Visão Geral
Este curso apresenta os principais Windows Event Logs utilizados na identificação e investigação de atividades suspeitas. O participante aprenderá a interpretar eventos de autenticação, processos, contas, privilégios, serviços e Active Directory, utilizando correlação de eventos e técnicas de threat hunting para identificar comportamentos associados a ataques e comprometimentos.
Conteúdo Programatico
Module 1: Windows Event Logging Fundamentals
- Windows Event Log architecture
- Event channels
- Event sources
- Event IDs
- Event levels
- Event metadata
- Event Viewer
- Windows auditing fundamentals
- Security log architecture
- Event retention and collection
Module 2: Windows Security Auditing
- Advanced Audit Policy
- Account logon auditing
- Logon and logoff auditing
- Account management auditing
- Object access auditing
- Policy change auditing
- Privilege use auditing
- System event auditing
- Process tracking
- Audit policy configuration
Module 3: Authentication and Account Events
- Successful logon events
- Failed authentication events
- Account logon events
- Logoff events
- Special privilege assignment
- Account creation and deletion
- Password changes
- Group membership changes
- Privileged account activity
- Authentication event correlation
Module 4: Process, Service and System Events
- Process creation events
- Process termination
- Parent-child process relationships
- Service installation events
- Service modification
- Scheduled task activity
- PowerShell logging
- Script execution monitoring
- System configuration changes
- Suspicious process detection
Module 5: Active Directory Security Events
- Domain authentication events
- Kerberos authentication events
- NTLM authentication events
- Directory Service events
- Account modifications
- Group modifications
- Privileged group changes
- Domain Controller monitoring
- Replication-related events
- Active Directory event correlation
Module 6: Credential Access and Lateral Movement Detection
- Credential access indicators
- LSASS-related activity
- Suspicious authentication patterns
- Pass-the-Hash indicators
- Pass-the-Ticket indicators
- Remote logon analysis
- Administrative share activity
- Lateral movement indicators
- Privilege escalation indicators
- Attack chain reconstruction
Module 7: Detection Engineering and Threat Hunting
- Event correlation
- Detection rule development
- Behavioral indicators
- Baseline creation
- Authentication anomaly detection
- Privilege escalation detection
- Lateral movement detection
- Credential access detection
- Threat hunting workflows
- Detection validation
Module 8: SIEM Integration and Practical Investigation
- Windows log forwarding
- SIEM ingestion
- Log normalization
- Search and correlation
- Detection dashboards
- Investigation timelines
- Incident investigation workflow
- Evidence preservation
- Security incident reporting
- Practical Windows Event Log investigation cases