Posts

Showing posts with the label training

Bejtlich Teaching at Black Hat West Coast Trainings

Image
I'm pleased to announce that I will be teaching at  Black Hat West Coast Trainings  9-10 December 2013 in Seattle, Washington. This is a brand new class, only offered thus far in Las Vegas in July 2013. I posted  Feedback from Network Security Monitoring 101 Classes  last month as a sample of the student feedback I received. Several students asked for a more complete class outline. So, in addition to the outline posted currently by Black Hat, I present the following that shows what sort of material I cover in my new class. Please note that discounted registration ends 11:59 pm EDT October 24th. You can  register here . I have only one session available in Seattle and fewer seats than in Las Vegas, so please plan accordingly. Thank you. OVERVIEW Is your network safe from intruders? Do you know how to find out? Do you know what to do when you learn the truth? If you are a beginner, and need answers to these questions, Network Security Monitoring...

Bejtlich Teaching New Class at Black Hat in July

Image
I'm pleased to announce I will teach two sessions of a brand-new two day class at Black Hat USA 2013 this summer. The new class is Network Security Monitoring 101 . From the overview: Is your network safe from intruders? Do you know how to find out? Do you know what to do when you learn the truth? If you are a beginner, and need answers to these questions, Network Security Monitoring 101 (NSM101) is the newest Black Hat course for you. This vendor-neutral, open source software-friendly, reality-driven two-day event will teach students the investigative mindset not found in classes that focus solely on tools. NSM101 is hands-on, lab-centric, and grounded in the latest strategies and tactics that work against adversaries like organized criminals, opportunistic intruders, and advanced persistent threats. Best of all, this class is designed *for beginners*: all you need is a desire to learn and a laptop ready to run a few virtual machines. Instructor Richard Bejtlich has taug...

TCP/IP Weapons School 3.0 in McLean, VA 26-27 Oct

Image
I just created a class page for my upcoming TCP/IP Weapons School 3.0 in McLean, VA on 26-27 October 2011. I decided to offer this class because I haven't taught anything nearby in quite a while, and many people asked for a class in NoVA. I don't plan to offer this sort of "solo" (i.e., outside Black Hat) class again (or anytime soon). So, if you're in the neighborhood and you'd like to attend a TWS3 class, this could be your chance! The venue only seats 20-25 students, so please keep that in mind. You can register through RegOnline immediately. Thank you. Tweet

Bejtlich Webinar for Dark Reading and InformationWeek

Image
Thanks to Dark Reading and InformationWeek I will participate in the How Security Breaches Happen online virtual event on 25 August 2011. At 1330 ET I present with Nicholas J. Percoco and Kelly Jackson Higgins on "Why Bad Breaches Happen To Good Companies." I will share the enterprise/CSO perspective while Nicholas will present the adversary simulation/pen tester perspective. Kelly will moderate. Lots of other speakers will participate from 1030 ET to 1815 ET. We hope you can attend! Tweet

Feedback from Latest TCP/IP Weapons School 3.0 Class

Image
At Black Hat in Las Vegas and USENIX Security in San Francisco I taught three TCP/IP Weapons School 3.0 classes. I think my weekday class at Black Hat set a personal record student count, and I was glad to have Steve Andres from Special Ops Security there to help students with questions and lab issues! I wanted to share some feedback from the classes, in case any of you are considering attending an upcoming class. Currently I'm scheduled to teach at Black Hat Abu Dhabi on 12-13 December. The only other possibilities for training this year include a class in northern VA in either September or October, and a class the weekend before USENIX LISA in Boston on 3-4 December 2011. Next year I will likely return to Las Vegas again in the summer (21-24 July) and DC in the fall (30-31 Oct) but beyond that I am not sure how much training I might do in 2012. Student feedback from TWS3 included: I've been to a lot of training sessions and this was by far the best. The dis...

