Kurser

4 dages virtuelt kursus

Virtual Masterclass: Windows Security and Infrastructure Management [WSI]

19. - 22. april 2022 Virtuelt kursus
DKK  20.999
ekskl. moms
Nr. 87795 A

Lær, at se på din infrastruktur med en hackers øjne. Du lærer at konfigurere passwords-mekanismer hensigtsmæssigt, bruge PowerShell i sikkerhedssammenhænge, DNS konfiguration og meget mere, der kan sikre din virksomhed mod angreb. Undervisningen foregår på engelsk.

This is a deep dive course on infrastructure services configuration, increasing their level of security and windows internals. It is a must-go for enterprise administrators, security officers and architects. Delivered by one of the best people in the market in the security field – with practical knowledge from tons of successful projects, many years of real-world experience, great teaching skills and no mercy for misconfigurations or insecure solutions.

The secure infrastructure configuration should be the most important line of defense in every organization. Unfortunately, people, the most valuable resource, are not always aware of the level of security in their companies, possible points of entry, how operating systems are attacked, and how to protect the infrastructure from successful attacks which are sometimes caused by configuration mistakes. Understanding internal OS protection mechanisms and services/roles completely provides a huge impact on the whole infrastructure security level. Unfortunately, the problem is… rarely anyone has this impact!

Deltagerprofil

Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.

Indhold

Module 1: Windows Internals & System Architecture
  • Introduction to the Windows 7/8.1 and Windows Server 2008/2012 R2 security concepts
  • Architecture overview and terms
  • Key System Components
  • Processes, Threads and Jobs
  • Services, Functions and Routines
  • Sessions
  • Objects and Handles
  • Registry
  • Advanced Local Procedure Call
  • Information gathering techniques
  • Windows Debugging
  • Performance Monitor
  • Windows Driver Kit
  • Other useful tools
Module 2: Process and Thread Management
  • Process and thread internals
  • Protected processes
  • Process priority management
  • Examining Thread Activity
  • Process and thread monitoring and troubleshooting techniques (advanced usage of Process Explorer, Process Monitor, and other tools)
Module 3: System Security Mechanisms
  • Integrity Levels
  • Session Zero
  • Privileges, permissions and rights
  • Passwords security (techniques for getting and cracking passwords)
  • Registry Internals
  • Monitoring Registry Activity
  • Driver signing (Windows Driver Foundation)
  • User Account Control Virtualization
  • System Accounts and their functions
  • Boot configuration
  • Services architecture
  • Access tokens
  • Biometric framework for user authentication
Module 4: Debugging & Auditing
  • Available debuggers
  • Working with symbols
  • Windows Global Flags
  • Process debugging
  • Kernel-mode debugging
  • User-mode debugging
  • Setting up kernel debugging with a virtual machine as the target
  • Debugging the boot process
  • Crash dump analysis
  • Direct Kernel Object Manipulation
  • Finding hidden processes
  • Rootkit Detection
Module 5: Memory Analysis
  • Memory acquisition techniques
  • Finding data and activities in memory
  • Step-by-step memory analysis techniques
  • Tools and techniques to perform memory forensic
Module 6: Storage Management
  • Securing and monitoring Files and Folders
  • Protecting Shared Files and Folders by Using Shadow Copies
  • Implementing Storage Spaces
  • Implementing iSCSI
  • Implementing FSRM, managing Quotas, File Screens, and Storage Reports
  • Implementing Classification and File Management Tasks, Dynamic Access Control
  • Configuring and troubleshooting Distributed File System
Module 7: Startup and Shutdown
  • Boot Process overview
  • BIOS Boot Sector and Bootmgr vs. the UEFI Boot Process
  • Booting from iSCSI
  • Smss, Csrss, and Wininit
  • Last Known Good configuration
  • Safe Mode capabilities
  • Windows Recovery Environment (WinRE)
  • Troubleshooting Boot and Startup Problems
Module 8: Infrastructure Security Solutions
  • Windows Server Core Improvements in Windows Server 2012 R2
  • AppLocker implementation scenarios
  • Advanced BitLocker implementation techniques (provisioning, Standard User Rights and Network Unlock?
  • Advanced Security Configuration Wizard
  • IPSec
  • Advanced GPO Management
  • Practicing Diagnostic and Recovery Toolkit
  • Tools
Module 9: Layered Network Services
  • Network sniffing techniques
  • Fingerprinting techniques
  • Enumeration techniques
  • Networking Services Security (DNS, DHCP, SNMP, SMTP and other)
  • Direct Access
  • High Availability features: cluster improvements and SMB? Scale – Out File Server)
  • Network Load Balancing
  • Remote Access
  • Network Location Awareness
  • Wireless technology recognition
  • Wireless fingerprinting
  • Wireless hacking ideas and demos
  • Optimizing wireless hacking
  • Protecting wireless networks
Module 10: Monitoring and Event Tracing
  • Windows Diagnostic Infrastructure
  • Building auditing
  • Expression-based audit policies
  • Logging Activity for Accounts and processes
  • Auditing tools, techniques and improvements
  • Auditing removable storage devices
Module 11: Points of Entry Analysis
  • Offline access
  • Linux BackTrack /other tools vs. Windows Security
  • Unpatched Windows and assigned attacks
  • Domain Controller attacks
  • Man-in-the Middle attacks
  • Services security

Anmeldelser af Virtual Masterclass: Windows Security and Infrastructure Management [WSI]

Ekstremt dygtig lærer, man bliver virkeligt godt klædt på. Altid flotte omgivelser og en virkelig, virkelig god kantine.
 - Mikkel Rønne Hansen Region Hovedstaden.

Materiale

Exercises, presentation slides with notes and all the lab exercises will be available for the participants for extra 3-weeks after the course concludes.

CPE Point (Continuing professional education)

It will be possible to earn CPE points after completion this course.

Form

Virtuelt med live underviser. Før deltagelse i et virtuelt kursus, vil vi altid forsøge at arrangere en testsession på 15 - 20 minutter en uges tid før, for at sikre, at alle er i stand til at deltage i masterclassen. Herunder finder du kravene til at oprette forbindelse til det virtuelle kursus:

  • En computer med en stabil internetforbindelse (skal helst køre Windows eller Mac OS).
  • Tilladelser til udgående RDP-forbindelser til eksterne servere (til vores laboratoriemiljø) – port 3389
  • Et headset (hovedtelefoner og mikrofon)
  • Webcam (indbygget eller tilsluttet)
  • En ekstra skærm er nyttig, men ikke påkrævet
23906
23354
Underviser

Paula Januszkiewicz

Paula er verdenskendt som sikkerhedsekspert. Paula elsker at lave penetrationstests, IT-sikkerhedsevalueringer, og hendes motto er: "harden em all"! Enterprise Security MVP og -underviser (MCT) og Microsoft Security Trusted Advisor.

Underviser

Kamil

Kamil er en infrastruktur- og sikkerhedsekspert, Office 365 mest værdifulde professionelle, træner (Microsoft Certified Trainer) og Certified Technology Specialist (CTS). Han er medlem af Microsoft Windows Server System (WSS.PL), en af de bedste talere i Warsaw Windows Users & Specialists Group (WGUiSW). Han er medlem af International Association of Microsoft Certified Trainers (IAMCT) og Polish Infrastructure Group (PiNG).

Vælg dato

Virtuelt kursus
19. - 22. april 2022

Få ny inspiration til din kompetence­udvikling

Unikke tilbud, relevante artikler og nyt om vores kurser og uddannelser.

Indtast venligst et validt navn
Tilmelder nyhedsbrev
Tak for din tilmelding
Teknisk fejl

Der er desværre en systemfejl på nuværende tidspunkt. Du kan alternativt skrive en mail til data@teknologisk.dk