Visão Geral
Este curso aborda investigação de comprometimentos em Active Directory, com foco em credenciais, autenticação, privilégios, Domain Controllers, persistência, movimentação lateral e reconstrução de ataques.
Conteúdo Programatico
Module 1: Active Directory Compromise Investigation
- Active Directory compromise scenarios
- Domain attack lifecycle
- Identity compromise
- Credential compromise
- Privilege escalation
- Lateral Movement
- Persistence
- Domain Controller compromise
- Investigation methodology
- Investigation scope
Module 2: Authentication Investigation
- Kerberos authentication
- NTLM authentication
- Authentication events
- Failed authentication
- Abnormal authentication
- Service ticket analysis
- Ticket-based attacks
- Pass-the-Hash indicators
- Authentication timeline
- Authentication investigation
Module 3: Credential Attack Investigation
- Credential Dumping
- LSASS activity
- Kerberoasting
- AS-REP Roasting
- Pass-the-Hash
- Pass-the-Ticket
- DCSync
- Golden Ticket
- Silver Ticket
- Credential compromise assessment
Module 4: Privilege and Persistence Investigation
- Privileged accounts
- Privileged group changes
- Group Policy modifications
- Service account abuse
- Delegation abuse
- Persistence mechanisms
- Golden Ticket persistence
- Silver Ticket persistence
- Administrative persistence
- Persistence investigation
Module 5: Lateral Movement Investigation
- SMB activity
- WinRM
- Remote Desktop
- WMI
- Remote service execution
- Credential reuse
- Privileged movement
- Authentication correlation
- Movement timeline
- Lateral Movement reconstruction
Module 6: Domain Controller Investigation
- Domain Controller telemetry
- Security logs
- Directory Service logs
- Replication activity
- DCSync investigation
- Group Policy activity
- Account management
- Privileged operations
- Domain compromise indicators
- Domain Controller investigation
Module 7: Attack Reconstruction and Response
- Attack timeline
- Initial Access
- Credential Access
- Privilege Escalation
- Lateral Movement
- Persistence
- Command and Control
- Impact assessment
- Containment
- Recovery planning
Module 8: Practical Active Directory Investigation
- Compromise triage
- Authentication analysis
- Credential investigation
- Privileged activity investigation
- Lateral Movement analysis
- Domain Controller analysis
- Timeline reconstruction
- SIEM investigation
- Incident response
- Active Directory compromise case study