Curso Active Directory Attack & Defense

  • Redes & Infraestrutura de TI

Curso Active Directory Attack & Defense

32h
Visão Geral

Este curso aborda segurança ofensiva e defensiva aplicada ao Active Directory, apresentando os principais caminhos de ataque e os respectivos controles de prevenção, detecção e resposta.

Objetivo

Após realizar este curso, você será capaz de:

  • Analisar ataques contra Active Directory
  • Identificar caminhos de comprometimento
  • Implementar mecanismos de defesa
  • Detectar e responder a ataques
Publico Alvo
  • Profissionais de Cybersecurity
  • Red Team e Penetration Testers
  • SOC e Blue Team
  • Administradores de Active Directory
Pre-Requisitos
  • Conhecimentos de Active Directory
  • Familiaridade com Kerberos e NTLM
  • Conhecimentos de Windows Server
  • Noções de PowerShell
  • Conhecimentos básicos de segurança de redes
Conteúdo Programatico

Module 1: Active Directory Attack Surface

  1. Active Directory attack surface
  2. Identity infrastructure
  3. Domain Controller security
  4. Authentication attack surface
  5. Privileged accounts
  6. Service accounts
  7. Trust relationships
  8. Delegation risks
  9. Common attack paths
  10. Attack surface assessment

Module 2: Credential Access Attacks

  1. Credential Dumping
  2. LSASS credential exposure
  3. SAM database
  4. Cached credentials
  5. Kerberoasting
  6. AS-REP Roasting
  7. Pass-the-Hash
  8. Pass-the-Ticket
  9. DCSync
  10. Credential attack detection

Module 3: Privilege Escalation and Persistence

  1. Privilege escalation concepts
  2. Misconfigured permissions
  3. Privileged group abuse
  4. Group Policy abuse
  5. Service account abuse
  6. Kerberos-based persistence
  7. Golden Ticket
  8. Silver Ticket
  9. Persistence detection
  10. Persistence remediation

Module 4: Lateral Movement

  1. Lateral Movement concepts
  2. Remote administration
  3. SMB
  4. WinRM
  5. Remote Desktop
  6. Credential reuse
  7. Pass-the-Hash
  8. Pass-the-Ticket
  9. Lateral Movement detection
  10. Movement prevention

Module 5: Defensive Architecture

  1. Least privilege
  2. Administrative tiering
  3. Privileged Access Workstations
  4. LAPS
  5. Credential Guard
  6. Protected Users
  7. Authentication hardening
  8. Network segmentation
  9. Domain Controller protection
  10. Defense-in-depth architecture

Module 6: Detection Engineering

  1. Windows Event Logs
  2. Authentication monitoring
  3. Process monitoring
  4. Privileged activity
  5. Group membership changes
  6. Kerberos monitoring
  7. NTLM monitoring
  8. SIEM correlation
  9. MITRE ATT&CK mapping
  10. Detection rule development

Module 7: Incident Response

  1. Active Directory compromise indicators
  2. Account compromise
  3. Credential compromise
  4. Domain persistence investigation
  5. Lateral Movement investigation
  6. Domain Controller investigation
  7. Credential revocation
  8. Containment
  9. Recovery
  10. Post-incident analysis

Module 8: Attack and Defense Simulation

  1. Active Directory attack simulation
  2. Credential attack detection
  3. Privilege escalation investigation
  4. Lateral Movement investigation
  5. Persistence investigation
  6. Defensive control implementation
  7. SIEM investigation
  8. Incident response workflow
  9. Security validation
  10. Attack and defense case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas