Curso Threat Hunting Windows & Active Directory

  • Redes & Infraestrutura de TI

Curso Threat Hunting Windows & Active Directory

32h
Visão Geral

Este curso integra Threat Hunting em Windows e Active Directory, permitindo investigar ataques contra endpoints, identidades, credenciais, autenticação, privilégios e movimentação lateral.

Objetivo

Após realizar este curso, você será capaz de:

  • Realizar hunting em Windows e AD
  • Correlacionar eventos de identidade e endpoint
  • Identificar ataques avançados
  • Reconstruir caminhos de comprometimento
Publico Alvo
  • Threat Hunters
  • SOC Analysts
  • Blue Team
  • Active Directory Security Professionals
Pre-Requisitos
  • Conhecimentos de Windows
  • Conhecimentos de Active Directory
  • Familiaridade com Kerberos e NTLM
  • Conhecimentos de SIEM
  • Familiaridade com PowerShell
Conteúdo Programatico

Module 1: Integrated Threat Hunting

  1. Windows and Active Directory threat landscape
  2. Integrated hunting methodology
  3. Hunt hypotheses
  4. Attack surface analysis
  5. Behavioral indicators
  6. Identity and endpoint telemetry
  7. Threat intelligence
  8. Hunt prioritization
  9. Evidence collection
  10. Integrated hunt documentation

Module 2: Windows Telemetry

  1. Security Event Logs
  2. PowerShell logging
  3. Sysmon
  4. Process creation
  5. Service activity
  6. Scheduled Tasks
  7. Network connections
  8. Registry activity
  9. Endpoint telemetry
  10. Windows hunting data sources

Module 3: Active Directory Telemetry

  1. Domain Controller logs
  2. Authentication events
  3. Account management
  4. Group membership
  5. Kerberos events
  6. NTLM events
  7. Directory changes
  8. Replication events
  9. Privileged activity
  10. Active Directory data sources

Module 4: Credential Attack Hunting

  1. Credential Dumping
  2. LSASS access
  3. Kerberoasting
  4. AS-REP Roasting
  5. Pass-the-Hash
  6. Pass-the-Ticket
  7. DCSync
  8. Golden Ticket
  9. Credential attack correlation
  10. Credential threat hunting

Module 5: Privilege and Persistence Hunting

  1. Privilege escalation
  2. Privileged accounts
  3. Group membership changes
  4. Group Policy modifications
  5. Service accounts
  6. Scheduled Tasks
  7. Registry persistence
  8. Kerberos persistence
  9. Persistence detection
  10. Privilege and persistence investigation

Module 6: Lateral Movement Hunting

  1. SMB
  2. WinRM
  3. Remote Desktop
  4. WMI
  5. Remote services
  6. Credential reuse
  7. Authentication anomalies
  8. Endpoint-to-domain correlation
  9. Lateral Movement detection
  10. Attack path reconstruction

Module 7: SIEM-Based Hunting

  1. Windows and AD data ingestion
  2. Query development
  3. Event correlation
  4. Identity-based hunting
  5. Endpoint-based hunting
  6. Attack chain correlation
  7. MITRE ATT&CK mapping
  8. Detection engineering
  9. Hunt automation
  10. Hunt reporting

Module 8: Practical Windows and Active Directory Hunting

  1. Hunt hypothesis creation
  2. Endpoint investigation
  3. Authentication hunting
  4. Credential attack hunting
  5. Privileged activity hunting
  6. Persistence hunting
  7. Lateral Movement hunting
  8. Attack timeline reconstruction
  9. Detection development
  10. Integrated threat hunting case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas