Curso Threat Hunting with SIEM

  • Redes & Infraestrutura de TI

Curso Threat Hunting with SIEM

24h
Visão Geral

Este curso apresenta técnicas de Threat Hunting utilizando plataformas SIEM para coleta, correlação, investigação e detecção de comportamentos maliciosos.

Objetivo

Após realizar este curso, você será capaz de:

  • Criar hunts em SIEM
  • Desenvolver consultas de investigação
  • Correlacionar eventos
  • Transformar hunts em detecções
Publico Alvo
  • Threat Hunters
  • SOC Analysts
  • Detection Engineers
  • Blue Team
Pre-Requisitos
  • Conhecimentos de Threat Hunting
  • Familiaridade com SIEM
  • Conhecimentos de logs
  • Noções de redes
  • Familiaridade com Windows Event Logs
Conteúdo Programatico

Module 1: SIEM-Based Threat Hunting

  1. SIEM architecture
  2. Threat hunting workflows
  3. SIEM data sources
  4. Log ingestion
  5. Event normalization
  6. Search methodology
  7. Hunt hypotheses
  8. Investigation workflows
  9. Hunt documentation
  10. SIEM hunting strategy

Module 2: Query Development

  1. Query fundamentals
  2. Search filters
  3. Field analysis
  4. Time-based queries
  5. Aggregation
  6. Statistical analysis
  7. Pattern matching
  8. Query optimization
  9. Query validation
  10. Reusable hunting queries

Module 3: Authentication Hunting

  1. Login events
  2. Failed authentication
  3. Password Spraying
  4. Brute Force
  5. Privileged authentication
  6. Geographic anomalies
  7. Impossible travel concepts
  8. Service account activity
  9. Authentication correlation
  10. Identity threat hunting

Module 4: Endpoint Hunting

  1. Process creation
  2. Command-line activity
  3. PowerShell
  4. Suspicious processes
  5. Services
  6. Scheduled Tasks
  7. Registry activity
  8. Malware indicators
  9. Endpoint correlation
  10. Endpoint threat hunting

Module 5: Network Hunting

  1. Network connections
  2. DNS queries
  3. Suspicious domains
  4. Command and Control
  5. Beaconing
  6. Port scanning
  7. Lateral Movement
  8. Data exfiltration
  9. Network correlation
  10. Network threat hunting

Module 6: Active Directory Hunting

  1. Kerberos events
  2. NTLM events
  3. Privileged group changes
  4. DCSync indicators
  5. Kerberoasting
  6. Pass-the-Hash
  7. Pass-the-Ticket
  8. Domain Controller activity
  9. Identity correlation
  10. Active Directory hunting

Module 7: Detection Engineering

  1. Hunt-to-detection conversion
  2. Detection rules
  3. Correlation rules
  4. Threshold detection
  5. Behavioral detection
  6. Detection tuning
  7. False positive reduction
  8. MITRE ATT&CK mapping
  9. Detection validation
  10. Detection lifecycle

Module 8: Practical SIEM Threat Hunting

  1. Hunt hypothesis creation
  2. Query development
  3. Authentication hunting
  4. Endpoint hunting
  5. Network hunting
  6. Active Directory hunting
  7. Attack chain correlation
  8. Detection development
  9. Hunt reporting
  10. SIEM threat hunting case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas