Visão Geral
Este curso apresenta técnicas de Threat Hunting em ambientes Windows, utilizando logs, telemetria de endpoints, processos, PowerShell, autenticação e indicadores comportamentais.
Conteúdo Programatico
Module 1: Windows Threat Hunting Fundamentals
- Threat Hunting concepts
- Hunt lifecycle
- Threat hypotheses
- Windows attack surface
- Behavioral indicators
- Indicators of Compromise
- Indicators of Attack
- Hunt planning
- Hunt documentation
- Threat hunting maturity
Module 2: Windows Telemetry
- Windows Event Logs
- Security logs
- System logs
- PowerShell logs
- Sysmon
- Process telemetry
- Network telemetry
- Authentication telemetry
- Registry telemetry
- Telemetry collection
Module 3: Process and Execution Hunting
- Process creation
- Parent-child relationships
- Suspicious command execution
- PowerShell activity
- Windows scripting
- LOLBins
- Command-line analysis
- Execution anomalies
- Process-based detection
- Process hunting methodology
Module 4: Credential Attack Hunting
- Credential Dumping indicators
- LSASS access
- Password attack indicators
- Kerberos anomalies
- NTLM anomalies
- Pass-the-Hash
- Pass-the-Ticket
- Credential theft patterns
- Authentication hunting
- Credential attack investigation
Module 5: Persistence and Privilege Hunting
- Windows persistence
- Scheduled tasks
- Services
- Registry persistence
- Startup locations
- Privilege escalation indicators
- Administrative activity
- Privileged account abuse
- Persistence hunting
- Privilege hunting
Module 6: Lateral Movement Hunting
- Lateral Movement concepts
- SMB activity
- WinRM activity
- Remote Desktop
- WMI activity
- Remote service execution
- Authentication patterns
- Network-based indicators
- Lateral Movement detection
- Movement investigation
Module 7: SIEM-Based Windows Hunting
- SIEM search methodology
- Query development
- Event correlation
- Time-based investigation
- Host-based investigation
- User-based investigation
- IOC-based hunting
- Behavioral hunting
- Detection rule conversion
- Hunt reporting
Module 8: Practical Windows Threat Hunting
- Hunt hypothesis creation
- Event Log investigation
- Process hunting
- PowerShell hunting
- Credential attack hunting
- Persistence hunting
- Lateral Movement hunting
- SIEM investigation
- Threat timeline reconstruction
- Windows threat hunting case studies