Visão Geral
Este curso apresenta o conceito de Silver Ticket no contexto do Kerberos e da autenticação de serviços em ambientes Active Directory. O participante compreenderá a relação entre Service Principal Names, contas de serviço e tickets, além de estudar indicadores de abuso, detecção, hardening e resposta a incidentes.
Conteúdo Programatico
Module 1: Kerberos Service Authentication
- Kerberos service authentication
- Service Principal Names
- Service accounts
- Service tickets
- Ticket Granting Tickets
- Service authentication flow
- Kerberos keys
- Session authentication
- Service trust relationships
- Service authentication security
Module 2: Silver Ticket Concepts
- Silver Ticket fundamentals
- Forged service tickets
- Service-specific authentication
- Service account key material
- Ticket validation
- Authentication trust boundaries
- Privileged service accounts
- Persistence implications
- Attack indicators
- Security implications
Module 3: Service Account Security
- Service account architecture
- Managed Service Accounts
- Group Managed Service Accounts
- Service account passwords
- SPN management
- Privileged service accounts
- Service account permissions
- Least privilege
- Service account inventory
- Service account hardening
Module 4: Silver Ticket Detection
- Kerberos service ticket monitoring
- Authentication event analysis
- Service account activity
- Ticket anomalies
- Source host analysis
- Service access patterns
- Domain Controller telemetry
- Event correlation
- Threat hunting
- Detection engineering
Module 5: Attack Investigation
- Silver Ticket incident identification
- Suspicious service authentication
- Service account compromise
- SPN analysis
- Host and service investigation
- Privilege assessment
- Persistence analysis
- Lateral movement investigation
- Credential exposure assessment
- Incident timeline reconstruction
Module 6: Prevention and Hardening
- Service account protection
- Managed Service Accounts
- Strong credential management
- SPN security
- Least privilege
- Administrative tiering
- Credential isolation
- Domain Controller hardening
- Authentication monitoring
- Service security baseline
Module 7: Incident Response and Remediation
- Silver Ticket response
- Compromised service account remediation
- Credential rotation
- Service account replacement
- Host containment
- Persistence removal
- Kerberos authentication validation
- Monitoring improvements
- Recovery procedures
- Post-incident assessment
Module 8: Practical Silver Ticket Analysis
- Service account inventory
- SPN security assessment
- Kerberos event investigation
- Suspicious service authentication scenario
- Detection rule development
- Hardening assessment
- Incident response exercise
- Security control validation
- Monitoring improvement
- Practical Silver Ticket investigation case studies