Security Conference Recommendations

Image
After my post Bejtlich Teaching at USENIX Security in San Francisco 8-9 Aug a reader asked the following: Richard, I was curious if you could suggest other security conferences that either you have attended or have heard are better than average? It seems as though everyone and their brother sponsor some sort of security conference and it is difficult to tell how educational they will be just by reading the website. Perhaps you could provide some insight into how you determine which conferences you would actually pay to attend? Thanks! Great question. The answer that follows is just my opinion, and I'm sure others feel differently. For me, I like these conferences: Black Hat offers the best combination of training plus briefings per unit time, on a consistent basis. In other words, I believe attendees will learn more in two days of Black Hat Training plus two days of Black Hat Briefings compared to any alternatives, every year. The content is uniformly high, regardless of whet...

Bejtlich Teaching at USENIX Security in San Francisco 8-9 Aug

Image
For the first time in four years, I will teach for the USENIX organization! I'm pleased to announce that on August 8-9 at USENIX Security 2011 in San Francisco, I will teach a special two-day edition of TCP/IP Weapons School 3.0 . This class is designed for junior and intermediate security analysts. The "sweet spot" for the potential student is someone working in a security operations center (SOC) or computer incident response team (CIRT), or someone trying to establish one of those organizations. The class is very hands-on, and focuses on labs and discussions. There are less than 10 slides at the very beginning of the class, and I build the flow of the class based on what you want to hear. If you would like details on the class, please see the linked site. You may also find my announcement for my Black Hat sessions on 30-31 July and 1-2 August to be helpful too. It will be a busy few weeks this summer but I'm looking forward to seeing you learn the investiga...

UBM Cancels GTEC, Bejtlich Considers Alternatives

Image
I received word this week that the venue hosting my special session of TCP/IP Weapons School 3.0 was cancelled! That means no GTEC and no extra DC class. I'm sad to hear this because I'm receiving word from students wondering what happened. As best I understand it, the current Federal budget situation made hosting this conference a tough prospect for the DC crowd. At this point I'm evaluating options, including hosting a class myself. If you would be interested in attending a group class of TCP/IP Weapons School 3.0 in northern VA this year, please email training [at] taosecurity [dot] com. I think a class late in the year, hopefully during FY 2012 (so 1 Oct or later), might be the best option for Federal workers enduring budget woes. I'd rather teach within another venue, like Black Hat, but if there's enough demand from the cancelled GTEC event I'll see what it takes to offer a solo class. As noted on my Training site, I am teaching Two Sessions of TWS3...

Bejtlich Teaching at Black Hat EU 2010

Image
Black Hat was kind enough to invite me back to teach multiple sessions of my 2-day course this year. After Black Hat DC comes Black Hat EU 2010 Training on 12-13 April 2010 at Hotel Rey Juan Carlos I in Barcelona, Spain. I will be teaching TCP/IP Weapons School 2.0 . Registration is now open. Black Hat set five price points and deadlines for registration. Super early ends 1 Feb Early ends 1 Mar Regular ends 1 Apr Late ends 11 Apr Onsite starts at the conference Seats are filling -- it pays to register early! If you review the Sample Lab I posted earlier this year, this class is all about developing an investigative mindset by hands-on analysis, using tools you can take back to your work. Furthermore, you can take the class materials back to work -- an 84 page investigation guide, a 25 page student workbook, and a 120 page teacher's guide, plus the DVD. I have been speaking with other trainers who are adopting this format after deciding they are also tired of the PowerPoint...

Friday is Last Day to Register for Black Hat DC at Reduced Rate

Image
Black Hat was kind enough to invite me back to teach multiple sessions of my 2-day course this year. First up is Black Hat DC 2010 Training on 31 January and 01 February 2010 at Grand Hyatt Crystal City in Arlington, VA. I will be teaching TCP/IP Weapons School 2.0 . Registration is now open. Black Hat set five price points and deadlines for registration, but only these three are left. Regular ends 15 Jan Late ends 30 Jan Onsite starts at the conference Seats are filling -- it pays to register early! If you review the Sample Lab I posted earlier this year, this class is all about developing an investigative mindset by hands-on analysis, using tools you can take back to your work. Furthermore, you can take the class materials back to work -- an 84 page investigation guide, a 25 page student workbook, and a 120 page teacher's guide, plus the DVD. I have been speaking with other trainers who are adopting this format after deciding they are also tired of the PowerPoint slide p...

