Visão Geral
Este curso apresenta o Microsoft Defender no contexto da proteção de endpoints Windows. Aborda mecanismos de prevenção, detecção, resposta, políticas de segurança, proteção contra malware, Attack Surface Reduction, monitoramento e integração com recursos corporativos de segurança.
Conteúdo Programatico
Module 1: Microsoft Defender Fundamentals
- Microsoft Defender architecture
- Endpoint protection concepts
- Malware protection
- Antivirus protection
- Real-time protection
- Threat detection
- Threat prevention
- Security intelligence
- Defender components
- Windows security architecture
Module 2: Antivirus Configuration
- Real-time protection
- Cloud-delivered protection
- Automatic sample submission
- Security intelligence updates
- Scheduled scans
- Quick and full scans
- Custom scans
- Exclusions
- Tamper Protection
- Antivirus policy management
Module 3: Attack Surface Reduction
- Attack Surface Reduction concepts
- ASR rules
- Office application protection
- Script-based attack prevention
- Credential theft protection
- Exploit mitigation
- Application behavior restrictions
- ASR auditing
- ASR block mode
- ASR policy management
Module 4: Defender and Active Directory
- Group Policy integration
- Centralized Defender configuration
- Organizational Unit targeting
- Security policy deployment
- Domain-based endpoint management
- Administrative permissions
- Defender policy inheritance
- Security baseline integration
- Policy troubleshooting
- Enterprise Defender management
Module 5: Threat Detection and Response
- Malware detection
- Suspicious process detection
- Behavioral detection
- Endpoint alerts
- Threat investigation
- Detection telemetry
- Automated response concepts
- Endpoint isolation
- Threat remediation
- Incident response workflows
Module 6: Monitoring and Logging
- Defender event logs
- Windows Event Logs
- Detection telemetry
- Security alerts
- PowerShell monitoring
- Process monitoring
- Threat hunting
- SIEM integration
- Alert correlation
- Security reporting
Module 7: Defender Hardening
- Defender security baselines
- Tamper Protection
- Attack Surface Reduction
- Credential protection
- Cloud protection
- Application control
- Exploit protection
- Endpoint security policies
- Administrative protection
- Defender hardening strategy
Module 8: Practical Defender Administration
- Defender configuration assessment
- Antivirus policy configuration
- ASR policy implementation
- Detection investigation
- Event Log analysis
- Alert analysis
- Security baseline validation
- Hardening assessment
- Incident response exercise
- Practical Microsoft Defender security cases