Curso Threat Hunting with MITRE ATT&CK

  • Redes & Infraestrutura de TI

Curso Threat Hunting with MITRE ATT&CK

24h
Visão Geral

Este curso ensina a utilização do MITRE ATT&CK como estrutura para criação de hipóteses, investigação de comportamentos adversários, desenvolvimento de detecções e avaliação de cobertura defensiva.

Objetivo

Após realizar este curso, você será capaz de:

  • Utilizar o MITRE ATT&CK em hunting
  • Mapear técnicas adversárias
  • Criar hipóteses baseadas em TTPs
  • Avaliar cobertura de detecção
Publico Alvo
  • Threat Hunters
  • SOC Analysts
  • Blue Team
  • Detection Engineers
Pre-Requisitos
  • Conhecimentos de Threat Hunting
  • Familiaridade com MITRE ATT&CK
  • Conhecimentos de SIEM
  • Conhecimentos de logs
  • Noções de incident response
Conteúdo Programatico

Module 1: MITRE ATT&CK Fundamentals

  1. MITRE ATT&CK framework
  2. Tactics
  3. Techniques
  4. Sub-techniques
  5. Procedures
  6. Groups
  7. Software
  8. Campaigns
  9. ATT&CK Navigator concepts
  10. ATT&CK knowledge base

Module 2: ATT&CK-Based Threat Hunting

  1. Threat hunting methodology
  2. Technique-based hunting
  3. TTP-based hypotheses
  4. Adversary behavior
  5. Hunt prioritization
  6. Data source mapping
  7. Evidence requirements
  8. Hunt validation
  9. Hunt documentation
  10. ATT&CK-based workflows

Module 3: Credential Access Hunting

  1. Credential Dumping
  2. Brute Force
  3. Password Spraying
  4. Kerberoasting
  5. AS-REP Roasting
  6. Pass-the-Hash
  7. Pass-the-Ticket
  8. DCSync
  9. Credential Access data sources
  10. Credential attack detection

Module 4: Execution and Persistence Hunting

  1. Command and Scripting Interpreter
  2. PowerShell
  3. Windows Command Shell
  4. Scheduled Tasks
  5. Services
  6. Registry Run Keys
  7. WMI
  8. Persistence indicators
  9. Execution telemetry
  10. Detection opportunities

Module 5: Discovery and Lateral Movement Hunting

  1. System Discovery
  2. Account Discovery
  3. Network Discovery
  4. Remote Services
  5. SMB
  6. WinRM
  7. Remote Desktop
  8. Credential reuse
  9. Lateral Movement indicators
  10. ATT&CK-based movement hunting

Module 6: Command and Control and Exfiltration

  1. Command and Control
  2. Application Layer Protocols
  3. DNS-based communication
  4. Web-based communication
  5. Beaconing
  6. Network anomalies
  7. Data Staged
  8. Data Exfiltration
  9. C2 detection
  10. Exfiltration hunting

Module 7: Detection Coverage

  1. ATT&CK coverage
  2. Detection gaps
  3. Data source coverage
  4. Detection engineering
  5. Detection maturity
  6. Detection validation
  7. False positive reduction
  8. Coverage visualization
  9. Hunt-to-detection workflows
  10. Security improvement planning

Module 8: Practical ATT&CK Threat Hunting

  1. Technique selection
  2. Hunt hypothesis
  3. Data source mapping
  4. SIEM investigation
  5. TTP analysis
  6. Attack reconstruction
  7. Detection development
  8. ATT&CK mapping
  9. Hunt reporting
  10. ATT&CK threat hunting case study
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas