Company Structure, Roles, and Pipeline Flashcards
What are the 6 (a3’s) supporting the business and their roles?
FS (Y-15) : Infrastructure, automation, tickets, troubleshooting, and network reliability
AT-PG : Red team that works with open source tooling
ET-PG : Enterprise Group that focus on main actors; total of 6 sections. 1 for telecom, 1 target agnostic, 4 for target groups
*Target agnostic helps other groups when struggling
PT-PG: Go after bad person themselves or bad types such as (stealing, human traffic, small devices, laptops)
- Majority have a lot of Endpoint expertise
JC-PG: Coordinates with C directory (old team); “Hack the Hackers”
ORC: Training and credentialing team ensuring technical workforce are compliant
What is the class pipeline for EAs?
Four classes
- First two are basics
- Class 3 is cyber basics
- Class 4 is the longest but most important (learning the internal goods)
What are the EA tiers (lowest to highest)? (5 total w/ explanation)
Very similar to my pipeline I went through
EAT = Trainee
CEA = Core; passed all classes and have sat in on 4 ops
AEA = Apprentice; you can do the work with supervision w/ 10 successful ops
JEA = Journeyman; you run the show and can conduct ops by yourself with minimal supervision
MEA = Master EA; Similar to journeyman but you focus on training and support (add value back) to more junior workforce
What is an EA job responsibilities? (4)
1) Operate under correct authorities (702, FISA, etc..)
2) Accountable for actions ; Every OP must follow specific reqs
- Clearance lvl
- Permissions
- Health and Safety
3) Network Accountable
- dont get caught
4) Responsible for the entire OP
- All prep work / ducks in a row {networks ready, room reserved, commands ready, notes,etc.}
What the core tools for an EA (5)
Ops dashboard - where all plans and technical information live (solid overview of OP)
RBF - CI/pipeline handling of system commands, schedulers, and pipelines
EMU/ELK - Personnel page that details skills sets of individuals
TP - PTPG uses this to find bad people
XKEY -
Name the 3 types of EAs
TDNA
- Leverage collected SIGINT gain target or additional target information (gap fill)
- Support Reports/Revisions
- Works with stored information
DNEA
- Review stored information to look for additional holes or areas of interest (ports, protocols, OSI layers)
- Develop new tradecraft
- Assist in developing Op plans
EAS
- Develop Ops plans
- Construct out in-depth plans (lower level on devices)
- {Echo Responsibilities}