Visão Geral
Este curso aborda resposta a incidentes de ransomware, incluindo identificação, contenção, investigação, análise de impacto, proteção de backups, erradicação e recuperação de ambientes.
Conteúdo Programatico
Module 1: Ransomware Fundamentals
- Ransomware attack lifecycle
- Ransomware families
- Initial Access
- Execution
- Persistence
- Credential Access
- Lateral Movement
- Data encryption
- Data exfiltration
- Impact assessment
Module 2: Ransomware Detection
- Early warning indicators
- Suspicious processes
- File modification activity
- Authentication anomalies
- Network anomalies
- Endpoint telemetry
- EDR alerts
- SIEM detection
- Behavioral detection
- Ransomware hunting
Module 3: Initial Response
- Incident triage
- Scope identification
- Host isolation
- Network containment
- Account containment
- Credential protection
- Backup protection
- Evidence preservation
- Incident escalation
- Initial response documentation
Module 4: Attack Chain Investigation
- Initial Access investigation
- Credential theft
- Privilege escalation
- Active Directory compromise
- Lateral Movement
- Persistence
- Command and Control
- Data exfiltration
- Attack timeline
- Root cause analysis
Module 5: Containment and Eradication
- Enterprise containment
- Endpoint isolation
- Account remediation
- Credential reset
- Persistence removal
- Malware removal
- Compromised system identification
- Security control reinforcement
- Eradication validation
- Threat actor removal
Module 6: Backup and Recovery
- Backup security
- Backup integrity
- Offline backups
- Recovery priorities
- System restoration
- Active Directory recovery
- Application recovery
- Recovery validation
- Post-recovery monitoring
- Business continuity
Module 7: Post-Incident Analysis
- Root cause analysis
- Attack timeline
- Initial Access analysis
- Security control gaps
- Detection gaps
- Recovery lessons
- Security improvements
- Threat intelligence
- Incident reporting
- Ransomware response improvement
Module 8: Practical Ransomware Response
- Ransomware detection
- Initial triage
- Scope assessment
- Containment
- Evidence collection
- Attack reconstruction
- Eradication
- Recovery
- Post-incident analysis
- Ransomware incident case study