Cyber Threat Intelligence Feeds
Learn what threat intelligence feeds contain, where defenders use them, and how to turn a stream of indicators into meas...
3 lessons · 2 hrThis course teaches SOC analysts, Windows administrators, and incident responders how Windows authentication becomes evidence across several systems. Learners build a mental model of credentials, authentication, logon sessions, tokens, and resource access; interpret common Security log events; reconstruct Kerberos and NTLM activity; and correlate host, domain-controller, network, and identity telemetry. The course treats event IDs as records with placement, fields, and collection limits rather than universal verdicts. Completion means the learner can investigate a suspicious sign-in, explain where supporting events should exist, distinguish common administrative and service behavior from meaningful anomalies, and hand off a scoped, time-aligned assessment.
You will get more from this course if these foundations are already familiar.
Understand what Windows creates during sign-in and why related records appear on different computers with different identifiers.
Trace the path from an authentication attempt to a local session and avoid equating every credential event with an interactive desktop sign-in.
Map endpoint, resource-server, and domain-controller records so absence on one system is not mistaken for absence everywhere.
Reconstruct the two dominant Active Directory authentication paths and recognize what ticket and credential-validation events cannot reveal alone.
Connect ticket-granting ticket requests, service tickets, and target-host logons without claiming a ticket request equals successful resource use.
Read NTLM credential-validation evidence, identify its missing destination context, and investigate why NTLM was used before assigning intent.
Turn distributed audit records into a bounded timeline, then use baselines and counter-evidence to decide whether access was expected, suspicious, or confirmed unauthorized.
Join failures, tickets, successes, privileges, processes, and resource access while preserving source-specific time and identifier limits.
Measure deviations against peer and historical behavior, assess impact separately, and write a sign-in disposition that another analyst can reproduce.