|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/offensive-security-pathway-level-2-of-6/
课程评论:没有评论
课程名称:进攻性安全路径 - 级别 2 之 6 课程概述: 在这个进攻性安全官(OSO)级别 2 的课程中,您将深入学习中级的进攻性安全概念,进一步推进网络安全的学习旅程。课程将探讨虚拟化工具如 VMware、VirtualBox 和 Hyper-V 的重要性,这些工具能够在隔离环境中安全地测试漏洞和技术。您还将提高在 Windows 和 Linux 操作系统上的技能,重点关注用户管理、系统配置,以及识别常见漏洞。 在网络方面,您将深入了解 DNS、防火墙和数据包分析,借助 Wireshark 等工具获得对 TCP、UDP 和 ICMP 网络协议的实践经验。此外,您将熟练掌握命令行界面,如 PowerShell 和 Bash,通过基础脚本在 Bash、PowerShell 和 Python 中实现系统控制和过程自动化。 课程还将引入开放源信息(OSINT),教您如何从公开来源收集有价值的信息。您将学习社交工程技术,包括网络钓鱼、鱼叉式钓鱼和伪装,并了解如何通过识别关键战术来防御这些攻击。本章非常适合那些具有基础进攻性安全知识的学习者,他们希望将技能提升到一个新的水平,学习将技术专长与社交工程见解相结合。 课程大纲包括: 1. 虚拟化基础:介绍 VMware、VirtualBox 和 Hyper-V 等工具及其在创建安全隔离环境中的重要性。 2. Windows 中级知识:涵盖中级 Windows 操作系统知识,包括用户管理、系统配置和常见 Windows 漏洞。 3. Linux 中级知识:对 Linux 命令、服务和配置的中级理解。 4. 网络中级知识:进一步探索网络概念,包括 VLAN、防火墙和基本数据包分析。 5. 网络协议与数据包分析:理解网络协议(如 TCP、UDP、ICMP)并使用 Wireshark 进行数据包分析。 6. 命令行界面:深入探讨 PowerShell(Windows)和 Bash(Linux)等命令行工具,以进行系统控制和自动化。 7. 自动化的基础脚本编写:介绍 Bash、PowerShell 和 Python 等脚本语言,以高效自动化任务和管理系统。 8. 开放源信息(OSINT):学习如何找到公共中可用的信息。 9. 社交工程导论:社交工程的基础知识,包括网络钓鱼、鱼叉式钓鱼和伪装,以操纵个人披露信息或凭证。 10. 社交工程防御技术:从进攻的角度识别和防御社交工程攻击的方法。 此课程将为希望提升中级进攻性安全技能的学习者提供丰富的知识和实践经验。
In this Level 2 course, Offensive Security Officer (OSO), you'll take the next step in your cybersecurity journey by diving deeper into intermediate offensive security concepts. You will explore the importance of virtualization tools like VMware, VirtualBox, and Hyper-V for safely testing exploits and techniques in isolated environments. You'll also enhance your skills in both Windows and Linux operating systems, focusing on user management, system configurations, and identifying common vulnerabilities.On the networking side, you'll delve into DNS, firewalls, and packet analysis, gaining hands-on experience with network protocols like TCP, UDP, and ICMP using tools like Wireshark. You'll also become more proficient in using command-line interfaces such as PowerShell and Bash for controlling systems and automating processes with basic scripting in Bash, PowerShell, and Python.Additionally, this course introduces you to OSINT, teaching you how to gather valuable information from public sources. You'll explore social engineering techniques-phishing, spear-phishing, and pretexting-and learn to defend against these attacks by recognizing key tactics.This chapter is ideal for those with a foundational knowledge in offensive security who are ready to take their skills to the next level, learning to combine technical expertise with social engineering insights.SyllabusVirtualization Basics: Introduction to tools like VMware, VirtualBox, and Hyper-V, and their importance in creating safe and isolated environments for testing.Windows Medium Knowledge: Intermediate Windows OS knowledge including user management, system configurations, and common Windows vulnerabilities.Linux Medium Knowledge: Intermediate-level understanding of Linux commands, services, and configurations.Networking Medium Knowledge: Further exploration into networking concepts, covering VLANs, firewalls, and basic packet analysis.Network Protocols & Packet Analysis: Understanding network protocols (e.g., TCP, UDP, ICMP) and using tools like Wireshark for packet analysis.Command Line Interfaces: In-depth exploration of command-line tools like PowerShell (Windows) and Bash (Linux) for system control and automation.Basic Scripting for Automation: Introduction to scripting languages like Bash, PowerShell, and Python to automate tasks and manage systems efficiently.OSINT: Learn what usable information is out there in the public and how to find it.Introduction to Social Engineering: Basics of social engineering, including phishing, spear-phishing, and pretexting, to manipulate individuals into revealing information or credentials.Social Engineering Defense Techniques: How to recognize and defend against social engineering attacks from an offensive perspective.