Advanced Threat Hunting on Active Directory

Advanced Threat Hunting on Active Directory

34mAdvanced2024-08-23

Authors

Laurentiu Gabriel Raducu

Laurentiu Gabriel Raducu

Course details

Active Directory is a widely used directory service on Windows servers, managing user and resource permissions and enabling efficient network organization. In this course, experienced instructor and software developer Laurentiu Gabriel Raducu guides you through the nuances of Active Directory, emphasizing its critical role in network security. Learn the basics of Active Directory and build your understanding of its structure and common vulnerabilities. Delve into more complex aspects, such as how to spot unusual activity that could indicate a breach or an ongoing attack. Plus, explore essential tools and techniques used in threat hunting, including how to analyze logs, monitor network traffic, and use advanced querying to detect anomalies. When you complete this course, you'll be well-equipped to proactively search for potential threats in AD environments, respond effectively to identified risks, and strengthen your network's defenses against future attacks.

Skills covered

Active DirectoryMicrosoft Entra ID (Azure Active Directory)Incident ResponseNetwork AdministrationCybersecurityNetwork and System AdministrationMicrosoftOne-Off

Concepts

Introduction

  • Introduction to threat hunting in Active Directory

Active Directory

  • Understanding Active Directory - Architecture and components
  • What are the key Active Directory services and roles
  • Getting to know the Active Directory security model

Threat Hunting

  • Understanding the essentials of threat hunting
  • Getting familiar with the threat hunting process
  • Tools and techniques for effective threat hunting

Threat Hunting in Active Directory

  • Auditing and monitoring AD for signs of compromise
  • Analyzing AD logs and events
  • Uncovering lateral movement and privilege escalation
  • Discovering common Kerberos attack techniques
  • Detecting and responding to malicious GPO activities

Conclusion

  • Next steps
40,000 Toman