|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/offensive-security-certified-professional-oscp-red-team/
课程评论:没有评论
课程名称:进攻安全认证专业人员(OSCP+)红队 课程概述: 本课程旨在帮助学员为进攻安全认证专业人员加(OSCP+)考试做好充分准备,该认证正式称为OffSec PEN-200(OSCP+)。该课程是一个专注于情景驱动的实践考试课程,专为道德黑客、渗透测试人员和红队专业人员设计。学员将通过模拟真实世界情况的挑战性选择题,掌握认证的关键领域。OffSec PEN-200(OSCP+)认证是进攻安全领域最受尊重的资质之一,它不仅测试学员的技术能力,还考察他们的方法论、批判性思维和在压力下的适应能力。课程强调PEN-200课程的关键概念,并要求学员在类似考试的环境中应用这些知识。 课程内容将通过六个练习测试来进行,分别聚焦于考试的关键领域: 1. **网络安全基础与报告**:理解渗透测试的核心原则、伦理考虑、参与范围的设定以及专业安全报告的撰写艺术。 2. **信息收集与枚举**:学习如何通过被动和主动侦查、DNS分析、服务发现和网络映射有效收集目标情报。 3. **漏洞扫描与利用基础**:使用公共漏洞和工具识别并验证系统弱点,应用获取初始访问权限所需的基础利用技术。 4. **Web应用攻击**:探讨OWASP前10大漏洞,实践利用实际的Web漏洞,如SQL注入、跨站脚本(XSS)和文件包含缺陷。 5. **客户端攻击及后期利用**:模拟社会工程、网络钓鱼和客户端攻击,学习提高权限、维持访问和在被攻陷环境中横向移动的方法。 6. **活动目录利用**:针对企业Windows网络,使用高级AD技术,包括Kerberos利用、凭证转储、BloodHound分析和域提升。 本课程特别适合以下人群: - 准备参加OSCP+认证的学生 - 正在学习或复习OffSec PEN-200培训的学习者 - 精炼进攻方法论的红队专业人员 - 正在进入高级角色的安全分析师、道德黑客和渗透测试人员 无论您是在进行PEN-200学习的深度阶段,还是准备迎接OSCP+考试,这门课程都将帮助您评估自己的准备情况,发现知识的薄弱环节,并通过真实、高影响力的问题集来加强考试的关键概念。开始更智能的培训,像考试期望您那样测试自己。
Get fully prepared for the Offensive Security Certified Professional Plus (OSCP+), officially known as OffSec PEN-200 (OSCP+), with this focused, scenario-driven practice exam course. Designed for ethical hackers, penetration testers, and red team professionals, this course helps you master the critical domains of the certification through challenging multiple-choice and multi-select questions modeled after real-world situations.The OffSec PEN-200 (OSCP+) certification is one of the most respected credentials in offensive security. It tests not only your technical abilities but also your methodology, critical thinking, and adaptability under pressure. This course reinforces the key concepts from the PEN-200 curriculum and challenges you to apply them in an exam-like environment.You'll progress through six practice tests, each focused on a key domain of the exam:Domain 1: Cybersecurity Foundations & ReportingUnderstand the core principles of penetration testing, ethical considerations, engagement scoping, and the art of writing professional-grade security reports.Domain 2: Information Gathering & EnumerationLearn how to effectively gather intelligence on your target through passive and active reconnaissance, DNS analysis, service discovery, and network mapping.Domain 3: Vulnerability Scanning & Exploitation BasicsIdentify and validate system weaknesses using public exploits and tools. Apply foundational exploitation techniques essential for gaining initial access.Domain 4: Web Application AttacksExplore the OWASP Top 10 and practice exploiting real-world web vulnerabilities such as SQL injection, cross-site scripting (XSS), and file inclusion flaws.Domain 5: Client-Side Attacks & Post-ExploitationSimulate social engineering, phishing, and client-side attacks. Learn to escalate privileges, maintain access, and move laterally through compromised environments.Domain 6: Active Directory ExploitationTarget enterprise Windows networks using advanced AD techniques including Kerberos exploitation, credential dumping, BloodHound analysis, and domain escalation.This course is ideal for:Students preparing for the OSCP+ certificationLearners enrolled in or reviewing the OffSec PEN-200 trainingRed team professionals refining their offensive methodologiesSecurity analysts, ethical hackers, and penetration testers transitioning into advanced rolesWhether you're deep into your PEN-200 studies or ready to take on OSCP+, this course will help you assess your preparedness, uncover knowledge gaps, and reinforce key exam concepts through realistic, high-impact question sets.Start training smarter-test yourself like the exam expects you to think.