This course is coming soon. It is not yet open for enrollment, and no payment is taken.
The outline and outcomes below reflect what this course will cover. Check back soon.
Coming soonIntermediate
Windows Internals for Defenders
Processes, tokens and the telemetry that catches abuse.
By LearnDefend Blue Team · Endpoint Security
About this course
Understand Windows the way an attacker abuses it and a defender catches them: process creation, tokens and privileges, LSASS, services and scheduled tasks, and the event and Sysmon telemetry that reveals each.
What you'll learn
- Trace process lineage and spot living-off-the-land abuse.
- Explain tokens, privileges and credential theft targets.
- Map defender-relevant behaviour to Windows and Sysmon events.
Course outline
- 1Processes and the creation chain
- 2Tokens, privileges and LSASS
- 3Services, tasks and persistence
- 4Telemetry: events and Sysmon
Prerequisites
- Basic Windows administration and log reading.