Visão Geral
Este curso ensina a utilização do MITRE ATT&CK como estrutura para criação de hipóteses, investigação de comportamentos adversários, desenvolvimento de detecções e avaliação de cobertura defensiva.
Conteúdo Programatico
Module 1: MITRE ATT&CK Fundamentals
- MITRE ATT&CK framework
- Tactics
- Techniques
- Sub-techniques
- Procedures
- Groups
- Software
- Campaigns
- ATT&CK Navigator concepts
- ATT&CK knowledge base
Module 2: ATT&CK-Based Threat Hunting
- Threat hunting methodology
- Technique-based hunting
- TTP-based hypotheses
- Adversary behavior
- Hunt prioritization
- Data source mapping
- Evidence requirements
- Hunt validation
- Hunt documentation
- ATT&CK-based workflows
Module 3: Credential Access Hunting
- Credential Dumping
- Brute Force
- Password Spraying
- Kerberoasting
- AS-REP Roasting
- Pass-the-Hash
- Pass-the-Ticket
- DCSync
- Credential Access data sources
- Credential attack detection
Module 4: Execution and Persistence Hunting
- Command and Scripting Interpreter
- PowerShell
- Windows Command Shell
- Scheduled Tasks
- Services
- Registry Run Keys
- WMI
- Persistence indicators
- Execution telemetry
- Detection opportunities
Module 5: Discovery and Lateral Movement Hunting
- System Discovery
- Account Discovery
- Network Discovery
- Remote Services
- SMB
- WinRM
- Remote Desktop
- Credential reuse
- Lateral Movement indicators
- ATT&CK-based movement hunting
Module 6: Command and Control and Exfiltration
- Command and Control
- Application Layer Protocols
- DNS-based communication
- Web-based communication
- Beaconing
- Network anomalies
- Data Staged
- Data Exfiltration
- C2 detection
- Exfiltration hunting
Module 7: Detection Coverage
- ATT&CK coverage
- Detection gaps
- Data source coverage
- Detection engineering
- Detection maturity
- Detection validation
- False positive reduction
- Coverage visualization
- Hunt-to-detection workflows
- Security improvement planning
Module 8: Practical ATT&CK Threat Hunting
- Technique selection
- Hunt hypothesis
- Data source mapping
- SIEM investigation
- TTP analysis
- Attack reconstruction
- Detection development
- ATT&CK mapping
- Hunt reporting
- ATT&CK threat hunting case study