NICE Framework Work Roles ▐ Cyber Defense Incident Responder (OPM 531) ▐ ICS/SCADA Security Engineer ▐ ICS/OT Systems Engineer ▐ OT SOC Operator ICS515: ICS Visibility, Detection, and Response™ CURRICULUM: Industrial Control Systems (ICS) Security 6 Day Program 36 CPEs 25+ Labs For detailed course description, visit SANS.ORG/ICS515 WAYS TO TAKE ICS515 Live Online In-Person OnDemand “ This course was like a catalyst. It not only boosted my knowledge about the threats facing ICS environments and provided me with a framework to actively defend these threats, it also inspired me to learn more.” —Srinath Kannan, Accenture DoD 8140* GRID Response and Industrial Defense giac.org/grid Robert M. Lee Course Author * sans.org/8140