Curso Threat Detection & Response

  • Redes & Infraestrutura de TI

Curso Threat Detection & Response

24h
Visão Geral

Este curso aborda o ciclo completo de detecção e resposta a ameaças, desde a identificação de indicadores até investigação, contenção, erradicação e recuperação.

Objetivo

Após realizar este curso, você será capaz de:

  • Desenvolver processos de detecção
  • Investigar ameaças
  • Realizar contenção inicial
  • Apoiar respostas a incidentes
Publico Alvo
  • Analistas de SOC
  • Blue Team
  • Incident Responders
  • Profissionais de Cybersecurity
Pre-Requisitos
  • Conhecimentos de redes
  • Familiaridade com Windows e Linux
  • Conhecimentos básicos de SIEM
  • Noções de incident response
  • Familiaridade com logs
Conteúdo Programatico

Module 1: Threat Detection Fundamentals

  1. Threat detection concepts
  2. Detection lifecycle
  3. Indicators of Compromise
  4. Indicators of Attack
  5. Behavioral detection
  6. Detection coverage
  7. Detection maturity
  8. Threat intelligence
  9. Detection engineering
  10. Detection validation

Module 2: Security Telemetry

  1. Windows Event Logs
  2. Linux logs
  3. Network telemetry
  4. Endpoint telemetry
  5. Authentication logs
  6. DNS telemetry
  7. Proxy logs
  8. Cloud telemetry
  9. Log normalization
  10. Telemetry quality

Module 3: Detection Engineering

  1. Detection rule design
  2. Behavioral analytics
  3. Correlation rules
  4. Threshold-based detection
  5. Signature-based detection
  6. Anomaly detection
  7. Detection tuning
  8. False positive reduction
  9. Detection testing
  10. Detection lifecycle management

Module 4: Threat Investigation

  1. Alert triage
  2. Event correlation
  3. Timeline analysis
  4. IOC investigation
  5. Endpoint investigation
  6. Network investigation
  7. Identity investigation
  8. Attack path reconstruction
  9. Threat classification
  10. Investigation reporting

Module 5: Credential and Identity Threats

  1. Password attacks
  2. Credential Dumping
  3. Kerberoasting
  4. Pass-the-Hash
  5. Pass-the-Ticket
  6. DCSync
  7. Privileged account abuse
  8. Authentication anomalies
  9. Identity detection
  10. Credential threat response

Module 6: Malware and Endpoint Threats

  1. Malware indicators
  2. Suspicious processes
  3. Command execution
  4. Persistence indicators
  5. Defense Evasion indicators
  6. Endpoint telemetry
  7. EDR investigation
  8. Malware containment
  9. Malware eradication
  10. Endpoint recovery

Module 7: Incident Response

  1. Incident triage
  2. Incident classification
  3. Containment
  4. Eradication
  5. Recovery
  6. Evidence preservation
  7. Threat actor tracking
  8. Incident communication
  9. Post-incident analysis
  10. Response improvement

Module 8: Practical Detection and Response

  1. Detection rule development
  2. SIEM investigation
  3. Endpoint investigation
  4. Credential attack detection
  5. Malware detection
  6. Attack timeline reconstruction
  7. Containment exercise
  8. Incident response simulation
  9. Detection validation
  10. Threat detection case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas