Curso Windows Incident Response

  • Redes & Infraestrutura de TI

Curso Windows Incident Response

24h
Visão Geral

Este curso apresenta técnicas de investigação e resposta a incidentes especificamente em sistemas Windows, utilizando Event Logs, PowerShell, processos, registro, serviços e demais fontes de evidência.

Objetivo

Após realizar este curso, você será capaz de:

  • Investigar incidentes em Windows
  • Analisar evidências do sistema
  • Identificar persistência e comprometimento
  • Apoiar contenção e recuperação
Publico Alvo
  • Incident Responders
  • SOC Analysts
  • Blue Team
  • Windows Security Professionals
Pre-Requisitos
  • Conhecimentos de Windows
  • Familiaridade com Event Logs
  • Conhecimentos básicos de PowerShell
  • Noções de redes
  • Conhecimentos de incident response
Conteúdo Programatico

Module 1: Windows Incident Response Fundamentals

  1. Windows incident response
  2. Incident lifecycle
  3. Windows attack surface
  4. Evidence sources
  5. Incident triage
  6. Host compromise
  7. User compromise
  8. Security telemetry
  9. Investigation methodology
  10. Response documentation

Module 2: Windows Event Log Investigation

  1. Security Event Logs
  2. System Event Logs
  3. Application logs
  4. PowerShell logs
  5. Authentication events
  6. Account management events
  7. Process creation events
  8. Service events
  9. Event correlation
  10. Timeline construction

Module 3: Process and Execution Investigation

  1. Process analysis
  2. Parent-child relationships
  3. Command-line investigation
  4. PowerShell activity
  5. Script execution
  6. Suspicious processes
  7. LOLBins
  8. Process persistence
  9. EDR telemetry
  10. Execution investigation

Module 4: Credential and Identity Investigation

  1. Credential theft
  2. LSASS activity
  3. Authentication anomalies
  4. Kerberos investigation
  5. NTLM investigation
  6. Privileged account abuse
  7. Pass-the-Hash
  8. Pass-the-Ticket
  9. Credential compromise
  10. Identity remediation

Module 5: Persistence Investigation

  1. Windows persistence
  2. Services
  3. Scheduled Tasks
  4. Registry Run Keys
  5. Startup folders
  6. WMI persistence
  7. Account persistence
  8. PowerShell persistence
  9. Persistence detection
  10. Persistence removal

Module 6: Network and Lateral Movement Investigation

  1. Network connections
  2. DNS activity
  3. SMB
  4. WinRM
  5. Remote Desktop
  6. WMI
  7. Remote services
  8. Lateral Movement indicators
  9. Network containment
  10. Movement investigation

Module 7: Containment and Recovery

  1. Host isolation
  2. Account containment
  3. Credential reset
  4. Malware removal
  5. Persistence removal
  6. System remediation
  7. Recovery
  8. Security validation
  9. Monitoring after recovery
  10. Recovery documentation

Module 8: Practical Windows Incident Response

  1. Incident triage
  2. Event Log analysis
  3. Process investigation
  4. Credential investigation
  5. Persistence investigation
  6. Network investigation
  7. Timeline reconstruction
  8. Containment
  9. Recovery
  10. Windows incident response case study
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas