Visão Geral
Este curso apresenta os fundamentos da defesa cibernética, abordando arquitetura defensiva, monitoramento, hardening, detecção, threat hunting e resposta a incidentes.
Conteúdo Programatico
Module 1: Blue Team Fundamentals
- Blue Team concepts
- Defensive security
- Defense-in-depth
- Security controls
- Attack surface reduction
- Security architecture
- Security monitoring
- Threat detection
- Incident response
- Blue Team operations
Module 2: Endpoint Security
- Endpoint security
- Windows security
- Linux security
- EDR concepts
- Antivirus
- Application control
- Endpoint telemetry
- Host hardening
- Endpoint monitoring
- Endpoint incident response
Module 3: Network Defense
- Network security architecture
- Firewalls
- IDS and IPS
- Network segmentation
- Network monitoring
- Secure protocols
- Traffic analysis
- Network-based detection
- Network hardening
- Network defense strategy
Module 4: Identity Defense
- Identity security
- Authentication
- Authorization
- Active Directory security
- Privileged accounts
- Credential protection
- MFA
- Identity monitoring
- Identity threat detection
- Identity hardening
Module 5: Security Monitoring
- Log collection
- Windows Event Logs
- Linux logs
- Network telemetry
- Endpoint telemetry
- SIEM
- Security alerts
- Event correlation
- Detection rules
- Monitoring strategy
Module 6: Threat Detection
- Detection engineering
- Indicators of compromise
- Behavioral detection
- MITRE ATT&CK
- Malware detection
- Credential attack detection
- Lateral Movement detection
- Persistence detection
- Threat intelligence integration
- Detection validation
Module 7: Incident Response
- Incident response lifecycle
- Detection and triage
- Containment
- Eradication
- Recovery
- Evidence collection
- Incident documentation
- Communication
- Lessons learned
- Incident response improvement
Module 8: Practical Blue Team Operations
- Security monitoring exercise
- Alert investigation
- Endpoint investigation
- Network investigation
- Identity investigation
- Threat detection exercise
- Incident response simulation
- Security control validation
- Defensive reporting
- Blue Team case studies