Visão Geral
Este curso apresenta os conceitos de Credential Dumping em ambientes Windows, abordando mecanismos de armazenamento de credenciais, exposição de material de autenticação, principais técnicas utilizadas por adversários e métodos de detecção e mitigação. O conteúdo é orientado à análise defensiva, threat hunting e resposta a incidentes.
Conteúdo Programatico
Module 1: Credential Dumping Fundamentals
- Credential dumping concepts
- Credential Access lifecycle
- Authentication material
- Credential exposure
- Password hashes
- Authentication tokens
- Session credentials
- Local and domain credentials
- Privileged credentials
- Credential theft risks
Module 2: Windows Credential Storage
- LSASS memory
- SAM database
- NTDS.dit
- Cached credentials
- Windows Credential Manager
- Windows secrets
- Registry-based credentials
- Service account credentials
- Application credentials
- Credential protection mechanisms
Module 3: Credential Dumping Techniques
- Memory-based credential access
- Local credential extraction concepts
- Domain credential exposure
- Credential database access
- Cached credential access
- Stored credential access
- Token-related credential exposure
- Privileged process access
- Credential dumping indicators
- Attack prerequisites
Module 4: Credential Access and Active Directory
- Domain credential exposure
- Domain Controller targeting
- NTDS.dit risks
- DCSync concepts
- Replication privilege abuse
- Privileged account compromise
- Credential reuse
- Lateral movement
- Domain compromise indicators
- Active Directory credential protection
Module 5: Detection and Telemetry
- Credential access telemetry
- Process creation monitoring
- Process access monitoring
- Authentication events
- Privileged activity
- Windows Event Logs
- Endpoint Detection and Response
- SIEM correlation
- Behavioral indicators
- Detection engineering
Module 6: Threat Hunting
- Credential Access hunting
- Suspicious process analysis
- Abnormal authentication analysis
- Privileged account hunting
- LSASS access hunting
- NTDS-related activity
- Credential exposure indicators
- Lateral movement hunting
- Attack chain reconstruction
- Hunt validation
Module 7: Prevention and Hardening
- Credential Guard
- Local Administrator Password Solution
- Privileged Access Management
- Administrative tiering
- Least privilege
- Protected Process Light
- Credential isolation
- Domain Controller hardening
- Endpoint security controls
- Credential protection policies
Module 8: Incident Response and Practical Investigation
- Credential dumping incident identification
- Compromised endpoint assessment
- Credential exposure analysis
- Account compromise investigation
- Lateral movement assessment
- Credential rotation
- Endpoint containment
- Domain security assessment
- Recovery procedures
- Practical credential dumping investigation cases