COURSE OBJECTIVE:
Not available. Please contact.
TARGET AUDIENCE:
Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.
COURSE PREREQUISITES:
COURSE CONTENT:
Module 1: Windows Internals & System Architecture a) Introduction to the Windows 10 and Windows Server 2019 security concepts
b) Architecture overview and terms
c) Key System Components i. Processes, Threads and Jobs ii. Services, Functions and Routines iii. Sessions iv. Objects and Handles v. Registry
d) Advanced Local Procedure Call
e) Information gathering techniques i. Windows Debugging ii. Performance Monitor iii. Windows Driver Kit iv. Other useful tools Module 2: Process and Thread Management a) Process and thread internals
b) Protected processes
c) Process priority management
d) Examining Thread Activity
e) Process and thread monitoring and troubleshooting techniques (advanced usage of Process Explorer, Process Monitor, and other tools) Module 3: System Security Mechanisms a) Integrity Levels
b) Session Zero
c) Privileges, permissions and rights
d) Passwords security (techniques for getting and cracking passwords)
e) Registry Internals
f) Monitoring Registry Activity
g) Driver signing (Windows Driver Foundation)
h) User Account Control Virtualization
i) System Accounts and their functions
j) Boot configuration
k) Services architecture
l) Access tokens
m) Biometric framework for user authentication Module 4: Debugging & Auditing a) Available debuggers
b) Working with symbols
c) Windows Global Flags
d) Process debugging
e) Kernel-mode debugging
f) User-mode debugging
g) Setting up kernel debugging with a virtual machine as the target
h) Debugging the boot process
i) Crash dump analysis
j) Direct Kernel Object Manipulation
k) Finding hidden processes
l) Rootkit Detection Module 5: Memory Analysis a) Memory acquisition techniques
b) Finding data and activities in memory
c) Step-by-step memory analysis techniques
d) Tools and techniques to perform memory forensic Module 6: Storage Management a) Securing and monitoring Files and Folders
b) Protecting Shared Files and Folders by Using Shadow Copies
c) Implementing Storage Spaces
d) Implementing iSCSI
e) Implementing FSRM, managing Quotas, File Screens, and Storage Reports
f) Implementing Classification and File Management Tasks, Dynamic Access Control
g) Configuring and troubleshooting Distributed File System Module 7: Startup and Shutdown a) Boot Process overview
b) BIOS Boot Sector and Bootmgr vs. the UEFI Boot Process
c) Booting from iSCSI
d) Smss, Csrss, and Wininit
e) Last Known Good configuration
f) Safe Mode capabilities
g) Windows Recovery Environment (WinRE)
h) Troubleshooting Boot and Startup Problems Module 8: Infrastructure Security Solutions a) Windows Server Core Improvements in Windows Server 2019
b) AppLocker implementation scenarios
c) Advanced BitLocker implementation techniques (provisioning, Standard User Rights and Network Unlock?
d) Advanced Security Configuration Wizard
e) IPSec
f) Advanced GPO Management
g) Practicing Diagnostic and Recovery Toolkit
h) Tools Module 9: Layered Network Services a) Network sniffing techniques
b) Fingerprinting techniques
c) Enumeration techniques
d) Networking Services Security (DNS, DHCP, SNMP, SMTP and other)
e) Direct Access
f) High Availability features: cluster improvements and SMB ?Scale – Out File Server)
g) Network Load Balancing Module 10: Monitoring and Event Tracinga) Windows Diagnostic Infrastructure
b) Building auditing
c) Expression-based audit policies
d) Logging Activity for Accounts and processes
e) Auditing tools, techniques and improvements
f) Auditing removable storage devices Module 11: Points of Entry Analysis a) Offline access
b) Kali Linux /other tools vs. Windows Security
c) Unpatched Windows and assigned attacks
d) Domain Controller attacks
e) Man-in-the Middle attacks
f) Services security
FOLLOW ON COURSES:
Not available. Please contact.