-
Analyze adversary behavior using incident response and attack frameworks
Assessment Strategies
Scenario Response and/or Test
Criteria
Classify observed activity within an incident response lifecycle
Map observed adversary behavior to applicable MITRE ATT&CK tactics and techniques
Differentiate normal, suspicious, and malicious activity using available context
Prioritize investigative actions based on incident scope and business impact
-
Analyze network traffic for indicators of compromise
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Filter packet and session data to isolate relevant traffic
Interpret protocol behavior to distinguish expected from anomalous activity
Identify network indicators associated with command and control, lateral movement, or exfiltration
Support conclusions with packet, flow, or alert evidence
-
Analyze endpoint and system log evidence
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Query Windows and endpoint telemetry for events relevant to an investigation
Interpret authentication, process, file, registry, and network activity
Correlate related events using timestamps, hosts, users, process identifiers, or other fields
Distinguish benign administrative activity from evidence of compromise
-
Correlate evidence across network and endpoint data sources
Assessment Strategies
Case Study and/or Report
Criteria
Combine network, host, and security monitoring evidence into a coherent sequence of events
Resolve differences in timestamps, identifiers, and data fields across sources
Validate significant findings using more than one evidence source when available
Identify evidence gaps and limit conclusions to findings supported by available data
-
Develop detection logic for suspicious activity
Assessment Strategies
Skill Demonstration and/or Project
Criteria
Construct filters, queries, or detection rules that match defined suspicious behavior
Test detection logic against representative network or log data
Refine detection logic to reduce irrelevant matches while preserving useful detection
Document the behavior and evidence the detection is intended to identify
-
Investigate the scope and root cause of a cybersecurity incident
Assessment Strategies
Case Study and/or Report
Criteria
Identify the likely initial access or triggering event from available evidence
Determine affected hosts, accounts, services, or data within the available evidence
Trace lateral movement, persistence, command and control, or exfiltration when present
Distinguish confirmed findings from hypotheses and unresolved questions
Summarize the probable root cause and progression of the incident
-
Apply containment, eradication, and recovery strategies
Assessment Strategies
Scenario Response and/or Written Product
Criteria
Select containment actions appropriate to the observed threat and business context
Recommend eradication actions that address identified persistence or access mechanisms
Recommend recovery actions that restore operations while reducing reinfection risk
Explain operational risks and tradeoffs associated with proposed response actions
-
Evaluate endpoint security controls for incident prevention and response
Assessment Strategies
Skill Demonstration and/or Written Product
Criteria
Configure or assess endpoint controls that restrict unauthorized activity
Verify control behavior using system or security event evidence
Relate endpoint controls to least privilege, explicit trust, or other defensive principles
Recommend improvements based on observed control limitations or gaps
-
Evaluate monitoring and response practices against organizational requirements
Assessment Strategies
Case Study and/or Written Product
Criteria
Identify monitoring evidence needed to support defined security requirements
Assess whether available logs and telemetry provide adequate visibility
Relate incident response practices to applicable compliance or security framework expectations
Recommend improvements to logging, monitoring, retention, or response procedures
-
Produce professional incident response documentation
Assessment Strategies
Report and/or Presentation
Criteria
Summarize the incident for a non-technical or management audience
Document the incident scope, evidence, timeline, and significant indicators of compromise
Support technical conclusions with relevant and readable evidence
Recommend remediation and follow-up actions based on investigation findings
Cite external technical sources when they materially support investigative conclusions