Curso Credential Attack Detection

  • Redes & Infraestrutura de TI

Curso Credential Attack Detection

16h
Visão Geral

Este curso apresenta métodos para identificar ataques contra credenciais, utilizando logs, telemetria de endpoints, eventos de autenticação, SIEM e técnicas de Threat Hunting.

Objetivo

Após realizar este curso, você será capaz de:

  • Detectar ataques contra credenciais
  • Analisar eventos de autenticação
  • Criar regras de detecção
  • Investigar comprometimento de contas
Publico Alvo
  • SOC Analysts
  • Blue Team
  • Threat Hunters
  • Incident Responders
Pre-Requisitos
  • Conhecimentos de Windows
  • Familiaridade com Active Directory
  • Conhecimentos de Kerberos e NTLM
  • Noções de SIEM
  • Conhecimentos de Windows Event Logs
Conteúdo Programatico

Module 1: Credential Attack Detection Fundamentals

  1. Credential attack lifecycle
  2. Credential Access techniques
  3. Authentication attack surface
  4. Credential theft indicators
  5. Behavioral indicators
  6. Detection opportunities
  7. Detection engineering
  8. Credential monitoring
  9. Security telemetry
  10. Credential attack detection strategy

Module 2: Password Attack Detection

  1. Brute Force detection
  2. Password Spraying detection
  3. Credential Stuffing indicators
  4. Failed authentication patterns
  5. Account lockout events
  6. Distributed authentication attacks
  7. Login anomaly detection
  8. Detection correlation
  9. SIEM rules
  10. Password attack response

Module 3: Windows Credential Attack Detection

  1. LSASS access
  2. Credential Dumping indicators
  3. SAM access
  4. Credential Manager activity
  5. Cached credentials
  6. Suspicious process behavior
  7. Memory access monitoring
  8. Sysmon telemetry
  9. Endpoint detection
  10. Credential theft investigation

Module 4: Active Directory Credential Detection

  1. Kerberoasting
  2. AS-REP Roasting
  3. Pass-the-Hash
  4. Pass-the-Ticket
  5. DCSync
  6. Golden Ticket
  7. Silver Ticket
  8. Privileged account abuse
  9. Domain Controller monitoring
  10. Credential attack hunting

Module 5: SIEM Detection and Response

  1. Event correlation
  2. Authentication analytics
  3. Detection rule development
  4. Alert tuning
  5. False positive management
  6. MITRE ATT&CK mapping
  7. Threat hunting
  8. Incident escalation
  9. Credential containment
  10. Detection case studies

Curso Cybersecurity Incident Response Fundamentals

Visão geral do Curso:
Este curso apresenta os fundamentos de resposta a incidentes de segurança, abordando preparação, detecção, triagem, contenção, erradicação, recuperação e documentação.

Público-alvo:

  • Incident Responders
  • SOC Analysts
  • Blue Team
  • Profissionais de Cybersecurity

Pré-requisitos:

  • Conhecimentos básicos de redes
  • Familiaridade com Windows e Linux
  • Conhecimentos de logs
  • Noções de SIEM
  • Conhecimentos básicos de segurança

Objetivo do Curso:
Após realizar este curso, você será capaz de:

  • Estruturar processos de incident response
  • Realizar triagem de incidentes
  • Apoiar contenção e erradicação
  • Documentar investigações

Carga horária sugerida:
24 horas

Conteúdo programático do curso:

Module 1: Incident Response Fundamentals

  1. Incident response concepts
  2. Incident lifecycle
  3. Incident response teams
  4. Incident classification
  5. Severity assessment
  6. Incident response plans
  7. Roles and responsibilities
  8. Communication
  9. Escalation
  10. Incident response governance

Module 2: Detection and Triage

  1. Security alerts
  2. Alert validation
  3. Incident identification
  4. Initial triage
  5. Evidence collection
  6. IOC identification
  7. Threat classification
  8. Incident prioritization
  9. Investigation scope
  10. Triage documentation

Module 3: Investigation

  1. Timeline analysis
  2. Log investigation
  3. Endpoint investigation
  4. Network investigation
  5. Identity investigation
  6. Malware indicators
  7. Credential attacks
  8. Lateral Movement
  9. Persistence
  10. Attack reconstruction

Module 4: Containment

  1. Containment strategies
  2. Host isolation
  3. Account containment
  4. Network containment
  5. Credential reset
  6. Malicious process containment
  7. Persistence containment
  8. Short-term containment
  9. Long-term containment
  10. Containment validation

