Course

Windows Sign-In Evidence: Investigating Authentication Across Hosts

Difficulty intermediate
Modules 3
Language en
Windows Sign-In EvidenceAccount, host, domain controller, protocol, session, and resource evidence combine into an authentication investigation.PRACTICAL SECURITY OPERATIONSWindows Sign-In EvidenceAccountEndpointDomain controllerSessionEVIDENCE → REASONING → DEFENSIBLE ACTION

About this course

This course teaches SOC analysts, Windows administrators, and incident responders how Windows authentication becomes evidence across several systems. Learners build a mental model of credentials, authentication, logon sessions, tokens, and resource access; interpret common Security log events; reconstruct Kerberos and NTLM activity; and correlate host, domain-controller, network, and identity telemetry. The course treats event IDs as records with placement, fields, and collection limits rather than universal verdicts. Completion means the learner can investigate a suspicious sign-in, explain where supporting events should exist, distinguish common administrative and service behavior from meaningful anomalies, and hand off a scoped, time-aligned assessment.

What you'll learn

  • Explain the difference between credential validation, authentication, a Windows logon session, and later resource access.
  • Locate and interpret common logon and account-logon events on endpoints, servers, and domain controllers.
  • Reconstruct Kerberos and NTLM activity while accounting for protocol, logging, and field limitations.
  • Build a corroborated sign-in timeline and write a disposition based on expected behavior, impact, and confidence.

Course Content