Difference Between Bejtlich Class and SANS Class

Image
A comment on my last post, Reminder: Bejtlich Teaching at Black Hat DC 2010 , a reader asked: I am trying to get my company sponsorship for your class at Black Hat. However, I was ask to justify between your class and SANS 503, Intrusion Detection In-Depth. Would you be able to provide some advice? That's a good question, but it's easy enough to answer. The overall point to keep in mind is that TCP/IP Weapons School 2.0 is a new class, and when I create a new class I design it to be different from everything that's currently on the market. It doesn't make sense to me to teach the same topics, or use the same teaching techniques, found in classes already being offered. Therefore, when I first taught TWS2 at Black Hat DC last year, I made sure it was unlike anything provided by SANS or other trainers. Beyond being unique, here are some specific points to consider. I'm sure I'll get some howls of protest from the SANS folks, but they have their own platform t...

PowerLite S4 Multimedia Projector

This week I taught TCP/IP Weapons School, Layers 2-3 at Techno Security 2007 in Myrtle Beach, SC. I enjoyed teaching the class, especially since several students were repeat customers. Two were even alumni from classes I taught at Foundstone five years ago! Because the cost of renting a projector and screen from the hotel (and even from rentacomputer.com) seemed outrageous, I decided to buy my own. I purchased an Epson PowerLite S4 Multimedia Projector and Da-Lite 72263 Versatol Tripod Screen 70"x70" Matte White with Keystone Elim for use in the class. I was extremely pleased with both. In fact, right after I bought the Epson projector I saw it covered in a USA TODAY review, which helped validate my purchase. If you're in the market for a projector and screen combination for less than $800 (or even $700 if you're not time-crunched, as I was) then I think you'll like these products.

Reminder: Early Registration Ends Soon for Bejtlich at SANSFIRE 2007

I'll be teaching a special one-day course, Enterprise Network Instrumentation , at SANSFIRE 2007 in Washington, DC on 25 July 2007. ENI is a one-day course designed to teach all methods of network traffic access. If you have a network you need to monitor, ENI will teach you what equipment is available (hubs, switch SPAN ports, taps, bypass switches, matrix switches, and so on) and how to use it effectively. Everyone else assumes network instrumentation is a given. ENI teaches the reality and provides practical solutions. Please register while there are still seats available. My class is the day before all the six-day tracks begin. If you register before 6 June you will save $250. If you register by 27 June you will save $150. If you take this one-day class with a full SANS track my class only costs $450. Please note SANS set all of these prices and schedules. This is the only time I'll be teaching this class in 2007. Thank you. Update: I cancelled the class. If you ...

Bejtlich Teaching Network Security Operations in Chicago

I am happy to announce that I will be teaching a three day edition of my Network Security Operations training class in Chicago, IL on 27-29 August 2007. This is a public class, although I will be speaking at the 30 August meeting of the Chicago Electronic Crimes Task Force . Please register here . The early discount applies to registrations before midnight 27 July. ISSA members get an additional discount on top of the early registration discount. Network Security Operations addresses the following topics: Network Security Monitoring NSM theory Building and deploying NSM sensors Accessing wired and wireless traffic Full content tools: Tcpdump, Ethereal/Tethereal, Snort as packet logger, Daemonlogger Additional data analysis tools: Tcpreplay, Tcpflow, Ngrep, Netdude Session data tools: Cisco NetFlow, Fprobe, Flow-tools, Argus, SANCP Statistical data tools: Ipcad, Trafshow, Tcpdstat, Cisco accounting records Sguil (sguil.sf.net) Case studies, personal war stories, and attendee partic...

