Visão Geral
Este curso apresenta técnicas de Threat Hunting utilizando plataformas SIEM para coleta, correlação, investigação e detecção de comportamentos maliciosos.
Conteúdo Programatico
Module 1: SIEM-Based Threat Hunting
- SIEM architecture
- Threat hunting workflows
- SIEM data sources
- Log ingestion
- Event normalization
- Search methodology
- Hunt hypotheses
- Investigation workflows
- Hunt documentation
- SIEM hunting strategy
Module 2: Query Development
- Query fundamentals
- Search filters
- Field analysis
- Time-based queries
- Aggregation
- Statistical analysis
- Pattern matching
- Query optimization
- Query validation
- Reusable hunting queries
Module 3: Authentication Hunting
- Login events
- Failed authentication
- Password Spraying
- Brute Force
- Privileged authentication
- Geographic anomalies
- Impossible travel concepts
- Service account activity
- Authentication correlation
- Identity threat hunting
Module 4: Endpoint Hunting
- Process creation
- Command-line activity
- PowerShell
- Suspicious processes
- Services
- Scheduled Tasks
- Registry activity
- Malware indicators
- Endpoint correlation
- Endpoint threat hunting
Module 5: Network Hunting
- Network connections
- DNS queries
- Suspicious domains
- Command and Control
- Beaconing
- Port scanning
- Lateral Movement
- Data exfiltration
- Network correlation
- Network threat hunting
Module 6: Active Directory Hunting
- Kerberos events
- NTLM events
- Privileged group changes
- DCSync indicators
- Kerberoasting
- Pass-the-Hash
- Pass-the-Ticket
- Domain Controller activity
- Identity correlation
- Active Directory hunting
Module 7: Detection Engineering
- Hunt-to-detection conversion
- Detection rules
- Correlation rules
- Threshold detection
- Behavioral detection
- Detection tuning
- False positive reduction
- MITRE ATT&CK mapping
- Detection validation
- Detection lifecycle
Module 8: Practical SIEM Threat Hunting
- Hunt hypothesis creation
- Query development
- Authentication hunting
- Endpoint hunting
- Network hunting
- Active Directory hunting
- Attack chain correlation
- Detection development
- Hunt reporting
- SIEM threat hunting case studies