Visão Geral
Este curso apresenta o protocolo NTLM, seu funcionamento, componentes de autenticação e utilização em ambientes Windows. O participante compreenderá o processo challenge-response, hashes, sessões, limitações de segurança e os principais riscos relacionados ao uso do NTLM, incluindo Pass-the-Hash e movimentação lateral.
Conteúdo Programatico
Module 1: NTLM Authentication Fundamentals
- NTLM authentication architecture
- Challenge-response authentication
- NTLM authentication flow
- NTLM credentials
- Password hash concepts
- Authentication challenges
- Authentication responses
- Session establishment
- Local authentication
- Domain authentication
Module 2: NTLM Protocol Architecture
- NTLM message structure
- Negotiate messages
- Challenge messages
- Authenticate messages
- Session security
- Authentication flags
- Security parameters
- NTLM protocol negotiation
- Client-server authentication
- Protocol limitations
Module 3: NTLM Credentials and Hashes
- Password hashing
- NT hashes
- Credential material
- Password verification
- Credential storage
- Credential exposure
- Local account credentials
- Domain account credentials
- Credential protection
- Password security
Module 4: NTLM in Active Directory
- NTLM and Domain Controllers
- Domain authentication
- NTLM fallback scenarios
- Legacy application compatibility
- SMB authentication
- Remote authentication
- Service authentication
- NTLM trust relationships
- NTLM usage monitoring
- NTLM security considerations
Module 5: NTLM Attack Techniques
- Pass-the-Hash fundamentals
- Credential reuse
- NTLM relay concepts
- Credential interception risks
- Authentication forwarding
- Lateral movement
- Privileged account abuse
- NTLM-based attack indicators
- Attack prerequisites
- Defensive considerations
Module 6: NTLM Detection and Monitoring
- NTLM authentication events
- Logon monitoring
- Source and destination analysis
- Authentication anomalies
- NTLM usage baselining
- Privileged authentication monitoring
- Event correlation
- Network telemetry
- Threat hunting
- Detection engineering
Module 7: NTLM Hardening
- NTLM reduction strategies
- Restricting NTLM usage
- Credential Guard
- SMB security
- LDAP signing considerations
- Extended Protection
- Privileged account protection
- Least privilege
- Legacy application assessment
- NTLM security baseline
Module 8: Practical NTLM Security Analysis
- NTLM authentication investigation
- Authentication flow analysis
- Suspicious NTLM activity
- Pass-the-Hash indicators
- Relay attack indicators
- Lateral movement investigation
- NTLM reduction assessment
- Security configuration review
- Incident response
- Practical NTLM security case studies