How To Hack The Box To Your OSCP (Part 3)

所在平台: Udemy

课程主页: https://www.udemy.com/course/how-to-hack-the-box-to-your-oscp-part-3/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** Hack The Box 攻破之道 (第三部分) **课程概述:** 本课程是“攻破 Hack The Box 机器”系列的三部曲终章,专为希望提升技能、挑战高难度机器并获得系统性学习体验的学习者设计。与市面上许多仅展示攻击过程的资源不同,本课程深入剖析了专家级黑客的思维方式和攻击流程,提供详细的步骤拆解、完整的命令参考,并将所有攻击技术映射到 MITRE ATT&CK 框架。 通过本课程,您将获得“幕后”视角,了解如何在复杂场景下进行思考和决策,一步步克服难关,最终成功攻破目标机器。在渗透完成后,课程还将带领您深入分析主机日志、漏洞应用程序的源代码以及事件日志,以理解和追踪导致初始入侵的漏洞。 **您将学习到(从进攻角度):** * **MITRE ATT&CK Enterprise Framework TTPs** * **常用工具:** ping, nmap, rpcdump, rpcclient, smbmap, smbclient, crackmapexec, whatweb, Wappalyzer, curl, openssl, gowitness, Burp Proxy, Burp Embedded Chromium Browser, feroxbuster, wfuzz, rlwrap, PEASS-ng, certutil, PowerView, Rubeus, Chisel, FoxyProxy SOCKS proxy, wireshark * **Web 应用攻击:** SQL 注入 (SQLi), 反射型 XSS, SSTI, Polyglot Payloads, 命令注入 * **反向 Shell:** Powershell (包括 Upgrade), Netcat, Meterpreter, PSExec, NoPAC * **Base64 编码的 Powershell Payload** * **Blue Team 工具(用于理解):** wmic, tasklist, Get-WmiObject * **CSRs** * **Lateral Movement** * **Resource Development:** Commando VM!, Exploit Testing and Maldoc creation (漏洞利用和恶意文档制作) * **Defense Evasion(防御规避):** charlotte, Meterpreter, certutil, SharpCollection, PowerView, Rubeus, Certifydate * **Detection Engineering(检测工程):** Log Review (日志审查) * **Secure Coding Principles(安全编码原则):** Source Code Review (源代码审查) **课程目标:** 本课程旨在帮助您“将您的游戏提升到下一个水平”(level up your game),让您在学习过程中获得乐趣,并将技能提升至“野兽模式”(beast mode)。如果您准备好迎接挑战并深入了解网络攻防的奥秘,本课程将是您的理想选择。

课程评论(0条)

课程详情

Are you ready to level up your game?Ready for the hardest boxes to hack?Want a challenge without feeling overwhelmed or confused?I finally did it. I finally decided to create the last series in my three part collection on pwning Hack The Box machines.There are tons of free write-ups and Youtube videos on-line that will show you how to breach a box but almost none of them break down the process step by step.And almost none of them include all the commands as a tidy reference.And even fewer map all attacks to the MITRE ATT & CK Matrix.What I've done is taken you on a journey into my mind as I help you understand how an expert hacker thinks. You will get the behind-the-curtain view into my thought process as I think through difficult scenarios and carefully step through each obstacle until the box is pwned.In addition, after we pop the box, we'll take a step back and understand what vulnerabilities led to the initial intrusion vector by exploring host logs, vulnerable application source code and event logs.I've prepared everything you need for learning success in one convenient package.So, I'm going to ask again - are you ready to level up your game?You are about to learn the following tools and techniques from an offensive perspective:MITRE ATT & CK Enterprise Framework TTPs pingnmaprpcdumprpcclientsmbmapsmbclientcrackmapexecwhatwebWappalyzercurlopensslgowitnessBurp ProxyBurp Embedded Chromium BrowserferoxbusterwfuzzWeb Application Attacks: SQLiWeb Application Attacks: Reflected XSSWeb Application Attacks: SSTIPolyglot PayloadsWeb Application Attacks: Command InjectionReverse Shells: PowershellReverse Shells: Powershell UpgradeReverse Shells: NetcatReverse Shells: MeterpeterReverse Shells: PSExecReverse Shells: NoPACBase64 Encoded Powershell PayloadsrlwrapPEASS-ngBlue Team: wmicBlue Team: tasklistBlue Team: Get-WmiObjectCSRsChiselProxyChainsFoxyProxy SOCKS ProxiestsharkresponderhashcatLateral MovementResource Development: Commando VM!Resource Development: Exploit Testing and Maldoc creationDefense Evasion: charlotteDefense Evasion: MeterpretercertutilSharpCollectionPowerViewRubeusCertifydate (sounds lame but we actually use it in a way you've never seen before)Detection Engineering: Log ReviewSecure Coding Principles: Source Code ReviewIf this doesn't excite you, you are not the right person for this course. But if you're ready to freggin' have a blast and take your learning and skills to beast mode click Buy Now and let's begin!

课程标签

0人关注该课程

主题相关的课程