Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

A Process is No One - Hunting for Token Manipulation

Black Hat via YouTube

Overview

This course focuses on teaching participants how to start Threat Hunting by emphasizing the importance of hunt hypothesis generation to guide targeted data collection and forensic artifact analysis. The course covers the Hacker Lifecycle, Mitre Attack Framework, tactics, procedures, and the process of building a hunt hypothesis. Participants will learn about Access Token Manipulation, Windows Authentication, different token types, token impersonation, and visualization techniques. The teaching method includes a combination of theoretical concepts, practical demonstrations, and Q&A sessions. This course is intended for individuals interested in starting Threat Hunting within their organizations and those looking to enhance their skills in cybersecurity and digital forensics.

Syllabus

Introduction
What is Hunting
Normal Hunt Cycle
Hypothesis Driven Hunting
Benefits
HypothesisDriven Hunting
Hacker Lifecycle
Mitre Attack Framework
Tactics Techniques Procedures
Tactics
Procedures
Why is this useful
What is this process
Building the hunt hypothesis
Identifying the tactic
Identifying the procedures
Scope
Documentation
Conclusion
Benefit
Tactics and Techniques
Access Token Manipulation
Windows Authentication
Access tokens
Token types
General overview
Token impersonation
Visualization
Create a Process
Make an Impostor Token
Create a New logon session
Collection Requirements
Collecting Access Tokens
Get Access Token
Impersonation
GetSystem
Kerberos ticket granting ticket
Get Kerberos ticket granting ticket
Make token attack
Scope of analysis
Excluded factors
Demo
Questions

Taught by

Black Hat

Reviews

Start your review of A Process is No One - Hunting for Token Manipulation

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.