This schedule is subject to change before the beginning of the school.
Week 1: Onboarding
Students will participate in site-specific onboarding proccesses, including badging, drug testing, employment paperwork, and required training. Students will also meet their mentors and other local national laboratory staff as well as other students. Finally, students will settle into their work locations and prepare for instruction (e.g., setting up computational resources for analysis).
Week 2: Network Archaeology
Network Archaeology teaches techniques to extract undocumented protocol communications from network traffic. Students will learn to use Cyber Fire toolsets to create their own custom decoders.
Week 3: Host Forensics
Host Forensics will teach you how to analyze forensic memory and hard drive images.
Weeks 4-5: Malware Analysis
Malware Analysis will walk you through using various tools to pull apart executables, and understand their capabilities and program flow.
Week 6: Operational Technology
During this week, students will learn how Operational Technology (OT) differs from traditional Information Technology, and get a chance to work with OT equipment from a security perspective.
Weeks 7-10: Analysis and Presentation
Students will be given their first piece of the project dataset. This dataset either mimics a real APT incident, or is real data from a past APT incident at a DOE site.
Using techniques taught in the classes, and with staff assistance, teams will disassemble the dataset, looking for indicators of compromise and better evidence fragments, such as command and control traffic, transferred files, malware executables, and more.
The school ends with a presentation of findings to senior site management. You play the role of an incident response team, presenting your findings to senior management. You will be required to package your findings in a standard report template, then give a verbal presentation, and field questions.