Course Section 1 Content Section 1 Content Left Section 1 Content Right Credit Type: Course ACE ID: DDCI-0014 Version: 4 Organization's ID: LA Organization: DC3 Cyber Training Academy Location: Online Length: 5 days (50 hours) Minimum Passing Score: 70 ACE Credit Recommendation Period: 10/1/2024 - 9/30/2027 5/1/2021 - 9/30/2024 12/1/2017 - 4/30/2021 3/1/2014 - 11/30/2017 Credit Recommendation & Competencies Section 2 Content Section 2 Content Left Section 2 Content Right Level Credits (SH) Subject Upper-Division Baccalaureate 6 Network Analysis Description Section 3 Content Section 3 Content Left Section 3 Content Right Objective: The course objective is for students to explain log analysis methodology; explain benefits of log analysis in an intrusion investigation; analyze and evaluate log files; and extract information from log files. Learning Outcomes: Determine the begin and end time of a log file. Describe the logs found on computer systems and network devices. Describe the common attributes of log file contents. Identify relevant tools used in time normalization. Describe the technology approaches to parsing and analyzing data from logs. Identify diverse types of binary logs. Perform a search of a Windows event log with GUI tools. Identify the types of statistical data that Wireshark can present. Create statistics about HTTP GET requests. Use TCPdump command options to filter output. Describe web server log formats. Describe FTP server log formats. Describe Syslog log format. Define intrusion detection system (IDS) logs. Assess log file size. Identify Linux commands for filtering and searching. Use regular expressions to create search patterns. Use Excel to perform searches of log files. Create and use PivotTables in Excel. Use intrusion keywords to search log files. Analyze text logs for intrusion artifacts List the benefits of log analysis in an intrusion investigation. Describe the common attributes of log file content. Identify time skew and time bias. Describe technology options for performing log analysis. Perform extraction of data from binary logs. Perform a search of a network traffic capture with GUI tools. Perform a search of a network traffic capture with command-line tools. Identify the filters that can be used to narrow a search. Export statistical data from Wireshark. Use TCPdump to read a binary capture and redirect the output to a text file. Display the contents of a text log. Use basic regular expressions. Convert log files into CSV format. Adjust date and time to account for time bias and skew. List the primary tasks of log analysis. Describe the features of modern logging infrastructure. Describe features of data formats. Describe the types of information found in logs. General Topics: Process logs from Windows and Linux operating systems, firewalls, intrusion detection systems, and web and email servers Assemble evidence found in logs to assist in tasks ranging from building a case to recognizing an intrusion Instruction & Assessment Section 4 Content Section 4 Content Left Section 4 Content Right Instructional Strategies: Audio Visual Materials Coaching/Mentoring Computer Based Training Practical Exercises Methods of Assessment: Examinations Quizzes Supplemental Materials Section 5 Content Section 5 Content Left Section 5 Content Right Equivalencies Section 6 Content Section 6 Content Left Section 6 Content Right Button Content Rail Content 1 Other offerings from DC3 Cyber Training Academy View All Courses College Credit Opportunities> Page Content