Visão Geral
Este curso apresenta o Kerberoasting e sua relação com Service Principal Names (SPNs), contas de serviço e autenticação Kerberos. O participante compreenderá os fundamentos da técnica, os fatores que aumentam a exposição, indicadores de detecção e estratégias de proteção de contas de serviço e ambientes Active Directory.
Conteúdo Programatico
Module 1: Kerberoasting Fundamentals
- Kerberoasting concepts
- Kerberos service authentication
- Service Principal Names
- Service accounts
- Service tickets
- Ticket encryption
- Credential exposure
- Attack prerequisites
- Security implications
- Kerberoasting attack lifecycle
Module 2: Service Principal Names
- SPN architecture
- SPN registration
- SPN uniqueness
- Service account association
- Computer-based SPNs
- Custom service SPNs
- SPN enumeration concepts
- Misconfigured SPNs
- Privileged service accounts
- SPN security assessment
Module 3: Service Ticket Security
- TGS-REQ and TGS-REP
- Service ticket generation
- Ticket encryption types
- Kerberos cryptographic material
- Service authentication
- Ticket request patterns
- Service account password security
- Weak credential risks
- Ticket security
- Service account exposure
Module 4: Kerberoasting Detection
- Kerberos service ticket monitoring
- TGS request analysis
- Unusual service ticket requests
- Request volume analysis
- Account behavior analysis
- Source host analysis
- Privileged account monitoring
- Windows Event Logs
- SIEM correlation
- Detection engineering
Module 5: Service Account Hardening
- Strong service account passwords
- Managed Service Accounts
- Group Managed Service Accounts
- Privileged service account protection
- Least privilege
- SPN management
- Account rotation
- Service account inventory
- Legacy service assessment
- Service account security baseline
Module 6: Threat Hunting
- Kerberoasting hunting methodology
- Suspicious TGS requests
- Service account activity
- Authentication baselining
- Privileged account behavior
- Source system analysis
- Ticket request anomalies
- Active Directory hunting
- Attack chain analysis
- Hunt validation
Module 7: Incident Response
- Kerberoasting incident identification
- Suspicious ticket investigation
- Compromised service account assessment
- Privilege analysis
- Lateral movement assessment
- Credential rotation
- Service account remediation
- Persistence investigation
- Domain security assessment
- Recovery procedures
Module 8: Practical Kerberoasting Analysis
- SPN inventory exercise
- Service account risk assessment
- Kerberos event analysis
- TGS request investigation
- Suspicious authentication scenario
- Detection rule development
- Hardening assessment
- Incident investigation workflow
- Security control validation
- Practical Kerberoasting case studies