Visão Geral
Este curso apresenta o funcionamento da autenticação Kerberos e os conceitos associados ao Pass-the-Ticket (PtT). O participante compreenderá tickets de autenticação, riscos relacionados ao roubo e reutilização de tickets, indicadores de comprometimento, técnicas de detecção e mecanismos de proteção do Active Directory.
Conteúdo Programatico
Module 1: Kerberos Authentication Fundamentals
- Kerberos architecture
- Key Distribution Center
- Authentication Service
- Ticket Granting Service
- Ticket Granting Tickets
- Service tickets
- Kerberos authentication flow
- Authentication sessions
- Ticket lifecycle
- Kerberos security principles
Module 2: Kerberos Tickets and Credentials
- Ticket structure
- Ticket Granting Ticket lifecycle
- Service ticket lifecycle
- Ticket encryption concepts
- Session keys
- Authentication identifiers
- Ticket caching
- User and service authentication
- Credential material associated with Kerberos
- Ticket security considerations
Module 3: Pass-the-Ticket Fundamentals
- Pass-the-Ticket concepts
- Ticket theft scenarios
- Ticket reuse
- Authentication session abuse
- Privileged ticket risks
- Ticket-based lateral movement
- Attack prerequisites
- Attack indicators
- Security implications
- Relationship between credential compromise and ticket compromise
Module 4: Kerberos Abuse and Lateral Movement
- Kerberos-based lateral movement
- Remote authentication
- Service authentication
- Privileged account abuse
- Service account risks
- Domain Controller interactions
- Authentication anomalies
- Lateral movement indicators
- Attack chain analysis
- Defensive visibility requirements
Module 5: Pass-the-Ticket Detection
- Kerberos event monitoring
- Authentication event analysis
- Ticket request analysis
- Logon event correlation
- Source and destination analysis
- Unusual ticket activity
- Account behavior analysis
- Privileged authentication monitoring
- Detection engineering
- Threat hunting
Module 6: Advanced Kerberos Threat Detection
- Golden Ticket concepts
- Silver Ticket concepts
- Forged authentication material
- Abnormal ticket lifetimes
- Unusual encryption types
- Service account anomalies
- Domain privilege abuse
- Domain Controller indicators
- Authentication baseline comparison
- Advanced detection strategies
Module 7: Kerberos Security and Hardening
- Kerberos security controls
- Privileged account protection
- Service account security
- Managed service accounts
- Administrative tiering
- Credential isolation
- Domain Controller hardening
- Password rotation
- Ticket lifetime considerations
- Identity security architecture
Module 8: Incident Response and Practical Investigation
- Pass-the-Ticket incident identification
- Suspicious ticket investigation
- Compromised account assessment
- Lateral movement investigation
- Domain compromise assessment
- Ticket and credential invalidation
- Account remediation
- Domain Controller assessment
- Recovery procedures
- Practical Pass-the-Ticket investigation case studies