Learn the Metasploit Framework inside out

所在平台: Udemy

课程主页: https://www.udemy.com/course/learn-the-metasploit-framework-inside-out/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:深入学习Metasploit框架 课程概述:本课程将覆盖Metasploit框架的所有基本方面,并将渗透测试执行标准(PTES)方法论的某些阶段与课程结构联系起来,具体包括信息收集、漏洞评估、利用和后渗透。课程内容超越基础,涉及社会工程学、权限提升、抗病毒软件的规避、持久性后门、特洛伊木马可执行文件、远程桌面、网页渗透测试、端口转发反向Shell、Beef-XSS框架和事件日志管理。参加本课程需要具备基本的软件操作能力,熟悉Linux命令行基础和一些系统管理知识。如果在学习过程中遇到困难,可以随时联系我解决。 硬件要求:建议使用至少8GB内存的主机,配有适度快速的处理器,70GB硬盘空间用于易受攻击的虚拟机,另外30GB用于Kali虚拟机,虽然这不是强制性要求,也可以选择在家网络中的另一台电脑上安装易受攻击的虚拟机,使用Kali进行工作。 课程结构共包括7个主要部分: 第一部分:设置环境并介绍渗透测试执行标准(PTES),这是进行渗透测试的顶尖方法论,同时覆盖Windows上的Metasploit框架、Metasploit社区版及Armitage。 第二部分:Metasploit的基本命令及其工作原理,如何自动化重复任务,运行漏洞利用和Metasploit模块。 第三部分:使用nmap及Metasploit中的其他工具进行目标机器的信息收集,检查安装的服务并有效映射攻击面。 第四部分:漏洞评估。检查指纹识别的服务中哪些可能存在漏洞,学习如何安装Nessus漏洞扫描仪,并与Metasploit集成以填充工作区。 第五部分:使用Metasploit对七个Metasploitable3服务进行最终利用,同时也会涉及网页渗透测试。 第六部分:通过社会工程学利用服务。主要创建社会工程学活动的攻击载体,让受害者执行恶意载荷以获取远程命令执行。我们将创建特洛伊木马文件,大幅降低抗病毒软件的检测率,结合Beef-XSS框架和Metasploit实施更复杂的攻击。 第七部分:监控用户在其机器上的活动,记录键盘操作,进行权限提升,生成持久性后门并进行日志管理。 课程最后包括总结和致谢。

课程评论(0条)

课程详情

This course will cover all of the fundamental aspects of the Metasploit framework, tying a subset of the phases of the Penetration Testing Execution Standard (PTES) methodology to the course structure. These will be specifically information gathering, vulnerability assessment, exploitation and post-exploitation. The course also goes beyond the basics by dealing with social engineering, privilege escalation, antivirus evasion, persistent backdoors, trojanizing executable files, remote desktop, web penetration testing, port forwarded reverse shells, the Beef-XSS Framework, event log management. To follow this course you will need to be confident using generic software programs, know the basics of the Linux command line and a little of system administration.If something isn't clear or doesn't work on your system you can always hit me up and we'll solve the problem. Concerning hardware requirements: a host machine with at least 8 GB of RAM with a moderately fast processor, 70 GB of hard-drive space for the vulnerable virtual machine and other 30GB for the Kali VM is a good setup to have, but not mandatory: you can also alternatively install the vulnerable machine on another PC in your home network and work with Kali on your main machine. The course is laid out in 7 main sections: Section 1: setup of our environment and introduction to the Penetration Testing Execution Standard (PTES), which is a state of art methodology to carry out a penetration test. Other Metasploit variants like the Metasploit framework on Windows, the Metasploit community edition and Armitage will be covered.Section 2: fundamental commands of Metasploit and how it works, how to automate repetitive tasks, how to run exploits and Metasploit modules.Section 3: information gathering on the target machine with nmap and the other tools available in Metasploit to check which services are installed and effectively map the the attack surface.Section 4: vulnerability assessment. We'll check which of the services fingerprinted are likely to be vulnerable. We'll learn how to install the Nessus vulnerability scanner and integrate it with Metasploit to populate its workspace.Section 5: finally exploit of seven Metasploitable3 services using Metasploit exclusively, web penetration testing will also be covered.Section 6: exploiting services via Social Engineering. We'll mainly create vectors for Social Engineering engagements, unsuspecting payloads for the victim to execute on their machine to obtain remote command execution. We'll create trojanized files, we'll greatly lower the antivirus detection rate and we'll use the Beef-XSS Framework together with Metasploit to deliver more complex attacks.Section 7: monitoring the user on his machine, logging his keyboard activity, performing privilege escalation, generating persistent backdoors and log management.Section 8: the course outro and credits.

课程标签

0人关注该课程

主题相关的课程