{"id":305,"date":"2026-07-14T11:28:40","date_gmt":"2026-07-14T09:28:40","guid":{"rendered":"https:\/\/it-defense.hostpress.me\/it-defense-2027\/?page_id=305"},"modified":"2026-07-22T12:28:22","modified_gmt":"2026-07-22T10:28:22","slug":"lessons-from-the-field","status":"publish","type":"page","link":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/","title":{"rendered":"Lessons From the Field:"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><strong>Lessons From the Field: What to Do When You\u2019re Under Attack (and Afterwards)<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><br><strong>Instructor:\u00a0<\/strong><a href=\"\/it-defense-2027\/en\/presentators\/paula-januszkiewicz\/\" data-type=\"link\" data-id=\"\/it-defense-2027\/en\/referenten\/paula-januszkiewicz\/\">Paula Januszkiewicz<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Duration:&nbsp;<\/strong>2 days \u2013 January 25-26, 2027<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is a deep-dive workshop on modern infrastructure security \u2013 on premises and in the cloud. During this workshop, we will learn how to identify the areas of vulnerability and manage them. Later, we will review and see in action the most sophisticated attacks on the systems and identity solutions that are used by modern adversaries targeting valuable data and resources. We will also learn how modern malware works and what the ways are to discover its operations. Additionally, we will cover the best practices for detecting and managing incidents: we will learn crucial steps in how to discover that the machine is under attack or that the whole system has been compromised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the end, we will look at different strategies and techniques for implementing endpoint security, including various approaches to securing the communication channel, and determine what modern organizations can do to boost their resilience against supply chain attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After completing this course, you will know how to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Analyze emerging trends in attack techniques<\/li>\n\n\n\n<li>Identify areas of vulnerability within your organization<\/li>\n\n\n\n<li>Prepare a risk assessment for your organization<\/li>\n\n\n\n<li>Report and recommend countermeasures<\/li>\n\n\n\n<li>Develop a cybersecurity crisis management plan for your organization<br><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Module 1: Identifying Areas of Vulnerability<\/strong><br>This part introduces new cybersecurity challenges and trends, putting an emphasis on data security and integration through and into the cloud, and the challenges of the coordination of the cloud and on-premises security solutions. Security is a business enabler, and it is only when it is viewed from a business perspective that we can truly make the right decisions. You will learn how to define valuable assets and resources of your company that need to be protected or restricted. We\u2019ll teach you how to find the obvious and the not-so-obvious sensitive information that can be monetized by adversaries. Having that scope defined and knowing your resources will allow you to understand where the biggest gaps in your security posture are and what can be done to seal them.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Defining the assets that your company needs to protect<\/li>\n\n\n\n<li>Defining other sensitive information that needs to be protected<\/li>\n\n\n\n<li>Managing vulnerabilities and developing a cybersecurity crisis management plan for your organization<br><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Module 2: Overview of Modern Attack Techniques<\/strong><br>In this world, where most of the things happen online, hacking provides wider opportunities for attackers to gain unauthorized access to classified information like credit card details, email account details and other personal information. So, it is also important to know some of the hacking techniques that are commonly used to get your personal information in an unauthorized way. In this module, you will become familiar with the modern hacking techniques.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>OS platform threats and attacks<\/li>\n\n\n\n<li>Email threats and attacks<\/li>\n\n\n\n<li>Physical access threats and attacks<\/li>\n\n\n\n<li>Social threats and attacks<\/li>\n\n\n\n<li>Network threats and attacks<br><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Module 3: Identity Attacks<\/strong><br>There are many methods widely in use today to steal personal information. These attacks on confidential data can be extremely high-tech, involving the latest technologies and the most recent security exploits. Many of the attack methods, however, are very low-tech, involving little or no technology at all. By taking a detailed look at various types of attacks, you will become familiar with the techniques used by cybercriminals today.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Performing the identity attacks<\/li>\n\n\n\n<li>Cached logons (credentials)<\/li>\n\n\n\n<li>Data Protection API (DPAPI) for user\u2019s secrets protection<\/li>\n\n\n\n<li>Performing the LSA secrets dump and implementing prevention<\/li>\n\n\n\n<li>Active Directory and Azure AD security<\/li>\n\n\n\n<li>Bypassing multi-factor authentication<\/li>\n\n\n\n<li>Detecting the most common attacks: DNS reconnaissance<\/li>\n\n\n\n<li>Directory service enumeration<\/li>\n\n\n\n<li>Enumerating high-privileged accounts<\/li>\n\n\n\n<li>SMB session enumeration<\/li>\n\n\n\n<li>Pass the ticket and its variants<\/li>\n\n\n\n<li>Compromise KRBTGT account<\/li>\n\n\n\n<li>Golden Ticket<br><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Module 4: Techniques Used by Malicious Software<\/strong><br>Modern adversaries will often aim to infect their victim\u2019s systems with custom malware that may be delivered in a variety of ways. Common attacks may include phishing campaigns, planting malicious software imitating real programs so the users download and install them themselves, or through compromising the supply chain and smuggling in malicious codes to the software used in the organization through updates. This way, after installing the malicious program, the hacker gets unprivileged access. Techniques are becoming more sophisticated than ever. In this module, you will learn how modern malware works and what techniques hackers use to cover their tracks.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Types of attacks<\/li>\n\n\n\n<li>Supply chain attacks<\/li>\n\n\n\n<li>Points of entry<\/li>\n\n\n\n<li>Persistence methods &amp; hiding traces<br><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Module 5: Cloud and Hybrid Environment Security<\/strong><br>In this section, we will review the most important features offered by cloud security solutions that can boost your organization\u2019s resilience against modern adversaries and emerging cybersecurity threats. We will cover implementation of identity management solutions and showcase the power of the cloud for effective monitoring, detection and response.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Effective identity management and information protection in the cloud<ol><li>MFA &amp; SSO<\/li><\/ol><ol><li>Conditional Access<\/li><\/ol>\n<ol class=\"wp-block-list\">\n<li>Data loss prevention (DLP)<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>Secure endpoint management<ol><li>Modern XDR solutions<\/li><\/ol><ol><li>Attack surface reduction rules<\/li><\/ol>\n<ol class=\"wp-block-list\">\n<li>Endpoint detection and response, investigation and remediation<\/li>\n<\/ol>\n<\/li>\n\n\n\n<li>The power of logs \u2013 security monitoring<ol><li>Why is monitoring so important?<\/li><\/ol><ol><li>Monitoring challenges \u2013 the most important issues to solve<\/li><\/ol>\n<ol class=\"wp-block-list\">\n<li>Modern security information and event management solutions for effective monitoring<br><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Module 6: Incident Response Considerations<\/strong><br>No matter what security solutions and measures are implemented, organizations should strive towards building and maintaining an effective cybersecurity crisis management plan. In this module, we will cover some of the best practices that organizations should consider while developing their policies and emergency procedures.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Incident response and handling steps<\/li>\n\n\n\n<li>Incident responders &amp; supporting team composition and skills<\/li>\n\n\n\n<li>Communications and securing monitoring operations<\/li>\n\n\n\n<li>Incident containment, eradication and recovery<\/li>\n\n\n\n<li>Post-incident analysis<br><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Prerequisites:<\/strong><br>To attend this training, you should have a good, hands-on experience in administering Windows infrastructure. At least 5 years in the field is recommended.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Target audience:<\/strong><br>Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This training will be held in English.