Curso Blue Team Fundamentals

  • Redes & Infraestrutura de TI

Curso Blue Team Fundamentals

24h
Visão Geral

Este curso apresenta os fundamentos da defesa cibernética, abordando arquitetura defensiva, monitoramento, hardening, detecção, threat hunting e resposta a incidentes.

Objetivo

Após realizar este curso, você será capaz de:

  • Implementar controles defensivos
  • Monitorar ambientes
  • Identificar ameaças
  • Apoiar processos de resposta a incidentes
Publico Alvo
  • Profissionais de Blue Team
  • Analistas de SOC
  • Profissionais de Cybersecurity
  • Administradores de sistemas
Pre-Requisitos
  • Conhecimentos básicos de redes
  • Familiaridade com Windows e Linux
  • Noções de segurança da informação
  • Conhecimentos básicos de logs
  • Familiaridade com conceitos de infraestrutura
Conteúdo Programatico

Module 1: Blue Team Fundamentals

  1. Blue Team concepts
  2. Defensive security
  3. Defense-in-depth
  4. Security controls
  5. Attack surface reduction
  6. Security architecture
  7. Security monitoring
  8. Threat detection
  9. Incident response
  10. Blue Team operations

Module 2: Endpoint Security

  1. Endpoint security
  2. Windows security
  3. Linux security
  4. EDR concepts
  5. Antivirus
  6. Application control
  7. Endpoint telemetry
  8. Host hardening
  9. Endpoint monitoring
  10. Endpoint incident response

Module 3: Network Defense

  1. Network security architecture
  2. Firewalls
  3. IDS and IPS
  4. Network segmentation
  5. Network monitoring
  6. Secure protocols
  7. Traffic analysis
  8. Network-based detection
  9. Network hardening
  10. Network defense strategy

Module 4: Identity Defense

  1. Identity security
  2. Authentication
  3. Authorization
  4. Active Directory security
  5. Privileged accounts
  6. Credential protection
  7. MFA
  8. Identity monitoring
  9. Identity threat detection
  10. Identity hardening

Module 5: Security Monitoring

  1. Log collection
  2. Windows Event Logs
  3. Linux logs
  4. Network telemetry
  5. Endpoint telemetry
  6. SIEM
  7. Security alerts
  8. Event correlation
  9. Detection rules
  10. Monitoring strategy

Module 6: Threat Detection

  1. Detection engineering
  2. Indicators of compromise
  3. Behavioral detection
  4. MITRE ATT&CK
  5. Malware detection
  6. Credential attack detection
  7. Lateral Movement detection
  8. Persistence detection
  9. Threat intelligence integration
  10. Detection validation

Module 7: Incident Response

  1. Incident response lifecycle
  2. Detection and triage
  3. Containment
  4. Eradication
  5. Recovery
  6. Evidence collection
  7. Incident documentation
  8. Communication
  9. Lessons learned
  10. Incident response improvement

Module 8: Practical Blue Team Operations

  1. Security monitoring exercise
  2. Alert investigation
  3. Endpoint investigation
  4. Network investigation
  5. Identity investigation
  6. Threat detection exercise
  7. Incident response simulation
  8. Security control validation
  9. Defensive reporting
  10. Blue Team case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas