Visão Geral
Este curso apresenta o funcionamento do Pass-the-Hash (PtH), técnica associada ao abuso de autenticação NTLM mediante reutilização de material de autenticação. O curso enfatiza os fundamentos técnicos, identificação de indicadores, investigação, prevenção e mitigação em ambientes Windows e Active Directory.
Conteúdo Programatico
Module 1: NTLM Authentication Fundamentals
- NTLM authentication architecture
- Challenge-response authentication
- NTLM authentication flow
- Password and hash concepts
- Authentication material
- Local authentication
- Domain authentication
- NTLM session security
- NTLM security limitations
- Credential protection mechanisms
Module 2: Pass-the-Hash Fundamentals
- Pass-the-Hash attack concepts
- Credential material reuse
- Authentication without plaintext passwords
- Relationship between NTLM hashes and authentication
- Local versus domain credential abuse
- Attack prerequisites
- Privileged account exposure
- Lateral movement concepts
- Attack objectives
- Security implications
Module 3: Credential Exposure and Attack Surface
- Credential exposure scenarios
- Local administrator credentials
- Domain administrator credentials
- Shared administrative credentials
- Credential reuse across endpoints
- Privileged account risks
- Credential isolation
- Administrative workstation security
- Credential theft indicators
- Attack surface reduction
Module 4: Pass-the-Hash and Lateral Movement
- Lateral movement fundamentals
- Remote authentication
- Windows administrative protocols
- Remote service access
- Administrative shares
- Remote management mechanisms
- Authentication source and destination analysis
- Privileged session monitoring
- Lateral movement indicators
- Attack chain analysis
Module 5: Pass-the-Hash Detection
- NTLM authentication monitoring
- Windows logon events
- Source workstation analysis
- Destination host analysis
- Account behavior analysis
- Privileged logon monitoring
- Unusual authentication patterns
- Authentication event correlation
- Behavioral detection
- Detection engineering
Module 6: Threat Hunting for Pass-the-Hash
- Threat hunting methodology
- Authentication-based hunting
- Identifying abnormal NTLM usage
- Investigating privileged authentication
- Host-to-host authentication analysis
- Account activity baselining
- Lateral movement hunting
- Credential compromise indicators
- Hunt hypothesis development
- Hunt result validation
Module 7: Prevention and Mitigation
- Credential Guard
- Local Administrator Password Solution
- Privileged Access Management
- Administrative tiering
- Least privilege
- NTLM reduction strategies
- Local administrator account protection
- Credential isolation
- Endpoint hardening
- Security policy implementation
Module 8: Incident Response and Practical Investigation
- Pass-the-Hash incident identification
- Compromised account investigation
- Source and destination host analysis
- Lateral movement investigation
- Credential exposure assessment
- Account containment
- Credential rotation
- Endpoint remediation
- Persistence investigation
- Practical Pass-the-Hash investigation case studies