Visão Geral
Este curso aborda investigação e resposta a incidentes envolvendo ambientes Active Directory. O participante aprenderá a identificar comprometimento de contas, investigar Domain Controllers, analisar autenticação, rastrear movimentação lateral e executar processos de contenção e recuperação.
Conteúdo Programatico
Module 1: Active Directory Incident Response Fundamentals
- Active Directory incident response
- Domain compromise scenarios
- Identity compromise
- Credential compromise
- Privileged account compromise
- Domain Controller incidents
- Incident severity assessment
- Evidence sources
- Response lifecycle
- Incident response preparation
Module 2: Authentication and Credential Investigation
- Kerberos event analysis
- NTLM event analysis
- Account logon events
- Credential theft indicators
- Pass-the-Hash indicators
- Pass-the-Ticket indicators
- Kerberoasting indicators
- DCSync indicators
- Suspicious authentication
- Authentication timeline reconstruction
Module 3: Active Directory Compromise Investigation
- Compromised account analysis
- Privileged group changes
- Group Policy modifications
- Suspicious account creation
- Domain Controller activity
- Replication activity
- Persistence mechanisms
- Lateral Movement
- Attack path reconstruction
- Domain compromise assessment
Module 4: Windows Event Log Investigation
- Security Event Logs
- System Event Logs
- PowerShell logs
- Process creation events
- Authentication events
- Account management events
- Group membership events
- Domain Controller events
- Event correlation
- Timeline analysis
Module 5: Containment and Eradication
- Account containment
- Credential reset
- Privileged account containment
- Kerberos ticket invalidation
- Endpoint isolation
- Persistence removal
- Malicious account removal
- Unauthorized GPO remediation
- Domain security restoration
- Eradication validation
Module 6: Recovery
- Active Directory recovery planning
- Domain Controller recovery
- Credential recovery
- Privileged access restoration
- Security configuration restoration
- Monitoring reinforcement
- Backup validation
- Recovery verification
- Post-recovery monitoring
- Business continuity considerations
Module 7: Threat Hunting During Response
- Compromise indicator development
- Authentication hunting
- Credential theft hunting
- Lateral Movement hunting
- Persistence hunting
- Privileged activity hunting
- SIEM queries
- Endpoint telemetry
- MITRE ATT&CK mapping
- Threat hunting documentation
Module 8: Practical Incident Response
- Active Directory compromise scenario
- Initial triage
- Evidence collection
- Authentication investigation
- Privileged account investigation
- Lateral Movement analysis
- Containment execution
- Eradication validation
- Recovery workflow
- Incident response case study