Advanced Windows Privilege Escalation with Hack The Box

所在平台: Udemy

课程主页: https://www.udemy.com/course/advanced-windows-privilege-escalation-with-hack-the-box/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:高级Windows权限提升与Hack The Box 课程概述:这是一门100%动手实践的课程,专为有志于学习如何在Windows终端上提升权限的中级到高级用户而设计。课程不使用PPT,而是通过直接的操作演示红队员和高级对手在获得初步访问权限后使用的策略和技术。课程重点讲解如何揭示和利用已修补的Windows 10终端上的新型漏洞提升权限。 课程内容包含以下技术: - Windows内核漏洞利用 - 弱注册表权限 - 令牌操控 - CVE漏洞 - DPAPI滥用 - AS-REP Roasting(2021年11月新增四个讲座) 使用的工具包括: - msfvenom - PowerShell Empire - CrackMapExec - Mimikatz - 以及更多 课程将带你通过10台易受攻击的机器进行实际操作,无需设置实验室环境,因为所有环境均已在HackTheBox VIP实验室中建立。虽然HackTheBox需要额外收费,但提供了数百台预配置的易受攻击机器,用户通过VPN即可安全访问,极大简化了学习过程。 课程目标:完成课程后,你将能够在日常工作中运用这些技术,为OSCP准备,并参与CTF黑客活动。 课程特色包括:所有命令均放大显示,方便在手机上观看,不再需要眯着眼睛看命令提示符或终端。

课程评论(0条)

课程详情

New Launch for Spring 2021!This is a 100% hands on course as you will be using the same tradecraft and techniques Red Teamer's and advanced adversaries use to escalate privileges on Windows endpoints after they have gained initial access and established a foothold. This course is not "death by PowerPoint", in fact there is not a single Powerpoint slide in the course. This course is aimed for intermediate to advanced users who are hungry to know how to discover and exploit novel escalation paths on patched fully patched Windows 10 endpoints. Everything is carefully, explained - step-by-step.Additionally, although Metasploit is used in some attacks, we will be using less Metasploit and more manual walk-throughs because I wanted to take the time to carefully explain WHY each method works and detail how common misconfigurations happen in enterprise environments.Where Metasploit is used, everything is carefully explained and deconstructed so you can understand why and how it works. Exploits start easy and escalate in difficulty as you progress through the course.The TechniquesYou will quickly learn and execute the following escalation of privilege techniques across 5 vulnerable machines Windows Kernel ExploitsWeak Registry Permissions Token ManipulationCVE Exploits DPAPI Abuse AS-REP Roasting (Four New Lectures Just Added November 2021!)The ToolsYou will use msfvenom, BC Security PowerShell Empire, CrackMapExec, PSExec, WMIExec, Bloodhound, netcat, smbserver, ldapsearch, smbclient, rpcclient, hashcat, GetNPUsers, evil-winrm, wfuzz, gobuster, dirsearch, sqlmap, Mimikatz, DeepBlueCLI, Burp Suite (advanced features), Python 3, Powershell 7 on Linux and more. You will learn IIS 10 Server Administration, how to threat hunt for SQLi attacks in web logs and much much more.My dream for youBy the end of this course you should be able to use these techniques in:Your day to day workOSCP preparationCTF hackingAbout the labThere are 10 vulnerable machines.No lab setup is required as the entire environment is already established in HackTheBox VIP labsI wanted to make this course as realistic as possible while removing as many barriers to entry as possible so I've partnered with HackTheBox VIP labs to make it as easy as possible to get started.Yes, HackTheBox is an additional charge but it offers hundreds of pre-configured vulnerable machines in a lab which is accessible via a VPN connection. This means you can get started right away and don't have to waste time fumbling with VirtualBox and VMWare settings on your local system. Most of the systems are also licensed which provides the best environment for realistic exploitation.Tip:I made these videos so all commands are zoomed in close so you can watch on a mobile phone if desired. I hate watching videos on my smartphone and squinting at the command prompt or terminal. Never again will that happen.

课程标签

0人关注该课程

主题相关的课程