Curso Threat Hunting Fundamentals

  • Redes & Infraestrutura de TI

Curso Threat Hunting Fundamentals

24h
Visão Geral

Este curso apresenta os fundamentos de Threat Hunting, abordando hipóteses de investigação, telemetria, indicadores, comportamento adversário, análise de eventos e transformação de hunts em mecanismos de detecção.

Objetivo

Após realizar este curso, você será capaz de:

  • Criar hipóteses de Threat Hunting
  • Investigar comportamentos suspeitos
  • Correlacionar evidências
  • Desenvolver processos de hunting
Publico Alvo
  • Threat Hunters
  • SOC Analysts
  • Blue Team
  • Cybersecurity Professionals
Pre-Requisitos
  • Conhecimentos de redes
  • Familiaridade com Windows e Linux
  • Conhecimentos básicos de SIEM
  • Noções de logs
  • Conhecimentos de segurança da informação
Conteúdo Programatico

Module 1: Threat Hunting Fundamentals

  1. Threat Hunting concepts
  2. Proactive security
  3. Hunt lifecycle
  4. Threat hypotheses
  5. Hunt objectives
  6. Threat intelligence
  7. Behavioral indicators
  8. Indicators of Compromise
  9. Hunt prioritization
  10. Hunt documentation

Module 2: Threat Hunting Data Sources

  1. Windows Event Logs
  2. Linux logs
  3. Network telemetry
  4. Endpoint telemetry
  5. DNS logs
  6. Authentication logs
  7. Cloud telemetry
  8. Application logs
  9. SIEM data
  10. Telemetry quality

Module 3: Hunt Hypothesis Development

  1. Threat-driven hypotheses
  2. Intelligence-driven hypotheses
  3. Behavior-based hypotheses
  4. Attack technique hypotheses
  5. Risk-based hunting
  6. Hypothesis validation
  7. Hunt scope
  8. Investigation criteria
  9. Evidence requirements
  10. Hunt planning

Module 4: Investigation Techniques

  1. IOC analysis
  2. Behavioral analysis
  3. Event correlation
  4. Timeline analysis
  5. User-based hunting
  6. Host-based hunting
  7. Network-based hunting
  8. Identity-based hunting
  9. Attack path analysis
  10. Investigation documentation

Module 5: MITRE ATT&CK and Threat Hunting

  1. MITRE ATT&CK fundamentals
  2. Tactics
  3. Techniques
  4. Sub-techniques
  5. Technique-based hunting
  6. ATT&CK data sources
  7. ATT&CK detection opportunities
  8. Threat actor TTPs
  9. Hunt-to-detection mapping
  10. ATT&CK-based reporting

Module 6: Detection Engineering

  1. Detection rule development
  2. Hunt findings
  3. Detection logic
  4. Correlation rules
  5. Detection tuning
  6. False positive management
  7. Detection validation
  8. Detection coverage
  9. Hunt automation
  10. Detection lifecycle

Module 7: Threat Hunting Operations

  1. Hunt scheduling
  2. Hunt prioritization
  3. Investigation workflows
  4. Collaboration
  5. Case management
  6. Hunt metrics
  7. Findings management
  8. Intelligence integration
  9. Continuous hunting
  10. Threat hunting maturity

Module 8: Practical Threat Hunting

  1. Hunt hypothesis creation
  2. Data source identification
  3. IOC investigation
  4. Behavioral hunting
  5. ATT&CK-based hunting
  6. SIEM investigation
  7. Timeline reconstruction
  8. Detection development
  9. Hunt reporting
  10. Threat hunting case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas