Masterclass: Threat Hunting with AI
- Kursuskode TAI
- Varighed 3 dage
Leveringsmetoder
Go to:
Leveringsmetoder
Kurset er tilgængeligt i følgende formater:
-
Åbent kursus (Virtuelt)
Live klasserumsundervisning du tilgår virtuelt
Anmod om dette kursus Med en anden leveringsløsning
Beskrivelse
ToppenKursusdato
ToppenMålgruppe
ToppenKursets formål
Toppen- Understand modern attack techniques and how they are executed and detected
- Identify and investigate privilege escalation and identity-based attacks
- Understand Windows authentication architecture and common exploitation paths
- Apply structured investigation methods using real-world case studies
- Use Microsoft Defender for Endpoint (EDR) for threat detection and hunting
- Detect and analyze attacks on identity infrastructure
- Perform basic network, memory, and disk forensic analysis
- Leverage Microsoft Sentinel and Security Copilot in threat detection and investigation
- Combine manual and AI-assisted methods to improve threat hunting and response
Kursusindhold
Toppen- Module 1: Modern Attack Techniques and Tracing Them
- Module 2: Local Privilege Escalation Techniques and Tracing Them
- Module 3: Case Study – Investigating In-Place Attacks
- Module 4: Windows Authentication Architecture & Cryptography
- Module 5: Case Study – Investigating Identity Theft
- Module 6: Attacks on Identity Infrastructure and Tracing Them
- Module 7: Microsoft 365 Defender for Endpoint (EDR)
- Module 8: Security Operations with Microsoft EDR (Defender for Endpoint) – Advanced Threat Hunting with Defender
- Module 9: Microsoft Security Copilot
- Module 10: Case Study – Detecting a Complex Threat with Microsoft Sentinel and Microsoft Copilot for Security
- Module 11: Network Forensics and Monitoring
- Module 12: Memory Dumping and Analysis
- Module 13: Disk Dumping and Analysis
Forudsætninger
ToppenCertificeringstest
Toppen- After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.