Course 9:Implementing PowerShell Security Best Practice 2019

所在平台: Udemy

课程主页: https://www.udemy.com/course/course-9implementing-powershell-security-best-practice-2019/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:课程9:实施PowerShell安全最佳实践2019 课程概述:本课程的主要目标是帮助IT专业人员和技术用户控制和自动化Windows操作系统及其应用程序的管理。为了充分利用Windows PowerShell带来的好处,同时最大限度地降低安全相关风险,了解Windows PowerShell操作安全的主要方面至关重要。课程中还将讨论Windows PowerShell在安全漏洞中的作用。 课程内容包括:探索黑客利用Windows PowerShell的常见技术,以获取对Windows操作系统的访问权,安装恶意软件,进行侦察任务,确保在目标计算机上的持久性,并促进横向移动。此外,课程还将审查一些基于Windows PowerShell的安全工具,这些工具有助于渗透测试、取证和逆向工程Windows PowerShell漏洞。课程最后将总结蓝队推荐的技术,旨在实施全面的深度防御安全,以防止基于Windows PowerShell的攻击。 **课程大纲:** 模块1,“PowerShell基础”:学习PowerShell的基本知识,包括架构设计、不同版本的使用,以及如何与PowerShell进行交互。 模块2,“PowerShell操作安全”:利用Windows PowerShell内置特性增强操作系统安全性,学习如何提升执行策略级别、处理代码签名证书和认证脚本文件。 模块3,“实施基于PowerShell的安全”:介绍提高操作系统安全的常见方法,如利用PowerShell Desired State Configuration (DSC)保护配置不受意外更改、在远程管理中实施最小权限原则和通过PowerShell日志跟踪可能的攻击事件。 模块4,“Windows PowerShell漏洞及其缓解”:从红队视角探讨黑客的常见攻击技术以及相关的渗透测试和取证工具,最后总结蓝队的推荐技术。 模块5,“网络与防火墙”:学习如何编写端口扫描脚本、测试网络服务器,并使用四种不同的方法来保护端口。 模块6,“域清单”:学习如何检测可疑配置文件,部署代码进行配置文件检测,并编写其他代码以创建AD组、用户和GPO等的报告。 模块7,“域共享”:学习如何管理网络共享,编写脚本处理域服务器共享和共享目录的安全信息。 完成此课程后,您将具备报名参加课程10的必要技能,该课程内容为:使用PowerShell和WMI攻击Windows Server 2019,并能够在该课程中编写3500多行代码的主工具脚本。

课程评论(0条)

课程详情

Course DescriptionThe primary objective of Windows PowerShell was to help IT professionals and power users control and automate the administration of the Windows operating system and applications that run on Windows.To take advantage of the benefits that Windows PowerShell has to offer, while at the same time, minimise security-related risks, it is essential to understand the primary aspects of Windows PowerShell operational security. Another aspect that is critical to consider in the context of this course is the role of Windows PowerShell in security exploits.You will then explore the most common Windows PowerShell-based techniques employed by hackers in order to leverage existing access to a Windows operating system to facilitate installation of malicious software, carry out reconnaissance tasks, establish its persistence on the target computer, and promote lateral movement. You will also review some of Windows PowerShell-based security tools that facilitate penetration testing, forensics, and reverse engineering of Windows PowerShell exploits. To conclude the course, you will provide a summary of technologies recommended by the Blue Team that are geared towards implementing comprehensive, defense-in-depth security against Windows PowerShell-based attacks.Course OutlineModule 1, "PowerShell Fundamentals", In this module, you will learn about PowerShell fundamentals, including its architectural design, its editions and versions, and basics of interacting with PowerShell, you will learn in practical the difference between FullCLR and CoreCLR, how to install PowerShell core on Windows, Linux and MAC, and how to deal with PowerShell profiles.Module 2, "PowerShell Operational Security", In this module, you will learn about enhancing operating system security by leveraging built-in Windows PowerShell features and technologies that are part of the Windows PowerShell operational environment.In practical side of this module you will learn to deal with below: 1. Upgrade execution policy level to increase security level in your network. 2. Deal with code signing certificate. 3. Authenticate script file with authorized certificate.Module 3, "Implementing PowerShell-based Security", The purpose of this module is to present the most common and effective methods of leveraging Windows PowerShell to enhance operating system security. These methods include:Protecting from unintended configuration changes by relying on PowerShell Desired State Configuration (DSC)Implementing the principle of least privilege in remote administration scenarios by using Just Enough Administration (JEA)Tracking and auditing events that might indicate exploit attempts by using Windows PowerShell logging.Module 4, "Windows PowerShell-based Exploits and their Mitigation ", In this module, we will first approach the Windows PowerShell-based security from the Red Team's perspective. We will explore the most common Windows PowerShell-based techniques employed by hackers in order to leverage existing access to a Windows operating system to facilitate installation of malicious software, carry out reconnaissance tasks, establish its persistence on the target computer, and promote lateral movement. We will also review some of Windows PowerShell-based security tools that facilitate penetration testing, forensics, and reverse engineering of Windows PowerShell exploits. To conclude the module and the course, we will provide a summary of technologies recommended by the Blue Team that are geared towards implementing comprehensive, defense-in-depth security against Windows PowerShell-based attacks.Module 5, "Network & Firewall", In this practical module, you will learn how to write ports scanner script, test network servers, and use 4 different methods to secure ports using firewall.Module 6, "Domain inventory", In this practical module, you will learn how to detect suspected profile in any domain PCs, deploy your code for profile detection, write other inventory codes to create reports of AD groups, users, GPOs..etc, write script to manage registry key and values.Module 7, "Domain shares", In this module, you will learn how to deal with network shares, you will write a script to manage following scenarios:Domain servers sharesShared Directory security infoNetwork sharesBy end of this course you have necessary skills to enroll into course 10: Hack windows Server 2019 using PowerShell & WMI, and you will be able to write the main tool script with 3500+ code lines in that course.

课程标签

0人关注该课程

主题相关的课程