NOTE: There are two virtual images, first one that supports exercises 1-22 and second that supports Honeypot exercise. The .pcap file supports the exercise number 19. Additionally Internet Explorer renames files with .ova extension to .tar. You will need to change the extension back before loading it into virtualisation environment.
ENISA CERT training material contains 23 exercises:
| No. | Exercise title | Handbook | Toolset | Virtual Image | Other material supporting the exercise |
|---|---|---|---|---|---|
| 1 | Triage & basic incident handling | Online version of Exercise 1 | |||
| 2 | Incident handling procedure testing |
Online version of Exercise 2 |
|||
| 3 | Recruitment of CERT staff |
Online version of Exercise 3 |
|||
| 4 | Developing CERT infrastructure |
Online version of Exercise 4 |
|||
| 5 | Vulnerability handling |
Online version of Exercise 5 |
|||
| 6 | Writing security advisories |
Online version of Exercise 6 |
|||
| 7 | Network forensics |
Online version of Exercise 7 |
|||
| 8 | Establishing external contacts |
Online version of Exercise 8 |
|||
| 9 | Large scale incident handling |
Online version of Exercise 9 |
|||
| 10 | Automation in incident handling |
Online version of Exercise 10 |
|||
| 11 | Incident handling in live role playing |
Online version of Exercise 11 |
|||
| 12 | Cooperation with Law Enforcement agencies |
Online version of Exercise 12 |
|||
| 13 | Incident handling during an attack on Critical Information Infrastructure | ||||
| 14 | Proactive incident detection | ||||
| 15 | Cost of ICT incident |
Download MS Excel workbook, Download workbook in open format |
|||
| 16 | Mobile threats incident handling | ||||
| 17 | Incident handling in the cloud | ||||
| 18 | Advanced Persistent Threat incident handling | ||||
| 19 | CERT participation in incident handling related to the Article 13a obligations | Download data_ddos.pcap | |||
| 20 | CERT participation in incident handling related to the Article 4 obligations | ||||
| 21 | Assessing and Testing Communication Channels with CERTs and all their stakeholders | ||||
| 22 | Social networks used as an attack vector for targeted attacks | ||||
| 23 | Honeypots | ||||
Complete CERT exercises Handbook -> 
Exercise Handbook in German (Exercises 13-23)-> 
Exercise Handbook in Spanish (Exercises 1-12)-> 
Complete CERT exercises Toolset ->
Exercise Toolset in Spanish (Exercises 1-12) -> 
Field report on the CERT exercise pilot -> 




