Curso Event Logs

  • Redes & Infraestrutura de TI

Curso Event Logs

24h
Visão Geral

Este curso apresenta os Windows Event Logs como fonte essencial de telemetria para administração, segurança, investigação e resposta a incidentes. O participante aprenderá a compreender os principais logs, identificar eventos relevantes, realizar correlação e utilizar os registros em atividades de threat hunting e troubleshooting.

Objetivo

Após realizar este curso, você será capaz de:

  • Compreender a estrutura dos Event Logs
  • Identificar eventos de segurança relevantes
  • Correlacionar eventos
  • Investigar atividades suspeitas
  • Utilizar logs em troubleshooting e incident response
Publico Alvo
  • Analistas de SOC
  • Analistas de Cybersecurity
  • Administradores Windows
  • Incident Responders
  • Threat Hunters
Pre-Requisitos
  • Conhecimentos de Windows
  • Familiaridade com Active Directory
  • Noções de segurança de endpoints
  • Conhecimentos básicos de PowerShell
  • Conhecimentos de auditoria Windows são recomendados
Conteúdo Programatico

Module 1: Windows Event Log Fundamentals

  1. Windows Event Log architecture
  2. Event channels
  3. Event providers
  4. Event IDs
  5. Event levels
  6. Event sources
  7. Event metadata
  8. Event timestamps
  9. Log retention
  10. Event Log management

Module 2: Security Event Logs

  1. Security event log
  2. Authentication events
  3. Account management events
  4. Privileged activity
  5. Process creation events
  6. Policy changes
  7. Object access
  8. Service activity
  9. System events
  10. Security event interpretation

Module 3: Active Directory Event Logs

  1. Domain Controller events
  2. Kerberos authentication events
  3. NTLM authentication events
  4. Account changes
  5. Group membership changes
  6. Directory service events
  7. Replication events
  8. Group Policy events
  9. Privileged activity
  10. Active Directory event analysis

Module 4: Event Log Analysis

  1. Event filtering
  2. Event correlation
  3. Timeline analysis
  4. Source and destination analysis
  5. User activity analysis
  6. Process activity analysis
  7. Authentication analysis
  8. Suspicious event identification
  9. Baseline comparison
  10. Investigation methodology

Module 5: Event Logs for Threat Detection

  1. Credential Access indicators
  2. Privilege Escalation indicators
  3. Lateral Movement indicators
  4. Persistence indicators
  5. Defense Evasion indicators
  6. Account compromise indicators
  7. Suspicious PowerShell activity
  8. Remote authentication monitoring
  9. Detection engineering
  10. Threat hunting

Module 6: Event Collection and SIEM

  1. Centralized event collection
  2. Windows Event Forwarding
  3. Log aggregation
  4. SIEM integration
  5. Event normalization
  6. Log parsing
  7. Correlation rules
  8. Alert generation
  9. Log retention strategies
  10. Security monitoring architecture

Module 7: Troubleshooting with Event Logs

  1. Authentication troubleshooting
  2. Group Policy troubleshooting
  3. Service failures
  4. Application errors
  5. Network-related events
  6. Domain Controller troubleshooting
  7. Replication troubleshooting
  8. Security configuration issues
  9. Event-based diagnostics
  10. Troubleshooting methodology

Module 8: Practical Event Log Investigation

  1. Security event investigation
  2. Authentication timeline reconstruction
  3. Privileged activity investigation
  4. Suspicious process analysis
  5. Lateral Movement investigation
  6. Active Directory event analysis
  7. SIEM correlation exercise
  8. Threat hunting exercise
  9. Incident response workflow
  10. Practical Windows Event Log cases
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas