Visão Geral
Este curso integra Threat Hunting em Windows e Active Directory, permitindo investigar ataques contra endpoints, identidades, credenciais, autenticação, privilégios e movimentação lateral.
Conteúdo Programatico
Module 1: Integrated Threat Hunting
- Windows and Active Directory threat landscape
- Integrated hunting methodology
- Hunt hypotheses
- Attack surface analysis
- Behavioral indicators
- Identity and endpoint telemetry
- Threat intelligence
- Hunt prioritization
- Evidence collection
- Integrated hunt documentation
Module 2: Windows Telemetry
- Security Event Logs
- PowerShell logging
- Sysmon
- Process creation
- Service activity
- Scheduled Tasks
- Network connections
- Registry activity
- Endpoint telemetry
- Windows hunting data sources
Module 3: Active Directory Telemetry
- Domain Controller logs
- Authentication events
- Account management
- Group membership
- Kerberos events
- NTLM events
- Directory changes
- Replication events
- Privileged activity
- Active Directory data sources
Module 4: Credential Attack Hunting
- Credential Dumping
- LSASS access
- Kerberoasting
- AS-REP Roasting
- Pass-the-Hash
- Pass-the-Ticket
- DCSync
- Golden Ticket
- Credential attack correlation
- Credential threat hunting
Module 5: Privilege and Persistence Hunting
- Privilege escalation
- Privileged accounts
- Group membership changes
- Group Policy modifications
- Service accounts
- Scheduled Tasks
- Registry persistence
- Kerberos persistence
- Persistence detection
- Privilege and persistence investigation
Module 6: Lateral Movement Hunting
- SMB
- WinRM
- Remote Desktop
- WMI
- Remote services
- Credential reuse
- Authentication anomalies
- Endpoint-to-domain correlation
- Lateral Movement detection
- Attack path reconstruction
Module 7: SIEM-Based Hunting
- Windows and AD data ingestion
- Query development
- Event correlation
- Identity-based hunting
- Endpoint-based hunting
- Attack chain correlation
- MITRE ATT&CK mapping
- Detection engineering
- Hunt automation
- Hunt reporting
Module 8: Practical Windows and Active Directory Hunting
- Hunt hypothesis creation
- Endpoint investigation
- Authentication hunting
- Credential attack hunting
- Privileged activity hunting
- Persistence hunting
- Lateral Movement hunting
- Attack timeline reconstruction
- Detection development
- Integrated threat hunting case studies