|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/how-to-use-ai-and-llms-for-offensive-and-defensive-security/
课程评论:没有评论
课程名称:如何利用AI和LLM进行攻防安全 课程概述:本课程将教授如何利用人工智能(AI)和大型语言模型(LLMs)在攻防安全中发挥作用。讲师马丁·沃尔克(Martin Voelk)是一位拥有25年网络安全经验的专家,持有多项高级认证,包括CISSP、OSCP、OSWP、Portswigger BSCP、CCIE、PCI ISA和PCIP。他目前为一家大型科技公司担任顾问,并参与漏洞赏金计划,发现了成千上万处关键和高危漏洞。 本课程包括理论和实践实验部分,视频内容易于跟随和复制。主要内容包括: - AI/LLM简介 - 模型/用户界面及本地设置 - 最常见的LLM模型 - 隐私RAG(检索增强生成) - 前端工具(Open WebUI, Jan AI, LMStudio等) - Ollama、Huggingface基础提示 - 提示工程:零样本、少样本、思维链 - 系统提示 - 创建自定义机器人、提示泄露和绕过 - 故障排除 - API使用和工具介绍 - YoloFabric LLM CLI - Burp AI功能探索 - AI登录序列、访问控制漏洞、影子重放器 - AI HTTP分析、LLM报告 使用AI/LLM进行攻防安全的实际应用: - 创建渗透测试机器人和示例 - 创建红队机器人和示例 - 生成HDI攻击和C&C攻击 - 创建蓝队机器人和示例 - 事件响应机器人 - 工具支持助手机器人 - 代码分析机器人 备注与免责声明:本课程仅供教育目的使用。所有信息不得用于恶意利用,仅应在您获得攻击授权的目标上使用。
How to leverage AI and LLMs for both offensive and defensive SecurityYour instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.This course has a both theory and practical lab sections The videos are easy to follow along and replicate. The course features the following:AI/LLM IntroductionModels / UIs and local setupMost common LLM ModelsPrivacy RAG (Retrieval Augmented Generation)Front Ends (Open WebUI, jan ai, lmstudio etc.)Ollama Huggingface PromptingBasicsPrompt EngineeringZero-shot, few-shot, Chain of ThoughtSystem PromptsMake your own bots Prompt leakage Jailbreaking TroubleshootingAPI usageToolsYoloFabric LLM CLIBurp AI FeaturesExplore Issue FeatureExplainer FeatureAI Login SequenceBroken Access ControlShadow RepeaterAI HTTP Analyzer LM ReportUsing AI/LLM for Offensive SecurityCreate Pentest bots and examplesCreate Redteam bots and examplesHDI attack generationC & C attack generation Using AI/LLM for Defensive SecurityCreate Blue Team bots and examplesIncident Response botTool support companion bots Code analysis bots Notes & DisclaimerThis course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.