Incident Analysis: Command and Control
In this hands-on lab, you will learn how to analyze common command and control mechanisms during an incident response engagement.

Course Content
Upon completing this lab, you should be able to:
- List and describe selected common methods of Command and Control associated with Windows environments.
- Develop and test hypotheses relevant to Command and Control observations.
- Describe how generic analytical methods can be applied to the examination of Command and Control activity.
- Examine example evidence of the Command and Control techniques T1573.002 Encrypted Channel / Asymmetric Cryptography and T1571 Non-Standard Port.
- Document different Command and Control findings.