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Price:<\/strong>&nbsp;2,000 \u20ac<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Date: <\/strong>January 25-26, 2027<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Location<\/strong><br>Scandic Frankfurt Hafenpark<br>Eytelweinstra\u00dfe 1<br>Frankfurt am Main<br>Phone: +49 69 219 777 0<br>Email: hafenpark@scandichotels.com<br>www.scandichotels.com\/en\/hotels\/scandic-frankfurt-hafenpark<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lessons From the Field: What to Do When You\u2019re Under Attack (and Afterwards) Instructor:\u00a0Paula Januszkiewicz Duration:&nbsp;2 days \u2013 January 25-26, 2027 This is a deep-dive workshop on modern infrastructure security \u2013 on premises and in the cloud. During this workshop, we will learn how to identify the areas of vulnerability and manage them. Later, we [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"parent":97,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-305","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Lessons From the Field: - IT Defense 2027<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Lessons From the Field: - IT Defense 2027\" \/>\n<meta property=\"og:description\" content=\"Lessons From the Field: What to Do When You\u2019re Under Attack (and Afterwards) Instructor:\u00a0Paula Januszkiewicz Duration:&nbsp;2 days \u2013 January 25-26, 2027 This is a deep-dive workshop on modern infrastructure security \u2013 on premises and in the cloud. During this workshop, we will learn how to identify the areas of vulnerability and manage them. Later, we [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/\" \/>\n<meta property=\"og:site_name\" content=\"IT Defense 2027\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-22T10:28:22+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/trainings\\\/lessons-from-the-field\\\/\",\"url\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/trainings\\\/lessons-from-the-field\\\/\",\"name\":\"Lessons From the Field: - IT Defense 2027\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/#website\"},\"datePublished\":\"2026-07-14T09:28:40+00:00\",\"dateModified\":\"2026-07-22T10:28:22+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/trainings\\\/lessons-from-the-field\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/trainings\\\/lessons-from-the-field\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/trainings\\\/lessons-from-the-field\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Start\",\"item\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trainings\",\"item\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/en\\\/trainings\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Lessons From the Field:\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/#website\",\"url\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/\",\"name\":\"IT Defense 2027\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/it-defense.de\\\/it-defense-2027\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Lessons From the Field: - IT Defense 2027","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/","og_locale":"en_US","og_type":"article","og_title":"Lessons From the Field: - IT Defense 2027","og_description":"Lessons From the Field: What to Do When You\u2019re Under Attack (and Afterwards) Instructor:\u00a0Paula Januszkiewicz Duration:&nbsp;2 days \u2013 January 25-26, 2027 This is a deep-dive workshop on modern infrastructure security \u2013 on premises and in the cloud. During this workshop, we will learn how to identify the areas of vulnerability and manage them. Later, we [&hellip;]","og_url":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/","og_site_name":"IT Defense 2027","article_modified_time":"2026-07-22T10:28:22+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/","url":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/","name":"Lessons From the Field: - IT Defense 2027","isPartOf":{"@id":"https:\/\/it-defense.de\/it-defense-2027\/#website"},"datePublished":"2026-07-14T09:28:40+00:00","dateModified":"2026-07-22T10:28:22+00:00","breadcrumb":{"@id":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/lessons-from-the-field\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Start","item":"https:\/\/it-defense.de\/it-defense-2027\/"},{"@type":"ListItem","position":2,"name":"Trainings","item":"https:\/\/it-defense.de\/it-defense-2027\/en\/trainings\/"},{"@type":"ListItem","position":3,"name":"Lessons From the Field:"}]},{"@type":"WebSite","@id":"https:\/\/it-defense.de\/it-defense-2027\/#website","url":"https:\/\/it-defense.de\/it-defense-2027\/","name":"IT Defense 2027","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/it-defense.de\/it-defense-2027\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/comments?post=305"}],"version-history":[{"count":6,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/305\/revisions"}],"predecessor-version":[{"id":319,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/305\/revisions\/319"}],"up":[{"embeddable":true,"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/pages\/97"}],"wp:attachment":[{"href":"https:\/\/it-defense.de\/it-defense-2027\/en\/wp-json\/wp\/v2\/media?parent=305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}