Advanced Windows Active Directory Penetration Testing

所在平台: Udemy

课程主页: https://www.udemy.com/course/advanced-windows-active-directory-penetration-testing/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:高级Windows Active Directory渗透测试 课程概述:Windows Active Directory (AD) 凭借其在企业基础架构中的重要性已成为安全专业人士的关键关注点。因此,掌握Windows基础设施的复杂性和相关威胁对安全专家至关重要。此课程旨在为有经验的渗透测试专家及有意提升其技能的人士提供深入的指导,包含大量详细的视频和全面的攻击场景及向量的演示,这些内容源于丰富的实践经验和深入研究Windows AD生态系统的方法。 课程模拟真实世界的攻击场景,从对手仅具备网络级访问权限开始,经过初步建立足迹,拉动网络中的横向移动,最终提升至企业管理员级别权限。本课程重点关注利用常被忽视的域特性,而非仅仅依赖软件漏洞。 主要关注领域包括: - 外部OSINT(开放源信息侦察) - 通过基于Kerberos的密码喷射、网络协议滥用等实现初始访问 - Active Directory情境意识 - 通过Kerberoasting、Kerberos代表、访问控制列表等实现特权提升 - 通过金票、银票、钻石票、蓝宝石票等手段实现持久性 - 滥用Active Directory证书服务(AD CS) - 域和森林信任滥用 - 渗透测试报告撰写 此课程为希望进一步提升渗透测试技能的学习者提供了全面的知识体系和实用的技能工具。

课程评论(0条)

课程详情

Windows Active Directory (AD) has been the center stage for most corporate infrastructure for decades. Hence, it is crucial for security professionals to grasp the intricacies and threats associated with Windows infrastructures.Active Directory Penetration Tests offer a better way for security experts to analyze and engage with the threats present in modern AD environments. This course, suitable for experienced pentesters and anyone interested in taking their pentesting to the next level, includes loads of detailed videos and thorough walkthroughs of attack scenarios and vectors, built upon extensive practical experience and dedicated research in compromising Windows AD ecosystems.This course emulates real-world attack scenarios, beginning with an adversary with nothing but just a network-level access and no Active Directory-level access to obtaining an initial foothold, laterally moving withing the network and escalating privileges to that of Enterprise Administrator level. The emphasis lies on abusing often-overlooked domain features rather than merely software vulnerabilities.Key areas of focus include:External OSINTInitial Access via Kerberos-based Password Spray, Network Protocol Abuses, etc.Active Directory Situational AwarenessPrivilege Escalation via Kerberoasting, Kerberos Delegations, Access Control Lists, etc.Persistence via Golden Ticket, Silver Ticket, Diamond Ticket, Sapphire Ticket, etc.Abusing Active Directory Certificate Services (AD CS)Domain and Forest Trust AbusesPenetration Testing Report Writing

课程标签

0人关注该课程

主题相关的课程