Getting Started with the Bash Bunny from Hak5

所在平台: Udemy

课程主页: https://www.udemy.com/course/bashbunny-intro/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:初识Hak5的Bash Bunny 课程概述:本课程将教您如何利用一款硬件设备Bash Bunny获得关键性初始访问权限。您将探索如何利用人机界面设备(HID)模拟来攻陷目标,以及如何编写自己的脚本以创建自定义有效载荷。在红队活动中,初始访问和如何提取重要信息是最重要的环节之一。本课程“使用Bash Bunny进行初始访问”将让您了解Bash Bunny的功能以及为什么它是红队工具包中的关键初始访问工具。 威胁行为者利用对设备的物理访问来获取存储在设备上的凭据。例如,APT集团DarkVishnya曾使用Bash Bunny设备渗透欧洲主要银行。能够在几秒钟内秘密插入一个设备,破解目标并提取机密数据,而无需任何用户交互,这对红队成员来说可能是一个颠覆游戏规则的改变。 在本课程中,您将学习如何利用这个工具实现您的红队目标。您将了解兔子脚本,如何加载和修改它们,以获取和提取目标的关键文件和信息。Bash Bunny非常灵活,还可以在网络攻击链的多个阶段发起多种攻击,包括啟动Empire的阶段。您还将学习到其他资源,以帮助您为特定任务制定完美的攻击向量。 完成本课程后,您将具备执行针对客户的APT能力模拟攻击的技能和知识。

课程评论(0条)

课程详情

In this course, you will learn how to gain that crucial initial access using a hardware device called a Bash Bunny. You will explore how to leverage Human Interface Device (HID) emulation to compromise targets, and how to write your own scripts to create custom payloads.One of the most important parts of a Red Team engagement is the initial access and how to exfiltrate important information to help you gain a deeper foothold into your target environment. In this course, Initial Access with Bash Bunny, you will learn the capabilities of the BashBunny and why it is a key initial access tool in the red team toolkit. Threat actors take advantage of physical access to devices in order to obtain credentials stored on the device. APT groups such as DarkVishnya have used Bash Bunny devices to help infiltrate major banks across Europe. Having the ability to covertly plug in a device that hacks your target in seconds and pull out confidential data ready for use with no interaction required can be a game changer for red team members. You will learn how to utilize this tool to help you achieve your red team goals. Within this course you will learn about bunny scripts, how to load them and even modify them to help obtain and exfiltrate key files and information from your target. The Bash Bunny is amazingly adaptable and can also be used to launch a number of attacks at multiple stages of the cyber kill chain including launching stagers for Empire and you will also show you where to find additional resources to help craft your perfect attack vector for those specialist jobs. When you have finished with this course, you will have the skills and knowledge to perform attacks from your team that simulate APT capability against your client

课程标签

0人关注该课程

主题相关的课程