Visão Geral
Este curso aborda técnicas avançadas de obtenção, extração, proteção e detecção de credenciais em ambientes Windows. O conteúdo explora fontes de credenciais, mecanismos de autenticação, riscos de exposição e técnicas de defesa utilizadas em avaliações de segurança e resposta a incidentes.
Conteúdo Programatico
Module 1: Advanced Credential Theft Fundamentals
- Credential theft attack lifecycle
- Windows authentication architecture
- Credential material and authentication secrets
- Credential exposure and attack surface
- Credential Access techniques
- Local and domain credential sources
- Privileged credential targeting
- Credential theft indicators
- Defensive architecture
- Credential protection strategy
Module 2: Windows Credential Sources
- LSASS memory
- SAM database
- Security Account Manager architecture
- Windows Credential Manager
- Cached domain credentials
- Registry-based credential material
- Service account credentials
- Browser and application credential stores
- DPAPI-protected secrets
- Credential source assessment
Module 3: Advanced Credential Access Techniques
- Memory-based credential extraction concepts
- Credential dumping attack chains
- Hash extraction
- Ticket extraction
- Token abuse
- Credential replay concepts
- Privileged credential targeting
- Remote credential exposure
- Credential theft detection opportunities
- Attack path analysis
Module 4: Credential Theft in Active Directory
- Domain credential exposure
- Kerberos ticket abuse
- NTLM credential abuse
- DCSync attack concepts
- Replication privilege abuse
- Service account targeting
- Kerberoasting
- AS-REP Roasting
- Domain credential compromise
- Active Directory credential defense
Module 5: Credential Protection and Hardening
- Credential Guard
- Protected Users
- LAPS
- Windows Defender protections
- Administrative tiering
- Privileged Access Workstations
- Least privilege
- Authentication hardening
- Credential exposure reduction
- Credential security architecture
Module 6: Detection and Investigation
- Credential Access detection
- Windows Event Logs
- Sysmon telemetry
- Process creation monitoring
- Authentication event analysis
- Suspicious memory access
- Privileged account monitoring
- SIEM correlation
- Threat hunting
- Credential theft investigation
Module 7: Incident Response
- Credential compromise assessment
- Compromised account identification
- Credential revocation
- Password reset strategy
- Kerberos ticket invalidation
- Privileged account containment
- Endpoint isolation
- Evidence preservation
- Recovery procedures
- Post-incident credential analysis
Module 8: Practical Credential Theft Defense
- Credential exposure assessment
- Credential source identification
- Detection rule development
- Event Log investigation
- Privileged account analysis
- Credential protection validation
- Attack path analysis
- Security control assessment
- Incident response simulation
- Advanced credential theft case studies