Visão Geral
Este curso apresenta os principais conceitos e técnicas de Lateral Movement em ambientes Windows e Active Directory. O participante compreenderá como adversários podem se deslocar entre sistemas após um comprometimento inicial, além de estudar protocolos, indicadores, telemetria, threat hunting e controles destinados a limitar a movimentação lateral.
Conteúdo Programatico
Module 1: Lateral Movement Fundamentals
- Lateral Movement concepts
- Post-compromise activity
- Internal reconnaissance
- Credential-based movement
- Remote authentication
- Trust relationships
- Privileged access
- Attack paths
- Movement objectives
- Lateral Movement lifecycle
Module 2: Windows Remote Services
- SMB
- Windows Remote Management
- Remote Desktop Protocol
- Windows Management Instrumentation
- Remote Service execution concepts
- Administrative shares
- Remote administration protocols
- Service-based movement
- Remote authentication
- Remote service security
Module 3: Credential-Based Lateral Movement
- Credential reuse
- Pass-the-Hash
- Pass-the-Ticket
- Kerberos authentication
- NTLM authentication
- Credential exposure
- Privileged credentials
- Service accounts
- Authentication material
- Credential protection
Module 4: Active Directory Attack Paths
- Domain relationships
- Privileged groups
- Delegated permissions
- Nested group memberships
- Service accounts
- Kerberos delegation
- Trust relationships
- Attack path analysis
- Privilege escalation relationships
- Domain compromise pathways
Module 5: Lateral Movement Detection
- Authentication monitoring
- Remote logon events
- Process creation monitoring
- Remote service activity
- SMB activity
- RDP activity
- PowerShell activity
- Windows Event Logs
- Endpoint telemetry
- SIEM correlation
Module 6: Threat Hunting
- Lateral Movement hunting
- Authentication baselining
- Host-to-host communication
- Privileged account behavior
- Remote service hunting
- Suspicious administrative activity
- Credential abuse indicators
- Attack chain reconstruction
- Hunt hypothesis development
- Hunt validation
Module 7: Prevention and Hardening
- Network segmentation
- Administrative tiering
- Privileged Access Management
- Least privilege
- Credential Guard
- Local Administrator Password Solution
- Remote service restrictions
- RDP security
- SMB security
- Lateral Movement attack surface reduction
Module 8: Incident Response and Practical Analysis
- Lateral Movement incident identification
- Source and destination analysis
- Authentication timeline reconstruction
- Compromised account investigation
- Host compromise assessment
- Attack path reconstruction
- Containment strategies
- Credential rotation
- Persistence assessment
- Practical Lateral Movement investigation cases