|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/active-directory-red-team-hacking/
课程评论:没有评论
课程名称:Active Directory 渗透测试完整课程 - 红队黑客 课程概览:如今,大多数企业网络都使用 Windows Active Directory 管理,因此安全专业人士必须了解 Windows 基础设施面临的威胁。Active Directory 渗透测试课程旨在帮助安全专业人士理解、分析并实践现代 Active Directory 环境中的威胁和攻击。该课程适合初学者,包含详细的演示视频和所有在视频中执行命令的文档。课程内容基于我们多年来破解 Windows 和 AD 环境的经验和研究。 在 Active Directory 安全领域,存在大量的知识空白,安全专业人士和管理员在尝试弥补时常常感到困难。多年来,我参加了许多关于 AD 安全的世界级培训,发现优质材料的缺乏,尤其是缺乏良好讲解和演练。因此本课程模拟真实的攻击与防御场景,从一个非管理员账户开始,逐步提升到企业管理员权限。我们重点关注利用被忽视的域功能,而不仅仅是软件漏洞。 课程涵盖的主题包括 AD 枚举、使用的工具、域权限提升、域持久性、基于 Kerberos 的攻击(如金票、银票等)、ACL 问题、SQL 服务器信任及防御绕过等内容。
Most enterprise networks today are managed using Windows Active Directory and it is imperative for a security professional to understand the threats to the Windows infrastructure. Active Directory Pretesting is designed to provide security professionals to understand, analyze and practice threats and attacks in a modern Active Directory environment. The course is beginner friendly and comes with a walkthrough videos course and all documents with all the commands executed in the videos. The course is based on our years of experience of breaking Windows and AD environments and research.When it comes to AD security, there is a large gap of knowledge which security professionals and administrators struggle to fill. Over the years, I have taken numerous world trainings on AD security and always found that there is a lack of quality material and specially, a lack of good walkthrough and explanation. The course simulate real world attack and defense scenarios and we start with a non-admin user account in the domain and we work our way up to enterprise admin. The focus is on exploiting the variety of overlooked domain features and not just software vulnerabilities.We cover topics like AD enumeration, tools to use, domain privilege escalation, domain persistence, Kerberos based attacks (Golden ticket, Silver ticket and more), ACL issues, SQL server trusts, and bypasses of defenses.