Visão Geral
Este curso aprofunda técnicas de investigação e resposta a incidentes complexos, incluindo ataques avançados, comprometimento de identidades, persistência, movimentação lateral e investigação de ameaças.
Conteúdo Programatico
Module 1: Advanced Incident Response
- Advanced incident response methodology
- Complex incident scenarios
- Multi-stage attacks
- Advanced threat actors
- Incident scoping
- Investigation prioritization
- Response coordination
- Advanced evidence sources
- Incident command
- Advanced response planning
Module 2: Advanced Threat Investigation
- Attack chain reconstruction
- Timeline analysis
- Threat actor behavior
- Initial Access analysis
- Persistence analysis
- Credential Access
- Privilege Escalation
- Lateral Movement
- Command and Control
- Impact assessment
Module 3: Advanced Identity Investigation
- Identity compromise
- Credential theft
- Kerberos investigation
- NTLM investigation
- Privileged account abuse
- Active Directory compromise
- DCSync indicators
- Golden Ticket investigation
- Authentication timeline
- Identity remediation
Module 4: Endpoint Investigation
- Endpoint telemetry
- Process analysis
- PowerShell investigation
- Persistence mechanisms
- Malware analysis
- EDR investigation
- Memory analysis concepts
- File system investigation
- Registry analysis
- Endpoint compromise assessment
Module 5: Network Investigation
- Network attack analysis
- DNS investigation
- HTTP and HTTPS traffic
- Network connections
- Command and Control
- Lateral Movement
- Network anomalies
- Traffic correlation
- Network containment
- Network evidence analysis
Module 6: Advanced Containment and Eradication
- Enterprise containment
- Identity containment
- Network containment
- Endpoint containment
- Credential revocation
- Persistence eradication
- Threat actor removal
- Security control reinforcement
- Eradication validation
- Recovery planning
Module 7: Threat Intelligence and Attribution
- Threat intelligence
- Threat actor profiling
- Campaign analysis
- IOC enrichment
- TTP analysis
- MITRE ATT&CK
- Intelligence correlation
- Attribution limitations
- Intelligence reporting
- Threat intelligence integration
Module 8: Advanced Incident Simulation
- Complex incident scenario
- Initial triage
- Evidence collection
- Attack reconstruction
- Threat hunting
- Containment
- Eradication
- Recovery
- Executive reporting
- Advanced incident response case study