Visão Geral
Este curso apresenta técnicas de investigação e resposta a incidentes especificamente em sistemas Windows, utilizando Event Logs, PowerShell, processos, registro, serviços e demais fontes de evidência.
Conteúdo Programatico
Module 1: Windows Incident Response Fundamentals
- Windows incident response
- Incident lifecycle
- Windows attack surface
- Evidence sources
- Incident triage
- Host compromise
- User compromise
- Security telemetry
- Investigation methodology
- Response documentation
Module 2: Windows Event Log Investigation
- Security Event Logs
- System Event Logs
- Application logs
- PowerShell logs
- Authentication events
- Account management events
- Process creation events
- Service events
- Event correlation
- Timeline construction
Module 3: Process and Execution Investigation
- Process analysis
- Parent-child relationships
- Command-line investigation
- PowerShell activity
- Script execution
- Suspicious processes
- LOLBins
- Process persistence
- EDR telemetry
- Execution investigation
Module 4: Credential and Identity Investigation
- Credential theft
- LSASS activity
- Authentication anomalies
- Kerberos investigation
- NTLM investigation
- Privileged account abuse
- Pass-the-Hash
- Pass-the-Ticket
- Credential compromise
- Identity remediation
Module 5: Persistence Investigation
- Windows persistence
- Services
- Scheduled Tasks
- Registry Run Keys
- Startup folders
- WMI persistence
- Account persistence
- PowerShell persistence
- Persistence detection
- Persistence removal
Module 6: Network and Lateral Movement Investigation
- Network connections
- DNS activity
- SMB
- WinRM
- Remote Desktop
- WMI
- Remote services
- Lateral Movement indicators
- Network containment
- Movement investigation
Module 7: Containment and Recovery
- Host isolation
- Account containment
- Credential reset
- Malware removal
- Persistence removal
- System remediation
- Recovery
- Security validation
- Monitoring after recovery
- Recovery documentation
Module 8: Practical Windows Incident Response
- Incident triage
- Event Log analysis
- Process investigation
- Credential investigation
- Persistence investigation
- Network investigation
- Timeline reconstruction
- Containment
- Recovery
- Windows incident response case study