Conteúdo Programatico
Module 1: Credential Attack Detection Fundamentals
- Credential attack lifecycle
- Credential Access techniques
- Authentication attack surface
- Credential theft indicators
- Behavioral indicators
- Detection opportunities
- Detection engineering
- Credential monitoring
- Security telemetry
- Credential attack detection strategy
Module 2: Password Attack Detection
- Brute Force detection
- Password Spraying detection
- Credential Stuffing indicators
- Failed authentication patterns
- Account lockout events
- Distributed authentication attacks
- Login anomaly detection
- Detection correlation
- SIEM rules
- Password attack response
Module 3: Windows Credential Attack Detection
- LSASS access
- Credential Dumping indicators
- SAM access
- Credential Manager activity
- Cached credentials
- Suspicious process behavior
- Memory access monitoring
- Sysmon telemetry
- Endpoint detection
- Credential theft investigation
Module 4: Active Directory Credential Detection
- Kerberoasting
- AS-REP Roasting
- Pass-the-Hash
- Pass-the-Ticket
- DCSync
- Golden Ticket
- Silver Ticket
- Privileged account abuse
- Domain Controller monitoring
- Credential attack hunting
Module 5: SIEM Detection and Response
- Event correlation
- Authentication analytics
- Detection rule development
- Alert tuning
- False positive management
- MITRE ATT&CK mapping
- Threat hunting
- Incident escalation
- Credential containment
- Detection case studies
Curso Cybersecurity Incident Response Fundamentals
Visão geral do Curso:
Este curso apresenta os fundamentos de resposta a incidentes de segurança, abordando preparação, detecção, triagem, contenção, erradicação, recuperação e documentação.
Público-alvo:
- Incident Responders
- SOC Analysts
- Blue Team
- Profissionais de Cybersecurity
Pré-requisitos:
- Conhecimentos básicos de redes
- Familiaridade com Windows e Linux
- Conhecimentos de logs
- Noções de SIEM
- Conhecimentos básicos de segurança
Objetivo do Curso:
Após realizar este curso, você será capaz de:
- Estruturar processos de incident response
- Realizar triagem de incidentes
- Apoiar contenção e erradicação
- Documentar investigações
Carga horária sugerida:
24 horas
Conteúdo programático do curso:
Module 1: Incident Response Fundamentals
- Incident response concepts
- Incident lifecycle
- Incident response teams
- Incident classification
- Severity assessment
- Incident response plans
- Roles and responsibilities
- Communication
- Escalation
- Incident response governance
Module 2: Detection and Triage
- Security alerts
- Alert validation
- Incident identification
- Initial triage
- Evidence collection
- IOC identification
- Threat classification
- Incident prioritization
- Investigation scope
- Triage documentation
Module 3: Investigation
- Timeline analysis
- Log investigation
- Endpoint investigation
- Network investigation
- Identity investigation
- Malware indicators
- Credential attacks
- Lateral Movement
- Persistence
- Attack reconstruction
Module 4: Containment
- Containment strategies
- Host isolation
- Account containment
- Network containment
- Credential reset
- Malicious process containment
- Persistence containment
- Short-term containment
- Long-term containment
- Containment validation
Module 5: Eradication and Recovery
- Malware removal
- Persistence removal
- Credential remediation
- Vulnerability remediation
- System recovery
- Identity recovery
- Security control restoration
- Recovery validation
- Monitoring after recovery
- Business continuity
Module 6: Evidence and Documentation
- Evidence handling
- Evidence preservation
- Chain of custody
- Investigation notes
- Timeline documentation
- IOC documentation
- Technical reporting
- Executive reporting
- Incident records
- Lessons learned
Module 7: Incident Response Tools
- SIEM
- EDR
- Network monitoring
- Threat intelligence
- Forensics tools
- Log analysis
- Case management
- Evidence collection tools
- Investigation workflows
- Tool integration
Module 8: Practical Incident Response
- Incident identification
- Initial triage
- Evidence collection
- Investigation
- Containment
- Eradication
- Recovery
- Reporting
- Lessons learned
- Incident response case study
Curso Advanced Incident Response
Visão geral do Curso:
Este curso aprofunda técnicas de investigação e resposta a incidentes complexos, incluindo ataques avançados, comprometimento de identidades, persistência, movimentação lateral e investigação de ameaças.
Público-alvo:
- Incident Responders
- DFIR Professionals
- SOC e Blue Team
- Cybersecurity Professionals
Pré-requisitos:
- Experiência com incident response
- Conhecimentos de Windows e Linux
- Conhecimentos de redes
- Familiaridade com SIEM e EDR
- Conhecimentos básicos de Digital Forensics
Objetivo do Curso:
Após realizar este curso, você será capaz de:
- Investigar incidentes complexos
- Reconstruir cadeias de ataque
- Analisar evidências avançadas
- Conduzir contenção e recuperação
Carga horária sugerida:
32 horas
Conteúdo programático do curso:
Module 1: Advanced Incident Response
- Advanced incident response methodology
- Complex incident scenarios
- Multi-stage attacks
- Advanced threat actors
- Incident scoping
- Investigation prioritization
- Response coordination
- Advanced evidence sources
- Incident command
- Advanced response planning
Module 2: Advanced Threat Investigation
- Attack chain reconstruction
- Timeline analysis
- Threat actor behavior
- Initial Access analysis
- Persistence analysis
- Credential Access
- Privilege Escalation
- Lateral Movement
- Command and Control
- Impact assessment
Module 3: Advanced Identity Investigation
- Identity compromise
- Credential theft
- Kerberos investigation
- NTLM investigation
- Privileged account abuse
- Active Directory compromise
- DCSync indicators
- Golden Ticket investigation
- Authentication timeline
- Identity remediation
Module 4: Endpoint Investigation
- Endpoint telemetry
- Process analysis
- PowerShell investigation
- Persistence mechanisms
- Malware analysis
- EDR investigation
- Memory analysis concepts
- File system investigation
- Registry analysis
- Endpoint compromise assessment
Module 5: Network Investigation
- Network attack analysis
- DNS investigation
- HTTP and HTTPS traffic
- Network connections
- Command and Control
- Lateral Movement
- Network anomalies
- Traffic correlation
- Network containment
- Network evidence analysis
Module 6: Advanced Containment and Eradication
- Enterprise containment
- Identity containment
- Network containment
- Endpoint containment
- Credential revocation
- Persistence eradication
- Threat actor removal
- Security control reinforcement
- Eradication validation
- Recovery planning
Module 7: Threat Intelligence and Attribution
- Threat intelligence
- Threat actor profiling
- Campaign analysis
- IOC enrichment
- TTP analysis
- MITRE ATT&CK
- Intelligence correlation
- Attribution limitations
- Intelligence reporting
- Threat intelligence integration
Module 8: Advanced Incident Simulation
- Complex incident scenario
- Initial triage
- Evidence collection
- Attack reconstruction
- Threat hunting
- Containment
- Eradication
- Recovery
- Executive reporting
- Advanced incident response case study