Visão Geral
Este curso apresenta os Windows Event Logs como fonte essencial de telemetria para administração, segurança, investigação e resposta a incidentes. O participante aprenderá a compreender os principais logs, identificar eventos relevantes, realizar correlação e utilizar os registros em atividades de threat hunting e troubleshooting.
Conteúdo Programatico
Module 1: Windows Event Log Fundamentals
- Windows Event Log architecture
- Event channels
- Event providers
- Event IDs
- Event levels
- Event sources
- Event metadata
- Event timestamps
- Log retention
- Event Log management
Module 2: Security Event Logs
- Security event log
- Authentication events
- Account management events
- Privileged activity
- Process creation events
- Policy changes
- Object access
- Service activity
- System events
- Security event interpretation
Module 3: Active Directory Event Logs
- Domain Controller events
- Kerberos authentication events
- NTLM authentication events
- Account changes
- Group membership changes
- Directory service events
- Replication events
- Group Policy events
- Privileged activity
- Active Directory event analysis
Module 4: Event Log Analysis
- Event filtering
- Event correlation
- Timeline analysis
- Source and destination analysis
- User activity analysis
- Process activity analysis
- Authentication analysis
- Suspicious event identification
- Baseline comparison
- Investigation methodology
Module 5: Event Logs for Threat Detection
- Credential Access indicators
- Privilege Escalation indicators
- Lateral Movement indicators
- Persistence indicators
- Defense Evasion indicators
- Account compromise indicators
- Suspicious PowerShell activity
- Remote authentication monitoring
- Detection engineering
- Threat hunting
Module 6: Event Collection and SIEM
- Centralized event collection
- Windows Event Forwarding
- Log aggregation
- SIEM integration
- Event normalization
- Log parsing
- Correlation rules
- Alert generation
- Log retention strategies
- Security monitoring architecture
Module 7: Troubleshooting with Event Logs
- Authentication troubleshooting
- Group Policy troubleshooting
- Service failures
- Application errors
- Network-related events
- Domain Controller troubleshooting
- Replication troubleshooting
- Security configuration issues
- Event-based diagnostics
- Troubleshooting methodology
Module 8: Practical Event Log Investigation
- Security event investigation
- Authentication timeline reconstruction
- Privileged activity investigation
- Suspicious process analysis
- Lateral Movement investigation
- Active Directory event analysis
- SIEM correlation exercise
- Threat hunting exercise
- Incident response workflow
- Practical Windows Event Log cases