Practical Course in Analysing and Countering Modern Cyber Threats
1Summary
Attackers do not announce themselves – by the time an alert fires, malware may already have been sitting quietly inside a network for weeks. The Analysing and Countering Modern Cyber Threats Practical Course, delivered by the Arab British Fellowship Training Academy, is built to close that gap between compromise and detection, training participants to read the behavioural signals that give an attack away long before the damage is done.
The course works hands-on through malware analysis, network traffic inspection, and forensic investigation using tools such as Wireshark, IDA Pro, and Snort, then applies that skill to advanced persistent threats (APT), insider risk, and incident documentation. By the end, participants can move from raw evidence to a confident, well-documented judgment about what happened and what to do next.
2Objectives and target group
Who Should Attend?
- Threat analysts and security engineers who investigate malware and advanced cyber attacks.
- Security experts managing incident response teams and threat analysis operations.
- Network and system security officers who need to assess complex cyber risks.
Knowledge and Benefits:
By the end of the program, participants will be able to:
- Analyze and assess modern cyber threats, including malware and advanced persistent threats (APT), using dedicated tools.
- Detect and investigate insider threats through behavioural analysis and user activity monitoring.
- Analyze network traffic to identify attack patterns and apply defensive measures to secure networks.
- Respond effectively to cybersecurity incidents and document findings for legal and organizational reporting.
3Course Content
-
Module 1: The Threat Landscape and Why Analysis Matters
- Defining cyber threats and how attack techniques have evolved over the past decade.
- Types of modern threats: malware, APTs, phishing, and social engineering.
- Why threat analysis matters: detecting attacks before impact and predicting future ones through behavioural patterns.
-
Module 2: Tools and Methods for Analysing Attacks
- Dynamic and static malware analysis, plus network traffic and forensic analysis to uncover attacks.
- Working with forensic tools (EnCase, FTK), malware analysis tools (IDA Pro, OllyDbg), and network tools (Wireshark, TCPdump).
- Advanced malware analysis: ransomware, trojans, and de-obfuscation techniques.
-
Module 3: Advanced Persistent Threats – Detection to Response
- The stages of an APT attack, its targeted objectives, and case studies such as APT1 and APT28.
- Detecting multi-stage, multi-vector attacks using tools like Snort and Suricata.
- Early detection strategies, investigation tools, and case-based response to APT incidents.
-
Module 4: The Threat From Inside – Insider Risk and Behavioural Analytics
- Defining insider threats and their causes, and the risks tied to internal staff.
- Behavioural analysis techniques, anomaly detection, and User Behavior Analytics (UBA) tools.
- Identifying, preventing, and responding to threats from malicious insiders.
-
Module 5: Network Traffic Analysis and Defence
- Reviewing network traffic with Deep Packet Inspection (DPI) and Flow Analysis, plus IDS/IPS for early detection.
- Analysing DDoS, Man-in-the-Middle (MitM), wireless, and HTTP/DNS-based attacks.
- Defensive best practices using firewalls and SIEM, and securing wireless and virtualized environments.
-
Module 6: Incident Response, Forensics, and Reporting
- Effective incident response and the role of Computer Security Incident Response Teams (CSIRT).
- Gathering and analysing forensic evidence with tools such as Autopsy and Sleuth Kit.
- Documenting incidents accurately and producing reports and recommendations for improving security.
-
Module 7: Threat Analysis Across Sectors and Looking Ahead
- Cyber threats specific to financial, healthcare, and government sectors, plus industrial control systems (ICS) and critical infrastructure.
- Cloud and virtualization threats and how to analyze them.
- Predicting future attack trends and using artificial intelligence for advanced threat analysis.