|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/ibm-penetration-testing-threat-hunting-cryptography
课程评论:没有评论
课程名称:渗透测试、威胁狩猎与密码学 课程概述:安全漏洞的成本平均约为500万美元(IBM), 并且每年都在增加。因此,企业始终在寻找能够预见和防止威胁的专业人员。本课程由IBM提供,旨在帮助学员掌握识别漏洞、保护资产的技能,并运用人工智能和密码学技术来增强组织的网络安全防护。 课程大纲: 1. 渗透测试:规划与发现阶段 - 介绍渗透测试的不同阶段,包括规划、发现、攻击、验证和报告。重点了解规划阶段的伦理和法律要求,以及发现阶段的被动和主动侦查方法,包括Google Dorking。 2. 渗透测试:攻击阶段 - 聚焦于渗透测试的攻击阶段,学习执行攻击的关键步骤,如运行利用工具、绕过防御、提升权限及后期攻击活动。通过实际操作掌握端口扫描、网络扫描和网络协议分析工具。 3. 渗透测试:报告阶段 - 关注于渗透测试的报告阶段,介绍软件和应用渗透测试的概念。学习扫描代码库存的漏洞并理解其重要性,创建全面的渗透测试报告,实施渗透测试执行标准(PTES)框架。 4. 威胁狩猎与威胁情报 - 介绍威胁狩猎的实践和威胁情报在网络安全中的作用。探索不同的威胁情报来源,使用IBM X-Force Threat Exchange审查最新的安全威胁报告,了解威胁情报平台和SIEM系统的工作方式。 5. 密码学:原理与技术 - 深入探讨密码学的基础概念与实践,涵盖保证数据完整性、保密性和真实性的关键技术,学习对称与非对称加密算法(如AES和RSA)及哈希技术。 6. 期末项目与总结 - 在期末项目中应用所学知识,总结课程学习的关键要点,并提供后续学习的建议和方向。 本课程将帮助学员建立在网络安全领域所需的技能,以应对不断演变的安全威胁。
Name:Penetration Testing: Planning and Discovery Phases
Description:This module provides an overview of the different phases of penetration testing, which includes planning, discovery, attack, verification, and reporting. You'll also learn about the fundamental concepts of penetration testing and its importance. The module will focus on the planning and discovery phases. The planning phase will cover the rules of engagement, which ensure penetration tests are conducted ethically and legally. Then, in the discovery phase, you will be introduced to passive and active reconnaissance methods and Google Dorking.
Name:Penetration Testing: Attack Phase
Description:This module focuses on the attack phase of penetration testing. You will learn about the key actions involved in the attack phase, including running exploits, bypassing defenses, gaining elevated privileges, and initiating post-attack activities. You will also explore various penetration testing tools and perform port and website scans using online penetration tools. Further, you will solidify your understanding of port scanning, network scanning, and network protocol analyzers through hands-on labs.
Name:Penetration Testing: Reporting Phase
Description:This module focuses on the reporting phase of penetration testing, while introducing the concepts of software and application pen testing. You will learn how to scan code repositories for vulnerabilities and understand its benefits. You will also understand the importance of the reporting phase, create comprehensive penetration testing reports, and implement the Penetration Testing Execution Standard (PTES) framework, which provides insights into industry standards for reporting.
Name:Threat Hunting and Threat Intelligence
Description:This module provides an overview of threat hunting practices and the role of threat intelligence in cybersecurity. You will explore various threat intelligence sources and learn how to review recent security threat reports using IBM X-Force Threat Exchange. You'll also learn about threat intelligence platforms, security information and event management (SIEM) systems, threat intelligence frameworks, and threat hunting models. Additionally, you'll gain insights into the role of AI in enhancing threat intelligence and hunting capabilities.
Name:Cryptography: Principles and Techniques
Description:This module delves into the fundamental concepts and practices of cryptography, covering essential techniques for ensuring data integrity, confidentiality, and authenticity. You will gain insights into symmetric and asymmetric encryption algorithms like AES and RSA, as well as hashing techniques. The module also examines key management practices and crucial cryptographic techniques, such as securing SSL/TLS. Further, it addresses common cryptographic attacks and cryptanalysis techniques, providing a comprehensive understanding of cryptographic solutions for enhancing organizational security.
Name:Final Project and Wrap-Up
Description:In this module, you will apply the knowledge gained in the course in a final project. The module also wraps up the course learning and highlights key takeaways and next steps.
The cost of a security breach averages nearly $5M (IBM) and is increasing every year. So, businesses are always looking for professionals who can anticipate threats and prevent them. This IBM Penetration Testing, Threat Hunting, and Cryptography course builds expertise in identifying vulnerabilities, protecting assets, and using AI and cryptography techniques to strengthen an organization’s cybersecurity posture. During the course, you’ll explore the penetration testing phases and gain practica