Visão Geral
Este curso integra Digital Forensics e Incident Response para investigação completa de incidentes, desde aquisição e análise de evidências até contenção, erradicação, recuperação e documentação.
Conteúdo Programatico
Module 1: DFIR Fundamentals
- DFIR concepts
- Digital Forensics
- Incident Response
- DFIR lifecycle
- Investigation planning
- Evidence preservation
- Incident scoping
- Investigation methodology
- DFIR documentation
- DFIR operational workflow
Module 2: Evidence Acquisition
- Disk acquisition
- Memory acquisition
- Log acquisition
- Network evidence
- File acquisition
- Evidence hashing
- Evidence validation
- Chain of custody
- Acquisition documentation
- Evidence preservation
Module 3: Endpoint Forensics
- Windows artifacts
- Linux artifacts
- Event Logs
- Registry
- Processes
- Services
- Scheduled Tasks
- Browser artifacts
- File system artifacts
- Endpoint investigation
Module 4: Network Forensics
- Packet capture
- Network flows
- DNS
- HTTP
- HTTPS
- Command and Control
- Lateral Movement
- Data exfiltration
- Network timelines
- Network investigation
Module 5: Threat Investigation
- Initial Access
- Execution
- Persistence
- Credential Access
- Privilege Escalation
- Discovery
- Lateral Movement
- Command and Control
- Impact
- Attack reconstruction
Module 6: Incident Response
- Detection
- Triage
- Containment
- Evidence preservation
- Eradication
- Recovery
- Credential remediation
- System restoration
- Post-incident monitoring
- Response documentation
Module 7: Threat Hunting and Intelligence
- Threat hunting
- IOC analysis
- TTP analysis
- MITRE ATT&CK
- Threat intelligence
- Behavioral analysis
- Attack path analysis
- Hunt hypotheses
- Detection development
- Intelligence reporting
Module 8: Practical DFIR Investigation
- Incident triage
- Evidence acquisition
- Endpoint analysis
- Network analysis
- Timeline construction
- Attack reconstruction
- Containment
- Eradication
- Recovery
- DFIR case study