Visão Geral
Este curso aborda o ciclo completo de detecção e resposta a ameaças, desde a identificação de indicadores até investigação, contenção, erradicação e recuperação.
Conteúdo Programatico
Module 1: Threat Detection Fundamentals
- Threat detection concepts
- Detection lifecycle
- Indicators of Compromise
- Indicators of Attack
- Behavioral detection
- Detection coverage
- Detection maturity
- Threat intelligence
- Detection engineering
- Detection validation
Module 2: Security Telemetry
- Windows Event Logs
- Linux logs
- Network telemetry
- Endpoint telemetry
- Authentication logs
- DNS telemetry
- Proxy logs
- Cloud telemetry
- Log normalization
- Telemetry quality
Module 3: Detection Engineering
- Detection rule design
- Behavioral analytics
- Correlation rules
- Threshold-based detection
- Signature-based detection
- Anomaly detection
- Detection tuning
- False positive reduction
- Detection testing
- Detection lifecycle management
Module 4: Threat Investigation
- Alert triage
- Event correlation
- Timeline analysis
- IOC investigation
- Endpoint investigation
- Network investigation
- Identity investigation
- Attack path reconstruction
- Threat classification
- Investigation reporting
Module 5: Credential and Identity Threats
- Password attacks
- Credential Dumping
- Kerberoasting
- Pass-the-Hash
- Pass-the-Ticket
- DCSync
- Privileged account abuse
- Authentication anomalies
- Identity detection
- Credential threat response
Module 6: Malware and Endpoint Threats
- Malware indicators
- Suspicious processes
- Command execution
- Persistence indicators
- Defense Evasion indicators
- Endpoint telemetry
- EDR investigation
- Malware containment
- Malware eradication
- Endpoint recovery
Module 7: Incident Response
- Incident triage
- Incident classification
- Containment
- Eradication
- Recovery
- Evidence preservation
- Threat actor tracking
- Incident communication
- Post-incident analysis
- Response improvement
Module 8: Practical Detection and Response
- Detection rule development
- SIEM investigation
- Endpoint investigation
- Credential attack detection
- Malware detection
- Attack timeline reconstruction
- Containment exercise
- Incident response simulation
- Detection validation
- Threat detection case studies