Curso Detecção com Windows Event Logs

  • Redes & Infraestrutura de TI

Curso Detecção com Windows Event Logs

24h
Visão Geral

Este curso apresenta os principais Windows Event Logs utilizados na identificação e investigação de atividades suspeitas. O participante aprenderá a interpretar eventos de autenticação, processos, contas, privilégios, serviços e Active Directory, utilizando correlação de eventos e técnicas de threat hunting para identificar comportamentos associados a ataques e comprometimentos.

Objetivo

Após realizar este curso, você será capaz de:

  • Compreender a estrutura dos Windows Event Logs
  • Identificar eventos relevantes para segurança
  • Investigar autenticações e atividades suspeitas
  • Correlacionar eventos de diferentes fontes
  • Desenvolver estratégias básicas de detecção
Publico Alvo
  • Analistas de SOC
  • Profissionais de Blue Team
  • Incident Responders
  • Threat Hunters
  • Administradores Windows
  • Analistas de Cybersecurity
Pre-Requisitos
  • Conhecimentos básicos de Windows
  • Familiaridade com Event Viewer
  • Noções de Active Directory
  • Conhecimentos básicos de autenticação
  • Familiaridade com SIEM é recomendada
Conteúdo Programatico

Module 1: Windows Event Logging Fundamentals

  1. Windows Event Log architecture
  2. Event channels
  3. Event sources
  4. Event IDs
  5. Event levels
  6. Event metadata
  7. Event Viewer
  8. Windows auditing fundamentals
  9. Security log architecture
  10. Event retention and collection

Module 2: Windows Security Auditing

  1. Advanced Audit Policy
  2. Account logon auditing
  3. Logon and logoff auditing
  4. Account management auditing
  5. Object access auditing
  6. Policy change auditing
  7. Privilege use auditing
  8. System event auditing
  9. Process tracking
  10. Audit policy configuration

Module 3: Authentication and Account Events

  1. Successful logon events
  2. Failed authentication events
  3. Account logon events
  4. Logoff events
  5. Special privilege assignment
  6. Account creation and deletion
  7. Password changes
  8. Group membership changes
  9. Privileged account activity
  10. Authentication event correlation

Module 4: Process, Service and System Events

  1. Process creation events
  2. Process termination
  3. Parent-child process relationships
  4. Service installation events
  5. Service modification
  6. Scheduled task activity
  7. PowerShell logging
  8. Script execution monitoring
  9. System configuration changes
  10. Suspicious process detection

Module 5: Active Directory Security Events

  1. Domain authentication events
  2. Kerberos authentication events
  3. NTLM authentication events
  4. Directory Service events
  5. Account modifications
  6. Group modifications
  7. Privileged group changes
  8. Domain Controller monitoring
  9. Replication-related events
  10. Active Directory event correlation

Module 6: Credential Access and Lateral Movement Detection

  1. Credential access indicators
  2. LSASS-related activity
  3. Suspicious authentication patterns
  4. Pass-the-Hash indicators
  5. Pass-the-Ticket indicators
  6. Remote logon analysis
  7. Administrative share activity
  8. Lateral movement indicators
  9. Privilege escalation indicators
  10. Attack chain reconstruction

Module 7: Detection Engineering and Threat Hunting

  1. Event correlation
  2. Detection rule development
  3. Behavioral indicators
  4. Baseline creation
  5. Authentication anomaly detection
  6. Privilege escalation detection
  7. Lateral movement detection
  8. Credential access detection
  9. Threat hunting workflows
  10. Detection validation

Module 8: SIEM Integration and Practical Investigation

  1. Windows log forwarding
  2. SIEM ingestion
  3. Log normalization
  4. Search and correlation
  5. Detection dashboards
  6. Investigation timelines
  7. Incident investigation workflow
  8. Evidence preservation
  9. Security incident reporting
  10. Practical Windows Event Log investigation cases
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas