Visão Geral
Este curso aborda Threat Hunting especificamente em ambientes Active Directory, com foco em autenticação, credenciais, privilégios, Kerberos, NTLM, Domain Controllers e movimentação lateral.
Conteúdo Programatico
Module 1: Active Directory Threat Hunting
- Active Directory threat landscape
- Threat Hunting methodology
- Attack hypotheses
- Identity attack surface
- Domain attack paths
- Threat hunting lifecycle
- Behavioral indicators
- Hunt prioritization
- Evidence collection
- Hunt documentation
Module 2: Active Directory Telemetry
- Domain Controller logs
- Authentication events
- Account management events
- Group membership events
- Directory Service logs
- Kerberos events
- NTLM events
- PowerShell logging
- Sysmon telemetry
- SIEM integration
Module 3: Kerberos Threat Hunting
- Kerberos authentication
- Ticket Granting Tickets
- Service tickets
- Kerberoasting indicators
- AS-REP Roasting indicators
- Pass-the-Ticket indicators
- Golden Ticket indicators
- Abnormal ticket activity
- Kerberos event correlation
- Kerberos threat hunting
Module 4: Credential Attack Hunting
- Credential Dumping
- LSASS access
- Pass-the-Hash
- DCSync
- Credential exposure
- Privileged credential abuse
- Authentication anomalies
- Suspicious account activity
- Credential attack correlation
- Credential threat hunting
Module 5: Privilege and Persistence Hunting
- Privileged account activity
- Group membership changes
- Administrative delegation
- Group Policy changes
- Service account abuse
- Persistence mechanisms
- Golden Ticket persistence
- Silver Ticket persistence
- Privileged persistence hunting
- Persistence investigation
Module 6: Lateral Movement Hunting
- Domain reconnaissance
- SMB activity
- WinRM activity
- Remote Desktop
- WMI
- Remote service activity
- Authentication patterns
- Privileged movement
- Lateral Movement indicators
- Attack path reconstruction
Module 7: SIEM and MITRE ATT&CK
- SIEM hunting methodology
- Query development
- Event correlation
- MITRE ATT&CK mapping
- Credential Access techniques
- Discovery techniques
- Lateral Movement techniques
- Persistence techniques
- Detection rule development
- Threat hunting reporting
Module 8: Practical Active Directory Hunting
- Hunt hypothesis creation
- Authentication hunting
- Kerberos hunting
- Credential attack hunting
- Privileged account hunting
- Persistence hunting
- Lateral Movement hunting
- SIEM investigation
- Attack timeline reconstruction
- Active Directory threat hunting case studies