This workshop focuses on the key aspects of Windows Infrastructure Security, applying best practices to secure interconnected information systems within your organization providing a holistically reliable framework to support an entire enterprise structure.
Businesses nowadays are almost fully dependent on IT services, making the hardening and securing processes even more intense. The number of possible attack surfaces has emerged exponentially in direct relation to the increasingly competitive field of current technology we are witnessing where developers try to achieve more and more functionality from implemented solutions and applications.
The CAST 616: Securing Windows Infrastructure is designed with the single purpose of providing Info-Sec professionals with complete knowledge and practical skills necessary to secure their network infrastructure which is fast becoming if already not a top priority plus a major tech challenge for most security conscious organizations.
This 4 day training deep dives into the key aspects of solving infrastructure-related problems by appreciating the key elements of how Windows Internal Security mechanisms actually work and how it can be further optimized without jeopardizing or easing an organization’s IT Environment configuration settings which becomes common as time passes. Some of the highlights of this course are techniques used in Kernel Debugging, Malware hunting, deep diving into BitLocker and the automation of the whole hardening process.
At the end of the workshop, you will learn how to:
- Break down the intricacies involved in a Windows Hardening process to little manageable bits
- Attack various infrastructure solutions to configure appropriate advanced security settings and defense
- Harden a Windows Environment by securing Windows objects and creating solution-related implementations
- Analyze and monitor infrastructure performance and security
- Examine the ways in which data can be protected on a corporate user’s desktops and on file servers
- Apply security settings to virtual private networks
- Familiarize the boot process and all the related investigation techniques
- Expose multiple methods to hacking operating systems, stealing information and getting malware into the network
- Secure vital communications between servers
Why Attend this Workshop
- Gain knowledge on how to apply Windows Server 2008 R2 and Windows Server 2012 features to secure your infrastructure
- Learn how to setup the appropriate rights, privileges and permissions to operating system objects
- Learn the key functionalities of IPSec (domain isolation, securing network traffic)
- Learn now to configure, monitor and troubleshoot Microsoft infrastructure services
- Gain knowledge how to implement Network Access Protection
- Learn how Windows operating systems work
- Learn how to implement BitLocker
- Learn how to deal with insecure or incompatible drivers
- Gain knowledge how to investigate Blue Screens
- Learn how to build the failover cluster and NLB used in the Web Server scenario
- Learn how to use Public Key Infrastructure in the everyday tasks
The International Council of E-Commerce Consultants (EC-Council) is a member-based organization that certifies individuals in various e-business and information security skills. It is the world’s largest cyber security technical certification body. It is the owner and creator of the world famous Certified Ethical Hacker (CEH), Computer Hacking Forensics Investigator (CHFI) and EC-Council Certified Security Analyst (ECSA)/License Penetration Tester (LPT) certifications and as well as many others certifications that are offered in over 87 countries globally. EC-Council has trained and certified over 200,000 information security professionals globally that have influenced the cyber security mindset of countless organizations worldwide.
EC Council certification programs are recognized worldwide and have received endorsements from various government agencies including the US Federal Government via the Montgomery GI Bill, and the US Government National Security Agency (NSA) and the Committee on National Security Systems (CNSS) certifying EC-Council’s Certified Ethical Hacking (CEH), Network Security Administrator (ENSA), Computer Hacking Forensics Investigator (CHFI), Disaster Recovery Professional (EDRP), Certified Security Analyst (E|CSA) and Licensed Penetration Tester(LPT) program for meeting the 4011, 4012, 4013A, 4014, 4015 and 4016 training standards for information security professionals and most recently EC-Council has received accreditation from the American National Standards Institute (ANSI).
Module 1: Windows 7 & 8 Hardening
This module covers a detailed deep-dive into Windows internal security mechanisms and their practical usage and adjustment.
- Windows Kernel role
- Securing operating system objects
- Modern malware and threats
- Device Drivers
- Group Policy Settings
- Practical Cryptography
At the end of this module, you would have practically learnt how to:
- Detect Threats and know about their effects
- Get Points of entry to the client operating system
- Secure configuration of the client operating system
- Perform Security management in the client operating system
Module 2: Windows Server 2008 R2 / Windows Server 8 Hardening
This module focuses on server architecture, security issues and hardening
- Securing Server Features
- Public Key Infrastructures
- Active Directory
- Microsoft SQL Server hardening
- Installation considerations
- Configuring crucial security features
- Lab: Hardening Microsoft SQL Server
At the end of this module, you would have practically learnt how to:
- Detect threats for servers and perform countermeasures
- Identify points of entry to the server operating system
- Implement solutions for server security
- Perform hardening of the Windows related roles
Module 3: Hardening Microsoft Network Roles
This module focuses on hardening and testing network related roles. Very intensive!
- Hardening minor network roles
- DNS Hardening
- Internet Information Security 7.5 / 8
- IPSec
- DirectAccess
- Remote Access
- Firewall
At the end of this module, you would have practically learnt how to:
- Configure secure remote access
- Implement Network Access Protection
- Implement techniques to avoid protocol misusage and implement prevention actions
- Perform DNS advanced configuration
- Harden the Windows networking roles and services – in details
- Build the secure web server
Module 4: Windows High Availability
This module covers business continuity support technologies
- Network Load Balancing design considerations and best practices
- iSCSI configuration
- Failover Clustering internals and security
- Lab: Building IIS Cluster with NLB
- Lab: Building the failover cluster
At the end of this module, you would have practically learnt how to:
- Implement High Availability technologies
Module 5: Data and Application Security
This module covers solutions that greatly support information and data security
- File Classification Infrastructure
- Designing security for File Server
- Active Directory Rights Management Services
- AppLocker and Software Restriction Policy
- Lab: Building secure solution with FCI and ADRMS
- Lab: Securing and auditing a File Server
- Lab: Restricting access to applications with Applocker and SRP
- Lab: Software Restriction Policy (in) security
At the end of this module, you would have practically learnt how to:
- Implement Information and data protection solutions
- Implement Best practices of data security solutions
- Implement Techniques for restricting access to data
- Implement Techniques of avoiding misusage of applications
Module 6: Monitoring, Troubleshooting and Auditing Windows
This module covers all best practices regarding to monitoring, troubleshooting and auditing Windows. It is a prefect module for Windows investigators
- Advanced logging and subscriptions
- Analyzing and troubleshooting the boot process
- Crash dump analysis
- Auditing tools and techniques
- Monitoring tools and techniques
- Professional troubleshooting tools
- Lab: Event logging and subscriptions
- Lab: Monitoring the boot process
- Lab: Blue Screen scenario
At the end of this module, you would have practically learnt about:
- Troubleshooting methodologies
- Collecting data methodologies
- Monitoring Windows after / during the attack and during situation specific events
- Windows forensics
Module 7: Automating Windows hardening
This module covers automation of monitoring, troubleshooting and auditing Windows.
- Advanced logging and subscriptions
- Analyzing and troubleshooting the boot process
- Crash dump analysis
- Auditing tools and techniques
- Monitoring tools and techniques
- Professional troubleshooting tools
- Lab: Event logging and subscriptions
- Lab: Monitoring the boot process
- Lab: Blue Screen scenario
At the end of this module, you would have practically learnt about automating:
- Troubleshooting methodologies
- Collecting data methodologies
- Monitoring Windows after / during the attack and during situation specific events
- Windows forensics