EACG Academy

EACG Academy

Die EACG Academy vermittelt praxisnahes Wissen rund um die Gestaltung und Absicherung digitaler Produkte: CRA und NIS2, DevSecOps, Scanning- Strategien sowie den Einsatz von TrustSource und SCANOSS.

Browsen Sie das aktuelle Kursangebot. Für Inhouse-Trainings und individuelle Formate sprechen Sie uns gerne direkt an.

Niveau
Preis
Themen

9 Kurse

Kostenlos

CRA Basics – What Manufacturers Need to Know Now

A concise introduction to the Cyber Resilience Act: what it means, who it affects, its four core obligations, and what the first step toward compliance looks like. No prior knowledge of EU product law required.

Beginner 55 min
cracompliancesecurityeacgbasics

Marcus Hale

Vorschau

Coordinated Vulnerability Disclosure – Professional Playbook

The professional playbook for CVD: assess vulnerabilities with CVSS, EPSS and SSVC, navigate difficult situations, and build your own CVD process and bug-bounty policy. With real-world stories from Heartbleed and Log4Shell. Prerequisite: none. It helps to have already taken the free EACG starter course "CVD Basics" first — this course assumes a working understanding of the topic and builds on it.

Advanced 2 hr 5 min
securitycvdvulnerability-disclosurepsirtbug-bountycvssepssssvccsafeacg

Tess Calder & Marcus Hale

Kostenlos

Coordinated Vulnerability Disclosure – Basics

A compact introduction to Coordinated Vulnerability Disclosure: what CVD is, why it exists, which roles are involved, and what finders and vendors must concretely do. Relevant for everyone subject to the Cyber Resilience Act or NIS2.

Beginner 42 min
securitycvdvulnerability-disclosureeacgcranis2

Marcus Hale & Tess Calder

Vorschau

EMB3D – Threat Analysis for Embedded Devices

The in-depth method and reference course on the MITRE EMB3D™ threat model: from the foundations (risk, threat, vulnerability) through all device properties, all 81 threats, and all mitigations with their tiers, to a complete worked analysis of an example device. Every lesson is self-contained and can be called up individually as a reference chapter. Note: This course is voiced by AI voices (AI narrated).

Beginner 9 hr 38 min
securitythreat-modelingemb3dembeddedeacgAI narrated

Marcus Hale & Tess Calder

Kostenlos

Understand and Manage TrustSource Legal Settings

Learn how TrustSource resolves open-source license obligations and how to configure the Legal Questionnaire for your projects and modules. Covers the solver mechanics, all questionnaire fields, practical workflow, and common edge cases.

Intermediate
trustsourceopen-source-compliancelegallicensing

CGM

Vorschau

MITRE ATT&CK®: Understanding Adversary Behavior

Attackers change their malware and infrastructure constantly, yet Process Injection has topped the list of most-observed techniques three years running. Chase the hashes and you are always a step behind the last attack; learn the behavior and you get ahead of the next one. This in-depth method and reference course on MITRE ATT&CK builds from the ground up (no threat-intelligence, SOC, or red-team background assumed) through the object model, the Enterprise matrix, real adversaries, detection and mitigation, the four use cases, and three worked cases: anticipating a live intruder, prioritizing vulnerabilities, and designing with ATT&CK. Every lesson is self-contained, so it doubles as a reference you return to. Note: This course is voiced by AI voices (AI narrated).

Beginner 4 hr 6 min
securitymitre-attackthreat-intelligencedetectioneacgAI narrated

Marcus Hale & Tess Calder

Kostenlos

Open Source Compliance – Basics

A foundation course on open source compliance: why it matters, the pillars of an open source program, change management, the OpenChain / ISO 5230 standard, open source boards and policies, and compliance tooling capabilities. Designed for developers, product owners, and anyone starting their compliance journey.

Beginner ~52 min
open-sourcecomplianceopenchainsbomgovernancetrustsource

Jan Thielscher

Vorschau

Threat Modeling – From Concept to Countermeasure

A hands-on course on threat modeling: why it pays off, what it is, how the process works, which methods exist (with a focus on STRIDE), a fully worked practical example, and the transition into risk management. Note: This course is voiced by AI voices (AI narrated).

Intermediate
securitythreat-modelingstrideeacgAI narrated

Marcus Hale & Tess Calder

Kostenlos

TrustSource: Vulnerability Management

A single unpatched Apache Struts vulnerability cost Equifax the data of 147 million people. This course is about never being the team that finds out about a CVE the hard way. You'll learn what TrustSource's scoring actually means, where its own tools surface a finding, and the full set of things you can do about one — from filing a ticket to publishing a formal advisory to handing a self-found zero-day into coordinated disclosure.

Intermediate 57 min
securityvulnerability-managementtrustsourcecvsscsafsast

Marcus Hale & Tess Calder

Interesse an einem Training?

Kontakt aufnehmen →