Kubernetes Hacking for Beginners

所在平台: Udemy

课程主页: https://www.udemy.com/course/kubernetes-hacking-for-beginners/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Kubernetes 入门黑客技术 课程概述:这个全面的课程旨在填补 Kubernetes 基础知识与安全测试之间的空白,专为希望在云原生环境中扩展技能的安全爱好者和渗透测试人员设计。您将通过实际操作练习和案例,学习如何识别、评估和利用 Kubernetes 集群中的安全漏洞。 课程开始时将介绍 Kubernetes 的基本概念,包括 pods、服务、部署和网络,为理解攻击面提供基础知识。您将学习如何使用 Minikube 或 Kind 等工具设置自己的测试环境,确保可以安全独立地进行实践。 随着课程的深入,您将发现 Kubernetes 部署中的常见错误配置和安全弱点,例如: - 暴露的 Kubernetes 仪表板和 API 服务器 - 错误配置的 RBAC 权限 - 容器逃逸技术 - 密钥管理漏洞 - 网络策略缺口 本课程强调实践技能,提供引导实验室,您将学习: - 使用专门针对 Kubernetes 环境的安全评估工具 - 对集群组件进行侦察 - 利用服务账户令牌和凭据 - 在集群内提升权限 - 在命名空间和 pods 之间进行横向移动 - 识别和利用脆弱的工作负载 同时,课程特别关注防御性考虑,帮助您理解如何记录发现并提供可操作的修复建议。课程结束时,您将具备独立进行 Kubernetes 集群安全评估的技能,并为加固这些环境提供有价值的见解。 先决条件:对 Linux 命令和容器概念的基本熟悉。所有必要的工具和技术将得到详细解释,使本课程对开始踏入容器编排安全领域的安全从业人员而言,能够轻松理解和掌握。

课程评论(0条)

课程详情

This comprehensive course bridges the gap between Kubernetes fundamentals and security testing, designed for security enthusiasts and penetration testers who want to expand their skillset into cloud-native environments. You'll learn how to identify, assess, and exploit security vulnerabilities in Kubernetes clusters through hands-on exercises and practical scenarios.The course begins with essential Kubernetes concepts, including pods, services, deployments, and networking, providing you with the foundational knowledge needed to understand the attack surface. You'll learn how to set up your own testing environment using tools like Minikube or Kind, ensuring you can practice safely and independently.As you progress, you'll discover common misconfigurations and security weaknesses in Kubernetes deployments, such as:Exposed Kubernetes dashboards and API serversMisconfigured RBAC permissionsContainer escape techniquesSecrets management vulnerabilitiesNetwork policy gapsThe course emphasizes practical skills with guided laboratories where you'll learn to:Use security assessment tools specific to Kubernetes environmentsPerform reconnaissance on cluster componentsExploit service account tokens and credentialsEscalate privileges within the clusterMove laterally between namespaces and podsIdentify and exploit vulnerable workloadsSpecial attention is given to defensive considerations, helping you understand how to document findings and provide actionable remediation advice. By the end of the course, you'll have the skills to independently conduct security assessments of Kubernetes clusters and provide valuable insights for hardening these environments.Prerequisites include basic familiarity with Linux commands and container concepts. All necessary tools and techniques will be thoroughly explained, making this course accessible to security practitioners beginning their journey into container orchestration security.

课程标签

0人关注该课程

主题相关的课程