Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend

This course is coming soon. It is not yet open for enrollment, and no payment is taken.

The outline and outcomes below reflect what this course will cover. Check back soon.

Coming soonIntermediate

Windows Internals for Defenders

Processes, tokens and the telemetry that catches abuse.

By LearnDefend Blue Team · Endpoint Security

About this course

Understand Windows the way an attacker abuses it and a defender catches them: process creation, tokens and privileges, LSASS, services and scheduled tasks, and the event and Sysmon telemetry that reveals each.

What you'll learn

  • Trace process lineage and spot living-off-the-land abuse.
  • Explain tokens, privileges and credential theft targets.
  • Map defender-relevant behaviour to Windows and Sysmon events.

Course outline

  1. 1Processes and the creation chain
  2. 2Tokens, privileges and LSASS
  3. 3Services, tasks and persistence
  4. 4Telemetry: events and Sysmon

Prerequisites

  • Basic Windows administration and log reading.
Windows Internals for Defenders | LearnDefend