Masterclass: Threat Hunting with AI
- Course Code TAI
- Duration 3 days
Course Delivery
Jump to:
Course Delivery
This course is available in the following formats:
-
Virtual Learning
Learning that is virtual
Request this course in a different delivery format.
Course Overview
TopVirtual Learning
This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.
Course Schedule
TopTarget Audience
TopCourse Objectives
Top- Understand modern attack techniques and how they are executed and detected
- Identify and investigate privilege escalation and identity-based attacks
- Understand Windows authentication architecture and common exploitation paths
- Apply structured investigation methods using real-world case studies
- Use Microsoft Defender for Endpoint (EDR) for threat detection and hunting
- Detect and analyze attacks on identity infrastructure
- Perform basic network, memory, and disk forensic analysis
- Leverage Microsoft Sentinel and Security Copilot in threat detection and investigation
- Combine manual and AI-assisted methods to improve threat hunting and response
Course Content
Top- Module 1: Modern Attack Techniques and Tracing Them
- Module 2: Local Privilege Escalation Techniques and Tracing Them
- Module 3: Case Study – Investigating In-Place Attacks
- Module 4: Windows Authentication Architecture & Cryptography
- Module 5: Case Study – Investigating Identity Theft
- Module 6: Attacks on Identity Infrastructure and Tracing Them
- Module 7: Microsoft 365 Defender for Endpoint (EDR)
- Module 8: Security Operations with Microsoft EDR (Defender for Endpoint) – Advanced Threat Hunting with Defender
- Module 9: Microsoft Security Copilot
- Module 10: Case Study – Detecting a Complex Threat with Microsoft Sentinel and Microsoft Copilot for Security
- Module 11: Network Forensics and Monitoring
- Module 12: Memory Dumping and Analysis
- Module 13: Disk Dumping and Analysis
Course Prerequisites
TopTest Certification
Top- After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.