Masterclass: Active Directory Security Attacks, Defense, Monitoring, and Investigation

During this 5-day course of super intensive training you will gain crucial cybersecurity knowledge and skills in terms of Attacks, Defense, Monitoring and Investigation of the Active Directory.

You´ll be able to:

  • Get the highest quality and unique learning experience – the class is limited to 16 participants by default.
  • Get the opportunity to interact with our world-renowned Experts.
  • Go through CQURE’s custom lab exercises and practice them after the course.
  • Receive a lifelong certification after completing the course!

Why this course?

This is a 5-day deep dive course on SOC analytics, a must-go for SOC analysts, Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security. It is delivered by one of the best people in the market in the security field and what is more, this is an international Live Virtual Class so you will be able to share the learning experience with a group of IT pros from around the world without leaving your home or office!

 Target Audience

Security architects, Active Directory administrators, security administrators, security auditors, and other people responsible for implementing secure identity. To attend this training, attendees should have a good hands-on experience with Active Directory Domain Services (AD DS) administration.

 

This Live Virtual Class consists of 4 Modules in terms of Attacks, Defense, Monitoring and Investigation of the Active Directory. They include essential theory combined with individual practice during the exercises as well as loads of hands-on tools and real-case scenarios.

Module 1: Advanced Attack Techniques

  1. Password based attacks
  2. NTLM related attacks
  3. Kerberos related attacks
  4. NGC / Shadow credentials
  5. AD objects privilege abuse
  6. Active Directory domain and forest trust abuse
  7. DPAPI related attacks
  8. Other: DCSync, DCShadow, SDAdmin holder

Module 2: Monitoring and Defending AD

  1. Auditing AD objects ACL’s
  2. Advanced Events monitoring
  3. Detection of IoC and IoA
  4. Preventing lateral movement
  5. Hardening with GPO
  6. Semi-automatic auditing

Module 3: Incident Response in AD

  1. Preparation: Toolkits, resources, techniques, skills
  2. Detection and analysis
  3. Containment in AD environment
  4. Eradication
  5. Recovery
  6. Lesson learns and processing changes in AD environment

Module 4: Beyond Active Directory Directory Services

  1. Beyond Active Directory Directory Services
  2. AD Certification Services
  3. AD Federation Services

Certification

After finishing the course, you will be granted a CQURE Certificate of Completion. Please note that after completing the course you will also be eligible for CPE points!

 

FAQ – Masterclass: Active Directory Security Attacks, Defense, Monitoring, and Investigation

Hva koster kurset?
Prisen er 39 900 NOK for 5 dager. Kurset inkluderer kursmateriell, praktiske lab-øvelser og livslang sertifisering etter fullført kurs.

Hvor lenge varer kurset?
Kurset går over 5 intensive dager fra 09:00 til 16:00 hver dag og gjennomføres som et internasjonalt live virtuelt kurs.

Hvordan gjennomføres kurset?
Kurset leveres som et live virtuelt kurs ledet av CQUREs cybersikkerhetseksperter. Deltakerne jobber i praktiske lab-miljøer og analyserer realistiske angrepsscenarioer for å lære hvordan Active Directory kan angripes, overvåkes og sikres.

Hvem passer kurset for?
Kurset er utviklet for fagpersoner som jobber med identitetssikkerhet og infrastruktur, blant annet:

  • Security architects
  • Active Directory administrators
  • Security administrators
  • Security auditors
  • Enterprise administrators
  • Infrastructure architects
  • System engineers
  • Network administrators
  • Security consultants

Hva lærer jeg i løpet av kurset?
Du lærer hvordan moderne angrep mot Active Directory fungerer, hvordan de oppdages, og hvordan miljøet kan sikres. Etter kurset vil du kunne:

  • Identifisere og analysere avanserte angrep mot Active Directory
  • Overvåke sikkerhetshendelser og identifisere kompromittering
  • Implementere sikkerhetskontroller og hardening av AD-miljøer
  • Gjennomføre incident response i Active Directory
  • Oppdage lateral movement og privilegieeskalering
  • Sikre identitetsinfrastruktur i enterprise-miljøer

Er kurset praktisk rettet?
Ja. Kurset inneholder omfattende hands-on lab-øvelser hvor deltakerne analyserer angrepsscenarioer og lærer hvordan sikkerhetsteam oppdager og stopper angrep i Active Directory-miljøer.

Hvilke temaer dekkes i kurset?
Kurset dekker blant annet:

  • Avanserte angrep mot Active Directory
  • Password- og Kerberos-baserte angrep
  • Privilege abuse og lateral movement
  • DCSync, DCShadow og Shadow Credentials
  • Overvåking av sikkerhetshendelser og indikatorer på kompromittering
  • Hardening av Active Directory med GPO
  • Incident response og gjenoppretting etter angrep
  • Sikkerhetsanalyse av AD Certificate Services og AD Federation Services

Får jeg sertifisering etter kurset?
Ja. Etter fullført kurs mottar du en livslang sertifisering som dokumenterer kompetanse innen sikkerhet, overvåking og hendelseshåndtering i Active Directory.

Hvilke forkunnskaper anbefales?
Det anbefales at deltakerne har god erfaring med administrasjon av Active Directory Domain Services (AD DS) og Windows-infrastruktur.

Hva gjør dette kurset unikt?
Kurset gir en helhetlig gjennomgang av Active Directory-sikkerhet fra både angreps- og forsvarsperspektiv. Du lærer hvordan angripere kompromitterer identitetsinfrastruktur – og hvordan sikkerhetsteam kan oppdage, analysere og stoppe slike angrep.