Bejtlich Teaching Network Security Operations in Cincinnati

I am happy to announce that I will be teaching a three day edition of my Network Security Operations training class in Cincinnati, OH on 21-23 August 2007. The Cincinnati ISSA chapter is hosting the class. Please register here . The early discount applies to registrations before 20 July. ISSA members get an additional discount on top of the early registration discount. Network Security Operations addresses the following topics: Network Security Monitoring NSM theory Building and deploying NSM sensors Accessing wired and wireless traffic Full content tools: Tcpdump, Ethereal/Tethereal, Snort as packet logger, Daemonlogger Additional data analysis tools: Tcpreplay, Tcpflow, Ngrep, Netdude Session data tools: Cisco NetFlow, Fprobe, Flow-tools, Argus, SANCP Statistical data tools: Ipcad, Trafshow, Tcpdstat, Cisco accounting records Sguil (sguil.sf.net) Case studies, personal war stories, and attendee participation Network Incident Response Simple steps to take now that make incident ...

Brief Thoughts on Security Education

Once in a while I get requests from blog readers for recommendations on security education. I am obviously biased because I offer training independently, in private and public forums. However, I've attended or spoken at just about every mainstream security forum, so I thought I would provide a few brief thoughts on the subject. First, decide if you want to attend training , briefings , or classes . I consider training to be an event of at least 1/2 day or longer. Anything less than 1/2 day is a briefing, and is probably part of a conference. Some conferences include training, so the two topics are not mutually exclusive. Classes include courses offered by .edu's. Training events focus on a specific problem set or technology, for an extended period of time. Training is usually a stand-alone affair. For example, when I prepared for my CCNA , took a week-long class by Global Net Training . If I choose to pursue the CCNP I will return to GNT for more training. I seldom a...

Bejtlich Teaching at Sys Admin Magazine Conference in Baltimore

I will be teaching two half-day tutorials for the Sys Admin Technical Conference on Monday 7 May 2007 in Baltimore, MD. I'll spend the morning teaching Network Incident Response and the afternoon teaching Network Forensics. Early Bird Pricing for SA Tech 2007 ends 30 March 2007, after which the price will escalate by $250. Please register before the seats fill. Thank you.

Bejtlich at AusCERT and Secure Agility/Sydney

I'm pleased to announce I will be speaking and training in Australia in May 2007. First, I will attend the AusCERT Asia Pacific Information Technology Security Conference in Gold Coast, Australia. According to the schedule I'll be discussing the Self-Defeating Network at 1420 on Wednesday 23 May 2007. The following day I'll present half-day tutorials on Network Incident Response and Network Forensics. Registration is open now. The day after my AusCERT tutorials I will be joining friends at Secure Agility to teach Network Security Monitoring in Sydney, Australia on Friday 25 May 2007. If you'd like to attend this class please review the class page and return the registration form to me before the class fills. Thanks to Christian Heinrich for coordinating my visit to Sydney. Secure Agility will be handling collecting class fees, and I'll post more information when that aspect of the event is finalized. Thank you.

Bejtlich Teaching at SANSFIRE 2007

I'll be teaching a special one-day course, Enterprise Network Instrumentation , at SANSFIRE 2007 in Washington, DC on 25 July 2007. ENI is a one-day course designed to teach all methods of network traffic access. If you have a network you need to monitor, ENI will teach you what equipment is available (hubs, switch SPAN ports, taps, bypass switches, matrix switches, and so on) and how to use it effectively. Everyone else assumes network instrumentation is a given. ENI teaches the reality and provides practical solutions. Please register while there are still seats available. Thank you.

TaoSecurity 2007 Training Schedule

I just posted the TaoSecurity 2007 Training Schedule on my company Web site. I didn't include all of the places I might be teaching this year. All of the public classes are tentative at this point, but I am working on securing hosting facilities. You'll notice I plan to conduct six public classes across the US, and I am appearing at a few overseas conferences too -- including a one-day public class in Sydney, Australia. If you would like to support my bid to teach at Black Hat USA Training (28-21 July 2007) in Las Vegas, NV, please email Ping Look via ping [at] blackhat [dot] com . Email training [at] taosecurity [dot] com for advance details on the classes listed below. Registration information for public classes will be posted shortly. I maintain the latest schedule at TaoSecurity training . If you would like me to conduct a private class at your facility, please email training [at] taosecurity [dot] com . Thank you. I hope to meet you in 2007!