Visão Geral
Este curso aborda técnicas de movimentação lateral em ambientes corporativos, com foco em Windows, Active Directory, autenticação, credenciais, administração remota, detecção e medidas defensivas.
Conteúdo Programatico
Module 1: Lateral Movement Fundamentals
- Lateral Movement concepts
- Attack chain and movement phases
- Internal reconnaissance
- Trust relationships
- Credential reuse
- Privileged access paths
- Remote administration
- Lateral Movement attack surface
- Detection opportunities
- Defensive strategies
Module 2: Windows Remote Services
- Server Message Block
- Windows Remote Management
- Remote Desktop Services
- Remote Service administration
- Windows Management Instrumentation
- Remote PowerShell
- Administrative shares
- Remote service authentication
- Service-based movement detection
- Remote service hardening
Module 3: Credential-Based Movement
- Credential reuse
- Pass-the-Hash
- Pass-the-Ticket
- NTLM authentication
- Kerberos authentication
- Credential exposure
- Privileged credentials
- Authentication monitoring
- Credential-based detection
- Credential protection
Module 4: Active Directory Lateral Movement
- Domain enumeration
- Privileged group discovery
- Domain Controller identification
- Trust relationships
- Service account discovery
- Administrative relationships
- Delegation risks
- Attack path analysis
- Active Directory monitoring
- Lateral Movement prevention
Module 5: Detection and Monitoring
- Windows Event Logs
- Authentication events
- Process creation
- Remote service events
- Network connections
- PowerShell logging
- Sysmon telemetry
- SIEM correlation
- MITRE ATT&CK mapping
- Detection rule development
Module 6: Defensive Controls
- Least privilege
- Administrative tiering
- Network segmentation
- Credential Guard
- Protected Users
- LAPS
- Remote service restrictions
- Privileged Access Workstations
- Authentication hardening
- Lateral Movement prevention
Module 7: Threat Hunting
- Lateral Movement indicators
- Authentication hunting
- Remote service hunting
- Privileged account hunting
- Suspicious network activity
- Credential reuse indicators
- Endpoint telemetry
- SIEM hunting queries
- Attack path reconstruction
- Threat hunting documentation
Module 8: Practical Lateral Movement Analysis
- Internal reconnaissance
- Credential-based access assessment
- Remote service analysis
- Active Directory attack path analysis
- Authentication investigation
- Event Log analysis
- SIEM investigation
- Defensive control validation
- Incident response workflow
- Lateral Movement case studies