Curso Windows Threat Hunting

  • Redes & Infraestrutura de TI

Curso Windows Threat Hunting

24h
Visão Geral

Este curso apresenta técnicas de Threat Hunting em ambientes Windows, utilizando logs, telemetria de endpoints, processos, PowerShell, autenticação e indicadores comportamentais.

Objetivo

Após realizar este curso, você será capaz de:

  • Realizar Threat Hunting em Windows
  • Analisar eventos e telemetria
  • Identificar comportamentos suspeitos
  • Criar hipóteses de investigação
Publico Alvo
  • Threat Hunters
  • SOC Analysts
  • Blue Team
  • Incident Responders
Pre-Requisitos
  • Conhecimentos de Windows
  • Familiaridade com PowerShell
  • Conhecimentos de Windows Event Logs
  • Noções de SIEM
  • Conhecimentos básicos de redes
Conteúdo Programatico

Module 1: Windows Threat Hunting Fundamentals

  1. Threat Hunting concepts
  2. Hunt lifecycle
  3. Threat hypotheses
  4. Windows attack surface
  5. Behavioral indicators
  6. Indicators of Compromise
  7. Indicators of Attack
  8. Hunt planning
  9. Hunt documentation
  10. Threat hunting maturity

Module 2: Windows Telemetry

  1. Windows Event Logs
  2. Security logs
  3. System logs
  4. PowerShell logs
  5. Sysmon
  6. Process telemetry
  7. Network telemetry
  8. Authentication telemetry
  9. Registry telemetry
  10. Telemetry collection

Module 3: Process and Execution Hunting

  1. Process creation
  2. Parent-child relationships
  3. Suspicious command execution
  4. PowerShell activity
  5. Windows scripting
  6. LOLBins
  7. Command-line analysis
  8. Execution anomalies
  9. Process-based detection
  10. Process hunting methodology

Module 4: Credential Attack Hunting

  1. Credential Dumping indicators
  2. LSASS access
  3. Password attack indicators
  4. Kerberos anomalies
  5. NTLM anomalies
  6. Pass-the-Hash
  7. Pass-the-Ticket
  8. Credential theft patterns
  9. Authentication hunting
  10. Credential attack investigation

Module 5: Persistence and Privilege Hunting

  1. Windows persistence
  2. Scheduled tasks
  3. Services
  4. Registry persistence
  5. Startup locations
  6. Privilege escalation indicators
  7. Administrative activity
  8. Privileged account abuse
  9. Persistence hunting
  10. Privilege hunting

Module 6: Lateral Movement Hunting

  1. Lateral Movement concepts
  2. SMB activity
  3. WinRM activity
  4. Remote Desktop
  5. WMI activity
  6. Remote service execution
  7. Authentication patterns
  8. Network-based indicators
  9. Lateral Movement detection
  10. Movement investigation

Module 7: SIEM-Based Windows Hunting

  1. SIEM search methodology
  2. Query development
  3. Event correlation
  4. Time-based investigation
  5. Host-based investigation
  6. User-based investigation
  7. IOC-based hunting
  8. Behavioral hunting
  9. Detection rule conversion
  10. Hunt reporting

Module 8: Practical Windows Threat Hunting

  1. Hunt hypothesis creation
  2. Event Log investigation
  3. Process hunting
  4. PowerShell hunting
  5. Credential attack hunting
  6. Persistence hunting
  7. Lateral Movement hunting
  8. SIEM investigation
  9. Threat timeline reconstruction
  10. Windows threat hunting case studies
TENHO INTERESSE

Cursos Relacionados

Curso CISCO CCNA Exame CCNA 200-125

40 horas

Curso SAP BASIS S4hana - Administração e Infraestrutura

40 horas

Curso MCSA Networking with Windows Server 2016

40 horas

Curso CCNP Route 300-101 Preparatório Para Certificação

40 horas

Curso Cloudera Cientista de Dados

32 horas

Curso VMware Instalando Configurando e Gerenciando vSphere

32 horas

Curso de Redes TCP/IP - Protocolo de Redes de Computadores

40 horas

Curso Cisco Switched Networks 300-115

40 horas

Curso Wireless LAN Foundations

16 horas

Curso Certified Network Defender Certification

40 horas