Curso Active Directory Threat Hunting

  • Redes & Infraestrutura de TI

Curso Active Directory Threat Hunting

24h
Visão Geral

Este curso aborda Threat Hunting especificamente em ambientes Active Directory, com foco em autenticação, credenciais, privilégios, Kerberos, NTLM, Domain Controllers e movimentação lateral.

Objetivo

Após realizar este curso, você será capaz de:

  • Investigar ameaças em Active Directory
  • Identificar anomalias de autenticação
  • Detectar ataques contra credenciais
  • Realizar hunting orientado a hipóteses
Publico Alvo
  • Threat Hunters
  • SOC Analysts
  • Blue Team
  • Active Directory Security Professionals
Pre-Requisitos
  • Conhecimentos de Active Directory
  • Familiaridade com Kerberos e NTLM
  • Conhecimentos de Windows Event Logs
  • Noções de SIEM
  • Conhecimentos básicos de PowerShell
Conteúdo Programatico

Module 1: Active Directory Threat Hunting

  1. Active Directory threat landscape
  2. Threat Hunting methodology
  3. Attack hypotheses
  4. Identity attack surface
  5. Domain attack paths
  6. Threat hunting lifecycle
  7. Behavioral indicators
  8. Hunt prioritization
  9. Evidence collection
  10. Hunt documentation

Module 2: Active Directory Telemetry

  1. Domain Controller logs
  2. Authentication events
  3. Account management events
  4. Group membership events
  5. Directory Service logs
  6. Kerberos events
  7. NTLM events
  8. PowerShell logging
  9. Sysmon telemetry
  10. SIEM integration

Module 3: Kerberos Threat Hunting

  1. Kerberos authentication
  2. Ticket Granting Tickets
  3. Service tickets
  4. Kerberoasting indicators
  5. AS-REP Roasting indicators
  6. Pass-the-Ticket indicators
  7. Golden Ticket indicators
  8. Abnormal ticket activity
  9. Kerberos event correlation
  10. Kerberos threat hunting

Module 4: Credential Attack Hunting

  1. Credential Dumping
  2. LSASS access
  3. Pass-the-Hash
  4. DCSync
  5. Credential exposure
  6. Privileged credential abuse
  7. Authentication anomalies
  8. Suspicious account activity
  9. Credential attack correlation
  10. Credential threat hunting

Module 5: Privilege and Persistence Hunting

  1. Privileged account activity
  2. Group membership changes
  3. Administrative delegation
  4. Group Policy changes
  5. Service account abuse
  6. Persistence mechanisms
  7. Golden Ticket persistence
  8. Silver Ticket persistence
  9. Privileged persistence hunting
  10. Persistence investigation

Module 6: Lateral Movement Hunting

  1. Domain reconnaissance
  2. SMB activity
  3. WinRM activity
  4. Remote Desktop
  5. WMI
  6. Remote service activity
  7. Authentication patterns
  8. Privileged movement
  9. Lateral Movement indicators
  10. Attack path reconstruction

Module 7: SIEM and MITRE ATT&CK

  1. SIEM hunting methodology
  2. Query development
  3. Event correlation
  4. MITRE ATT&CK mapping
  5. Credential Access techniques
  6. Discovery techniques
  7. Lateral Movement techniques
  8. Persistence techniques
  9. Detection rule development
  10. Threat hunting reporting

Module 8: Practical Active Directory Hunting

  1. Hunt hypothesis creation
  2. Authentication hunting
  3. Kerberos hunting
  4. Credential attack hunting
  5. Privileged account hunting
  6. Persistence hunting
  7. Lateral Movement hunting
  8. SIEM investigation
  9. Attack timeline reconstruction
  10. Active Directory threat hunting case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas