Threat Hunting Training – JNUC Edition

threat_hunting_2

Jamf Nation Conference Edition!

This training is offered IN PERSON ONLY.

The Mitten Mac is proud to announce the first ever in person Threat Hunting Training course dedicated to macOS!

Whether you’re new to threat hunting or an experienced threat hunter this two day course will bring an in-depth and hands on experience to those looking to deep dive into using macOS internals to their advantage for threat hunting. Learn how to use the less commonly used artifacts to hunt down malicious activity in your environment.

This course uses simulated attack data collected with the Apple Endpoint Security Framework and teaches attendees how to connect the dots to determine what took place on the system.

Topics are discussed in presentation form and then applied via hands on labs. Among the different topics explored are

  • Exploring the process tree and understanding process creation
  • Understanding the complications of XPC
  • Tracing the steps of real malware samples and determining the scope of the attack
  • Hunting using the lesser explored pid values
  • Hunting using macOS and Unix specific technologies
  • …And much more
Attendees will walk away with a solid understanding of the system internals knowledge required for threat hunting on macOS as well as a new set of investigation skills.

Location : 

When :
  • Training Dates – September 26-27th, 2022
  • Jamf Nation Conference Dates – September 27th-29th
Price :
  • $1500
    Prerequisites
    • You have a laptop capable of searching keywords with-in large amounts of text data
    • You have a basic understanding of how to operate a Mac
    • You understand the general concept of how computers work and what a process is
    • You must be willing to miss the Tuesday afternoon speaker sessions of the JNUC conference (the non-keynote portion)
    • General understanding of one of the following topics 
      • threat hunting
      • forensics
      • incident response
      • computer science

    Sign up Instructions

    • Email jaron@themittenmac.com asking if any space is left in the class. Further questions can be sent to this same email address.