Module 5: Eradication and Recovery

  1. Malware removal
  2. Persistence removal
  3. Credential remediation
  4. Vulnerability remediation
  5. System recovery
  6. Identity recovery
  7. Security control restoration
  8. Recovery validation
  9. Monitoring after recovery
  10. Business continuity

Module 6: Evidence and Documentation

  1. Evidence handling
  2. Evidence preservation
  3. Chain of custody
  4. Investigation notes
  5. Timeline documentation
  6. IOC documentation
  7. Technical reporting
  8. Executive reporting
  9. Incident records
  10. Lessons learned

Module 7: Incident Response Tools

  1. SIEM
  2. EDR
  3. Network monitoring
  4. Threat intelligence
  5. Forensics tools
  6. Log analysis
  7. Case management
  8. Evidence collection tools
  9. Investigation workflows
  10. Tool integration

Module 8: Practical Incident Response

  1. Incident identification
  2. Initial triage
  3. Evidence collection
  4. Investigation
  5. Containment
  6. Eradication
  7. Recovery
  8. Reporting
  9. Lessons learned
  10. Incident response case study

Curso Advanced Incident Response

Visão geral do Curso:
Este curso aprofunda técnicas de investigação e resposta a incidentes complexos, incluindo ataques avançados, comprometimento de identidades, persistência, movimentação lateral e investigação de ameaças.

Público-alvo:

  • Incident Responders
  • DFIR Professionals
  • SOC e Blue Team
  • Cybersecurity Professionals

Pré-requisitos:

  • Experiência com incident response
  • Conhecimentos de Windows e Linux
  • Conhecimentos de redes
  • Familiaridade com SIEM e EDR
  • Conhecimentos básicos de Digital Forensics

Objetivo do Curso:
Após realizar este curso, você será capaz de:

  • Investigar incidentes complexos
  • Reconstruir cadeias de ataque
  • Analisar evidências avançadas
  • Conduzir contenção e recuperação

Carga horária sugerida:
32 horas

Conteúdo programático do curso:

Module 1: Advanced Incident Response

  1. Advanced incident response methodology
  2. Complex incident scenarios
  3. Multi-stage attacks
  4. Advanced threat actors
  5. Incident scoping
  6. Investigation prioritization
  7. Response coordination
  8. Advanced evidence sources
  9. Incident command
  10. Advanced response planning

Module 2: Advanced Threat Investigation

  1. Attack chain reconstruction
  2. Timeline analysis
  3. Threat actor behavior
  4. Initial Access analysis
  5. Persistence analysis
  6. Credential Access
  7. Privilege Escalation
  8. Lateral Movement
  9. Command and Control
  10. Impact assessment

Module 3: Advanced Identity Investigation

  1. Identity compromise
  2. Credential theft
  3. Kerberos investigation
  4. NTLM investigation
  5. Privileged account abuse
  6. Active Directory compromise
  7. DCSync indicators
  8. Golden Ticket investigation
  9. Authentication timeline
  10. Identity remediation

Module 4: Endpoint Investigation

  1. Endpoint telemetry
  2. Process analysis
  3. PowerShell investigation
  4. Persistence mechanisms
  5. Malware analysis
  6. EDR investigation
  7. Memory analysis concepts
  8. File system investigation
  9. Registry analysis
  10. Endpoint compromise assessment

Module 5: Network Investigation

  1. Network attack analysis
  2. DNS investigation
  3. HTTP and HTTPS traffic
  4. Network connections
  5. Command and Control
  6. Lateral Movement
  7. Network anomalies
  8. Traffic correlation
  9. Network containment
  10. Network evidence analysis

Module 6: Advanced Containment and Eradication

  1. Enterprise containment
  2. Identity containment
  3. Network containment
  4. Endpoint containment
  5. Credential revocation
  6. Persistence eradication
  7. Threat actor removal
  8. Security control reinforcement
  9. Eradication validation
  10. Recovery planning

Module 7: Threat Intelligence and Attribution

  1. Threat intelligence
  2. Threat actor profiling
  3. Campaign analysis
  4. IOC enrichment
  5. TTP analysis
  6. MITRE ATT&CK
  7. Intelligence correlation
  8. Attribution limitations
  9. Intelligence reporting
  10. Threat intelligence integration

Module 8: Advanced Incident Simulation

  1. Complex incident scenario
  2. Initial triage
  3. Evidence collection
  4. Attack reconstruction
  5. Threat hunting
  6. Containment
  7. Eradication
  8. Recovery
  9. Executive reporting
  10. Advanced incident response case study
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas