IT Defense 2027 > Trainings > Lessons From the Field:
en de

Lessons From the Field:

Lessons From the Field: What to Do When You’re Under Attack (and Afterwards)


Instructor: Paula Januszkiewicz

Duration: 2 days – January 25-26, 2027

This is a deep-dive workshop on modern infrastructure security – on premises and in the cloud. During this workshop, we will learn how to identify the areas of vulnerability and manage them. Later, we will review and see in action the most sophisticated attacks on the systems and identity solutions that are used by modern adversaries targeting valuable data and resources. We will also learn how modern malware works and what the ways are to discover its operations. Additionally, we will cover the best practices for detecting and managing incidents: we will learn crucial steps in how to discover that the machine is under attack or that the whole system has been compromised.

At the end, we will look at different strategies and techniques for implementing endpoint security, including various approaches to securing the communication channel, and determine what modern organizations can do to boost their resilience against supply chain attacks.

After completing this course, you will know how to:

  • Analyze emerging trends in attack techniques
  • Identify areas of vulnerability within your organization
  • Prepare a risk assessment for your organization
  • Report and recommend countermeasures
  • Develop a cybersecurity crisis management plan for your organization

Module 1: Identifying Areas of Vulnerability
This part introduces new cybersecurity challenges and trends, putting an emphasis on data security and integration through and into the cloud, and the challenges of the coordination of the cloud and on-premises security solutions. Security is a business enabler, and it is only when it is viewed from a business perspective that we can truly make the right decisions. You will learn how to define valuable assets and resources of your company that need to be protected or restricted. We’ll teach you how to find the obvious and the not-so-obvious sensitive information that can be monetized by adversaries. Having that scope defined and knowing your resources will allow you to understand where the biggest gaps in your security posture are and what can be done to seal them.

  1. Defining the assets that your company needs to protect
  2. Defining other sensitive information that needs to be protected
  3. Managing vulnerabilities and developing a cybersecurity crisis management plan for your organization

Module 2: Overview of Modern Attack Techniques
In this world, where most of the things happen online, hacking provides wider opportunities for attackers to gain unauthorized access to classified information like credit card details, email account details and other personal information. So, it is also important to know some of the hacking techniques that are commonly used to get your personal information in an unauthorized way. In this module, you will become familiar with the modern hacking techniques.

  1. OS platform threats and attacks
  2. Email threats and attacks
  3. Physical access threats and attacks
  4. Social threats and attacks
  5. Network threats and attacks

Module 3: Identity Attacks
There are many methods widely in use today to steal personal information. These attacks on confidential data can be extremely high-tech, involving the latest technologies and the most recent security exploits. Many of the attack methods, however, are very low-tech, involving little or no technology at all. By taking a detailed look at various types of attacks, you will become familiar with the techniques used by cybercriminals today.

  1. Performing the identity attacks
  2. Cached logons (credentials)
  3. Data Protection API (DPAPI) for user’s secrets protection
  4. Performing the LSA secrets dump and implementing prevention
  5. Active Directory and Azure AD security
  6. Bypassing multi-factor authentication
  7. Detecting the most common attacks: DNS reconnaissance
  8. Directory service enumeration
  9. Enumerating high-privileged accounts
  10. SMB session enumeration
  11. Pass the ticket and its variants
  12. Compromise KRBTGT account
  13. Golden Ticket

Module 4: Techniques Used by Malicious Software
Modern adversaries will often aim to infect their victim’s systems with custom malware that may be delivered in a variety of ways. Common attacks may include phishing campaigns, planting malicious software imitating real programs so the users download and install them themselves, or through compromising the supply chain and smuggling in malicious codes to the software used in the organization through updates. This way, after installing the malicious program, the hacker gets unprivileged access. Techniques are becoming more sophisticated than ever. In this module, you will learn how modern malware works and what techniques hackers use to cover their tracks.

  1. Types of attacks
  2. Supply chain attacks
  3. Points of entry
  4. Persistence methods & hiding traces

Module 5: Cloud and Hybrid Environment Security
In this section, we will review the most important features offered by cloud security solutions that can boost your organization’s resilience against modern adversaries and emerging cybersecurity threats. We will cover implementation of identity management solutions and showcase the power of the cloud for effective monitoring, detection and response.

  1. Effective identity management and information protection in the cloud
    1. MFA & SSO
    1. Conditional Access
    1. Data loss prevention (DLP)
  2. Secure endpoint management
    1. Modern XDR solutions
    1. Attack surface reduction rules
    1. Endpoint detection and response, investigation and remediation
  3. The power of logs – security monitoring
    1. Why is monitoring so important?
    1. Monitoring challenges – the most important issues to solve
    1. Modern security information and event management solutions for effective monitoring

Module 6: Incident Response Considerations
No matter what security solutions and measures are implemented, organizations should strive towards building and maintaining an effective cybersecurity crisis management plan. In this module, we will cover some of the best practices that organizations should consider while developing their policies and emergency procedures.

  1. Incident response and handling steps
  2. Incident responders & supporting team composition and skills
  3. Communications and securing monitoring operations
  4. Incident containment, eradication and recovery
  5. Post-incident analysis

Prerequisites:
To attend this training, you should have a good, hands-on experience in administering Windows infrastructure. At least 5 years in the field is recommended.

Target audience:
Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.

This training will be held in English.

Price: 2,000 €

Date: January 25-26, 2027

Location
Scandic Frankfurt Hafenpark
Eytelweinstraße 1
Frankfurt am Main
Phone: +49 69 219 777 0
Email: hafenpark@scandichotels.com
www.scandichotels.com/en/hotels/scandic-frankfurt-hafenpark