|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/offensive-security-pathway-level-5-of-6/
课程评论:没有评论
**Coursera 课程总结:进攻性安全路径 - 第 5 级 (共 6 级)** 本课程是进攻性安全路径的第五阶段,旨在深化学员在渗透测试领域的实践技能,特别是在以下关键领域: * **高级持久化技术 (Windows/Linux)**:深入学习如何在攻陷系统后保持长期访问权限,包括通过操纵 Windows 计划任务、注册表修改、Linux CRON 作业、SSH 配置错误和动态链接器劫持等技术。 * **数据泄露技术**:掌握从目标系统中安全有效地窃取数据的各种方法。 * **横向移动与跳板**:学习如何在已攻陷的网络中进行探测和移动,以扩大控制范围并访问更多网络设备,同时保持隐蔽性。 * **云环境攻击 (聚焦 Azure)**:了解云环境中的安全风险,特别关注 Azure 平台的常见配置错误和利用方式,包括 Azure AD 和 IAM 的漏洞。 * **缓冲区溢出漏洞利用**:作为漏洞利用开发的基础,学习如何在 Linux 和 Windows 环境中发现并利用缓冲区溢出漏洞,以及开发相应的 exploit。 * **文档与报告撰写**:培养专业记录发现和撰写高质量渗透测试报告的能力,以便有效地向客户和利益相关者展示安全评估结果。 完成本课程后,学员将具备在复杂环境中实现长期持久化、网络渗透以及对抗性云操作的关键技术能力,为成为一名合格的进攻性安全专家打下坚实基础。
In Level 5, Offensive Security Major (OSM), you'll sharpen your technical skills with advanced persistence techniques and move toward mastering the art of post-exploitation. Whether on Windows or Linux, this module teaches you how to maintain control over compromised systems long after the initial breach. You'll learn persistence tactics like manipulating Windows Scheduled Tasks, registry hacks, or hijacking CRON jobs and SSH misconfigurations in Linux.Understanding how to move through a compromised network is critical, and this course covers pivoting and lateral movement strategies, allowing you to expand access and explore other machines in the network undetected. You'll also explore cloud environments, with a focus on Azure, learning how to exploit misconfigurations in Azure AD.Documentation and reporting are vital skills for any penetration tester. You'll learn how to compile findings, write comprehensive reports, and present professional-grade documentation to stakeholders. Finally, the course introduces buffer overflows, a foundational skill for exploit development. You'll discover vulnerabilities in both Linux and Windows environments and develop exploits to take advantage of buffer overflows.By the end of this chapter, you'll be equipped with the techniques necessary for long-term persistence, network navigation, and cloud-based exploitation, positioning yourself as a key player in offensive security operations.SyllabusDocumentation & Reporting: How to properly document vulnerabilities and write professional penetration test reports for clients and stakeholders.Advanced Windows Persistence Techniques: Techniques to maintain access to compromised systems, including Windows Scheduled Tasks, registry hacks, and hidden users.Advanced Linux Persistence Techniques: Techniques to maintain access to compromised systems, including SSH Authorized Keys, Scheduled Tasks (CRON), Shell misconfiguration and Dynamic Linker Hijacking.Data Exfiltration Techniques: Learn different techniques to exfiltrate data from systems.Pivoting / Lateral Movement: How to move within a compromised network using pivoting and lateral movement strategies to expand access.Introduction to Cloud Exploitation: Fundamentals of cloud security and how to exploit common vulnerabilities in cloud environments.Hacking Azure: Techniques specific to exploiting Azure infrastructure, including misconfigurations in Azure AD and IAM.Buffer Overflows: Exploit development focusing on discovering and exploiting buffer overflow vulnerabilities in both Linux and Windows environments.