Visão Geral
Este curso apresenta os fundamentos de Threat Hunting, abordando hipóteses de investigação, telemetria, indicadores, comportamento adversário, análise de eventos e transformação de hunts em mecanismos de detecção.
Conteúdo Programatico
Module 1: Threat Hunting Fundamentals
- Threat Hunting concepts
- Proactive security
- Hunt lifecycle
- Threat hypotheses
- Hunt objectives
- Threat intelligence
- Behavioral indicators
- Indicators of Compromise
- Hunt prioritization
- Hunt documentation
Module 2: Threat Hunting Data Sources
- Windows Event Logs
- Linux logs
- Network telemetry
- Endpoint telemetry
- DNS logs
- Authentication logs
- Cloud telemetry
- Application logs
- SIEM data
- Telemetry quality
Module 3: Hunt Hypothesis Development
- Threat-driven hypotheses
- Intelligence-driven hypotheses
- Behavior-based hypotheses
- Attack technique hypotheses
- Risk-based hunting
- Hypothesis validation
- Hunt scope
- Investigation criteria
- Evidence requirements
- Hunt planning
Module 4: Investigation Techniques
- IOC analysis
- Behavioral analysis
- Event correlation
- Timeline analysis
- User-based hunting
- Host-based hunting
- Network-based hunting
- Identity-based hunting
- Attack path analysis
- Investigation documentation
Module 5: MITRE ATT&CK and Threat Hunting
- MITRE ATT&CK fundamentals
- Tactics
- Techniques
- Sub-techniques
- Technique-based hunting
- ATT&CK data sources
- ATT&CK detection opportunities
- Threat actor TTPs
- Hunt-to-detection mapping
- ATT&CK-based reporting
Module 6: Detection Engineering
- Detection rule development
- Hunt findings
- Detection logic
- Correlation rules
- Detection tuning
- False positive management
- Detection validation
- Detection coverage
- Hunt automation
- Detection lifecycle
Module 7: Threat Hunting Operations
- Hunt scheduling
- Hunt prioritization
- Investigation workflows
- Collaboration
- Case management
- Hunt metrics
- Findings management
- Intelligence integration
- Continuous hunting
- Threat hunting maturity
Module 8: Practical Threat Hunting
- Hunt hypothesis creation
- Data source identification
- IOC investigation
- Behavioral hunting
- ATT&CK-based hunting
- SIEM investigation
- Timeline reconstruction
- Detection development
- Hunt reporting
- Threat hunting case studies