Seminarinhalt
Programm
1. Password based attacks
2. NTLM related attacks
3. Kerberos related attacks
4. NGC / Shadow credentials
5. AD objects privilege abuse
6. Active Directory domain and forest trust abuse
7. DPAPI related attacks
8. Other: DCSync, DCShadow, SDAdmin holder
Module 2: Monitoring and Defending AD
1. Auditing AD objects ACL’s
2. Advanced Events monitoring
3. Detection of IoC and IoA
4. Preventing lateral movement:
5. Hardening with GPO
6. Semi-automatic auditing
Module 3: Incident Response in AD
1. Preparation: Toolkits, resources, techniques, skills
2. Detection and analysis
3. Containment in AD environment
4. Eradication:
5. Recovery
6. Lesson learns and processing changes in AD environment
Module 4: Beyond Active Directory Directory Services
1. Beyond Active Directory Directory Services
2. AD Certification Services
3. AD Federation Services
Zielgruppen
- Security architects
- Active Directory administrators
- security administrators
- security auditors
- and other people responsible for implementing secure identity.
Vorkenntnisse
- To attend this training, attendees should have a good hands-on experience with Active Directory Domain Services (AD DS) administration.