Visão Geral
Este curso aborda segurança ofensiva e defensiva aplicada ao Active Directory, apresentando os principais caminhos de ataque e os respectivos controles de prevenção, detecção e resposta.
Conteúdo Programatico
Module 1: Active Directory Attack Surface
- Active Directory attack surface
- Identity infrastructure
- Domain Controller security
- Authentication attack surface
- Privileged accounts
- Service accounts
- Trust relationships
- Delegation risks
- Common attack paths
- Attack surface assessment
Module 2: Credential Access Attacks
- Credential Dumping
- LSASS credential exposure
- SAM database
- Cached credentials
- Kerberoasting
- AS-REP Roasting
- Pass-the-Hash
- Pass-the-Ticket
- DCSync
- Credential attack detection
Module 3: Privilege Escalation and Persistence
- Privilege escalation concepts
- Misconfigured permissions
- Privileged group abuse
- Group Policy abuse
- Service account abuse
- Kerberos-based persistence
- Golden Ticket
- Silver Ticket
- Persistence detection
- Persistence remediation
Module 4: Lateral Movement
- Lateral Movement concepts
- Remote administration
- SMB
- WinRM
- Remote Desktop
- Credential reuse
- Pass-the-Hash
- Pass-the-Ticket
- Lateral Movement detection
- Movement prevention
Module 5: Defensive Architecture
- Least privilege
- Administrative tiering
- Privileged Access Workstations
- LAPS
- Credential Guard
- Protected Users
- Authentication hardening
- Network segmentation
- Domain Controller protection
- Defense-in-depth architecture
Module 6: Detection Engineering
- Windows Event Logs
- Authentication monitoring
- Process monitoring
- Privileged activity
- Group membership changes
- Kerberos monitoring
- NTLM monitoring
- SIEM correlation
- MITRE ATT&CK mapping
- Detection rule development
Module 7: Incident Response
- Active Directory compromise indicators
- Account compromise
- Credential compromise
- Domain persistence investigation
- Lateral Movement investigation
- Domain Controller investigation
- Credential revocation
- Containment
- Recovery
- Post-incident analysis
Module 8: Attack and Defense Simulation
- Active Directory attack simulation
- Credential attack detection
- Privilege escalation investigation
- Lateral Movement investigation
- Persistence investigation
- Defensive control implementation
- SIEM investigation
- Incident response workflow
- Security validation
- Attack and defense case studies