Mô tả

The course provides refined, standardized and verified information that cannot be found in any other single source publicly available. It does not contain engaging labs or tasks, but only demonstrations. The content is heavily condensed and it will take significantly more than 3 hours to absorb it. You will need a high level of motivation to be able to complete the course and digest the information so that it can be applied practically. At the end of each section, there is a review with multiple-choice questions and explanations. Download and use the course transcript instead of taking notes and follow the references for digging deeper in topics of interest.


The course will introduce you to Microsoft implementation of Kerberos authentication protocol and its benefits, terminology, concepts, and service infrastructure. It will then explain how Kerberos works through detail and step-by-step examination of the ticketing system and communication messages in various configurations using flow diagrams and network traffic analyzer to get better understanding of the processes. Understanding how Kerberos works will help you with troubleshooting complex problems and reduce stress.


We will walk through the configuration of the most common Microsoft applications such as IIS, SQL, Exchange, and file servers, including multi-hop setups and mid-tier service integration, discuss impersonation, review delegation options, and see why some of these options are not so secure. We will also learn how to Kerberize non-Windows services so they can benefit from Kerberos security and convenience of SSO.


Then we will dive into troubleshooting issues, go through a checklist so we don’t miss most common misconfigurations and we will look into specific troubleshooting examples. We will also examine Kerberos vulnerabilities and the most common attacks, such as Kerberoasting and Golden and Silver Tickets and talk about how to prevent and detect compromise. Finally, we will look into relevant monitoring and alerting options and learn how to use these for detecting malicious activity.

Bạn sẽ học được gì

Improve Windows domain and service security by using Kerberos authentication.

Learn Kerberos terminology, concepts and benefits.

Understand how Kerberos authentication works and why it is preferred authentication protocol.

Configure Kerberos authentication in a secure way for multi-tier applications.

Resolve Kerberos authentication problems using Network Monitor and analytical thinking.

Secure and monitor Kerberos infrastructure and communications.

Yêu cầu

  • This is expert level course with focus on Kerberos infrastructure and authentication.
  • You should have experience with Windows server infrastructure and Active Directory.
  • You should be familiar with communication protocols and security standards.
  • Knowledge of Microsoft IIS, SQL Server and Exchange Server will help a lot.

Nội dung khoá học

8 sections

Introduction

11 lectures
Welcome
01:33
Introduction to Kerberos
01:56
Kerberos advantages
01:06
Kerberos ticketing system
01:08
Symmetric encryption
01:17
Encryption prerequisites
00:51
Kerberos terminology
01:02
Kerberos secret keys
02:15
Kerberos cache
00:53
Messages, tickets and encryption algorithms
04:51
Introduction to Kerberos review
5 questions

How Kerberos works

7 lectures
Domain user logon to a PC
02:17
Demo: how to use Microsoft Network Monitor
02:26
User logon step by step
07:59
Smart card logon
02:11
Network service access step by step
06:30
Cross-realm authentication step by step
04:45
Kerberos authentication process review
6 questions

Kerberos configuration

9 lectures
Basic Kerberos configuration
06:10
Configure Kerberos for IIS
02:39
Configure Kerberos for Exchange
03:56
Demo: configure Kerberos for Exchange
05:45
Configure Kerberos for SharePoint, SQL and network file servers
04:01
Kerberos authentication through SMB
01:03
Configure Kerberos for non-Windows systems
01:47
Demo: configure Kerberos for non-Windows systems
03:42
Kerberos configuration review
5 questions

User impersonation and Kerberos delegation

13 lectures
IIS configuration for ASP.NET impersonation
03:59
Kerberos delegation and unconstrained delegation
04:43
Demo: forwarding the client's TGT to a service account
03:55
Constrained delegation
04:30
Demo: constrained delegation lab config
03:03
Demo: constrained delegation log events and network packet analysis
05:33
Resource based constrained delegation
02:53
Demo: RBCD
02:11
Kerberos delegation and Managed Service Accounts
01:02
Demo: constrained delegation with MSAs
02:04
Demo: RBCD with MSAs
01:16
IIS application integration
03:47
Kerberos delegation review
7 questions

Troubleshooting Kerberos issues

14 lectures
Kerberos troubleshooting checklist
04:00
Troubleshooting IIS
03:09
Troubleshooting delegation with WCF and .Net Core
03:44
Troubleshooting local calls
01:49
Troubleshooting issues with eTypes
02:11
Anonymous logon and BADOPTION error
02:01
Troubleshooting TGT delegation and missing SPNs
02:08
Demo: troubleshooting tools
04:27
Demo: KRB_AP_ERR_MODIFIED
02:39
Demo: account is sensitive and cannot be delegated
02:50
Demo: KDC_ERR_BADOPTION
01:22
Demo: KDC_ERR_ETYPE_NOTSUPP
01:34
Demo: KDC_ERR_S_PRINCIPAL_UNKNOWN
01:51
Troubleshooting Kerberos review
7 questions

Kerberos security

14 lectures
Kerberoasting
01:52
AS-REP Roasting
01:56
Overpass the Hash and Pass the Ticket
04:01
Golden and Silver Tickets
02:49
DCSync
02:40
Additional considerations
01:32
Preventive measures
04:06
Who is using RC4?
02:29
Audit the system for usage of non-AES256 eTypes
02:24
Disable non-AES256 eTypes
03:52
Kerberos Armoring
07:27
Demo: Kerberos Armoring misconfiguration case 1
04:36
Demo: Kerberos Armoring misconfiguration case 2
03:29
Kerberos security review
8 questions

Monitor Kerberos

2 lectures
Monitoring Kerberos related activities
05:09
Kerberos monitoring review
5 questions

Conclusion and thank you

1 lectures
Thank you
01:27

Đánh giá của học viên

Chưa có đánh giá
Course Rating
5
0%
4
0%
3
0%
2
0%
1
0%

Bình luận khách hàng

Viết Bình Luận

Bạn đánh giá khoá học này thế nào?

image

Đăng ký get khoá học Udemy - Unica - Gitiho giá chỉ 50k!

Get khoá học giá rẻ ngay trước khi bị fix.