|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/attacking-active-directory-with-advanced-techniques/
课程评论:没有评论
**课程名称:** 攻击活动目录:高级技术与实战操作 **课程概述:** 本课程是一项深入的、实践性强的培训项目,专为希望提升利用和攻击活动目录(AD)环境技能的网络安全专业人士、道德黑客和渗透测试人员而设计。通过本课程,学员将掌握一系列高级技术,用于发现和利用AD系统中的漏洞,从而深入了解如何有效地保护AD基础设施。 **核心学习目标:** * **侦察:** 学习高级侦察技术,收集关于活动目录基础设施的关键信息,包括域控制器、用户、组和信任关系。掌握绘制AD环境图的方法,识别潜在的攻击面和弱点。 * **利用(投毒与中继):** 深入研究NTLM中继攻击、SMB中继和Kerberos票据篡改等技术,通过各种攻击向量利用AD系统。 * **活动目录用户枚举利用:** 精通从AD用户和组中提取敏感信息,并利用这些数据发起定向攻击。 * **使用Metasploit攻击活动目录:** 了解如何利用强大的Metasploit框架 against AD环境发起复杂的攻击,包括漏洞利用和后渗透活动。 * **攻击活动目录证书服务:** 探索利用AD证书服务中的技术,绕过安全机制并获取未经授权的访问。 * **MSSQL服务器利用:** 学习如何识别和利用与活动目录集成的MSSQL服务器中的配置错误和漏洞,可能导致权限提升和数据泄露。 * **用户ACL利用:** 深入了解活动目录的访问控制列表(ACLs),并学习如何操纵权限以获取未经授权的访问和提升权限。
Course Overview: The "Attacking Active Directory with Advanced Techniques" course is an intensive and hands-on training program designed for cybersecurity professionals, ethical hackers, and penetration testers who wish to elevate their skills in exploiting and attacking Active Directory (AD) environments. This comprehensive course covers a wide array of advanced techniques that participants can use to discover and exploit vulnerabilities in AD systems, gaining invaluable insights into securing AD infrastructures effectively.Key Learning Objectives:Reconnaissance: Learn advanced reconnaissance techniques to gather critical information about Active Directory infrastructures, including domain controllers, users, groups, and trusts. Understand how to map out the AD environment to identify potential attack surfaces and weaknesses.Exploiting with Poisoning and Relay: Dive into techniques like NTLM relay attacks, SMB relay, and Kerberos ticket manipulation to exploit AD systems through various attack vectors.Active Directory User Enumeration Exploits: Master the art of extracting sensitive information from AD users and groups, and use this data to launch targeted attacks.Hacking Active Directory with Metasploit: Understand how to utilize the powerful Metasploit framework to launch sophisticated attacks against AD environments, including exploiting vulnerabilities and post-exploitation activities.Hacking Active Directory Certificate Services: Explore techniques to exploit Certificate Services in AD environments, bypassing security mechanisms and gaining unauthorized access.MSSQL Servers Exploitation: Learn how to identify and exploit misconfigurations and vulnerabilities in MSSQL servers integrated with Active Directory, potentially leading to privilege escalation and data exfiltration.User ACL Exploits in Active Directory: Delve into Active Directory's Access Control Lists (ACLs) and understand how to manipulate permissions to gain unauthorized access and escalate privileges.