|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/most-complete-real-world-ethical-hacking/
课程评论:没有评论
**Coursera 课程总结:2022 全方位实战道德黑客** 本课程专为希望掌握道德黑客技能的学习者设计,强调理论与实践相结合,并在动手操作中深入学习。课程要求学习者具备一定的网络基础知识。 **课程主要内容分为四大模块:** **1. MITRE 框架:** * 深入学习 MITRE ATT&CK 框架及其工作原理,并掌握 MITRE ATT&CK Navigator 的使用。 * 了解面向蓝队和调查人员的 DETT&CT 框架及其操作。 * 学习威胁狩猎方法论 TaHiTI 的工作原理,并初步了解 MaGMa Use Case (UCS) 框架。 * 介绍 MITRE Cyber Analytics Repository (CAR) 框架、MITRE D3FEND 框架、MITRE ENGENUITY 框架、MITRE Engage 框架及 MITRE RE&CT 框架。 **2. 开源情报 (OSINT):** * 本模块特别适合道德黑客、调查人员和研究人员。 * 学习使用搜索引擎、暗网进行 OSINT。 * 掌握搜索引擎聚类技术。 * 学习 Whois 和反向 Whois 查询。 * 学习使用 Spiderfoot 进行网站分析。 * 了解 DNS 记录和 DNS 分析工具。 * 学习无线 OSINT 技术。 * 通过 Recon-ng 等工具和网站学习电子邮件 OSINT。 * 学习人们 OSINT 技术。 * 掌握图像 OSINT 技术,如反向图像搜索。 * 学习 OCR(光学字符识别)技术在图像 OSINT 中的应用。 * 了解 Sock Puppet 在社交网络中的运用。 * 学习 Twitter 和 Facebook 等社交网络 OSINT。 * 全面学习 Maltego 的功能和使用,包括基础操作、网站分析及 Footprint Machine 的不同层级。 * 学习文档编写,并提供文档模板。 **3. 网络渗透测试:** * **二层攻击:** 学习 CDP/LLDP 侦察、CDP 泛洪、CAM 表溢出攻击、ARP 欺骗攻击、VLAN 跳过攻击(交换机欺骗和双层标记)以及生成树协议 (STP) 攻击。 * **三层攻击:** 学习思科密码解密攻击(Type 5 & Type 7)、DHCP 饥饿攻击以及 FHRP 协议攻击(HSRP 攻击)。 * **监控攻击:** 学习日志欺骗攻击和日志 DDoS 攻击。 * **DNS 攻击:** 学习 DNS 欺骗攻击和 DNS 放大攻击。 * 介绍防火墙渗透测试的步骤。 **4. 客户端渗透测试:** * 学习 Metasploit 框架的组成部分。 * 掌握使用 Metasploit 进行服务器端和客户端攻击。 * 学习通过绕过用户访问控制 (UAC) 进行权限提升。 * 学习后渗透攻击,如远程嗅探和主机 DNS 欺骗。 课程中的所有技术均经过高度实操性检验,旨在帮助学习者在课程结束时成为一名经验丰富的道德黑客。 **注意:** 本课程纯属教育目的,所有攻击均在学员自己的实验环境中进行。本课程由 Hamed Mehdi 创建,与任何其他组织无关,学员将获得 Udemy 的课程完成证书。
Welcome to this comprehensive Ethical Hacking course...!This course assumes you have prior Networking knowledge. This course is practical but it won't neglect the theory. You'll learn everything Practically by exploiting everything such as Network Infrastructure Devices (Switch & Router) and Client (Windows 10) and you will never waste your time theoretical lecturesThis course is divided into 4 main sections1- MITRE FrameworksIn this Section, you will Learn MITRE Frameworks Such as:MITRE ATT & CK Framework and how it really works and how to use MITRE ATT & CK Navigator.You will learn DETT & CT Framework for Blue Teams and Investigators and how to use ityou will learn Threat Hunting Methodology (TaHiTI) for Threat Hunting, and how it works and introduction to MaGMa Use Case (UCS) Framework.and I will introduce MITRE Cyber Analytics Repository (CAR) Framework, MITRE D3FEND Framework, MITRE ENGENUITY Framework, MITRE Engage Framework, and MITRE RE & CT Framework.2- Open-source intelligence (OSINT)This Section is ideal for Ethical Hackers, Investigators and ResearchersYou will learn Search Engines, Dark Web For OSINTYou will learn Search Engine ClusteringYou will Learn Whois and Reverse WhoisYou will learn Spiderfoot for Website Analysis.You will learn DNS Records and DNS Analysis ToolsYou will learn Wireless OSINTYou will learn Email OSINT with Tools such as Recon-ng and WebsitesYou will learn People OSINTYou will learn Image OSINT Techniques such as Reverse Image SearchYou will learn OCR Technology for Image OSINTYou will learn Sock Puppet for Social NetworksYou will learn Social Networks OSINT such as Twitter and FacebookYou will learn Maltego and how it works.You will learn Maltego BasicsYou will learn Website analysis with MaltegoYou will learn Footprint Machine Levels with maltegoYou will learn documentation and see document template3- Network Penetration Testingin This section, You will learn Layer 2 Attacks such as:CDP/LLDP Recon and CDP FloodingCAM Table Overflow AttackARP Spoofing AttackVlan Hopping Attack (Switch Spoofing)Vlan Hopping Attack (Double Tagging)Spanning-Tree Protocol (STP) AttackYou will learn Layer 3 Attacks such as:Cisco Password Decryption Attacks (Type 5 & Type 7)DHCP Starvation AttackFHRP Protocol Attacks (HSRP Attack)You will learn Monitoring Attacks such as:Log Spoofing AttackLog DDoS Attackyou will learn DNS Attacks such as:DNS Spoofing AttackDNS Amplification AttackFirewall Pentesting Steps4- Client Penetration TestingYou will learn Metasploit Framework ComponentsYou will learn Server-Side Exploitation using MetasploitYou will learn Client-Side Exploitation using MetasploitYou will learn Privilege Escalation using Bypass User Access Control (UAC)You will learn Post-Exploitation Attacks such as Remote SniffingYou will learn Post-Exploitation Attacks such as Host-Based DNS PoisoningAll the techniques in this comprehensive course are highly practical and at the end of this course, expected you to become an expert in Ethical HackingNotes:This course is created for educational purposes only. all the attacks are launched in my own lab. This course is a product of Hamed Mehdi and no other organization is associated with it or a certification exam but you will receive a Course Completion Certification from Udemy