|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/practical-ics-pentesting/
课程评论:没有评论
课程名称:实用工业控制系统渗透测试 课程概述:想要在Shodan上或自己公司中进行ICS/OT的黑客攻击?那可不行!我相信最好的学习方式就是实践经验。ICS/OT安全是所有从事工业控制系统技术人员和工程师的新兴重要技能。虽然有很多开源工具可用于调查工业控制系统的网络安全,但合适的培训机会却不多。对于IT渗透测试的学习者,像HackTheBox和VulnHub这样的机会比比皆是,可以尝试渗透测试工具和黑客技能。然而,专注于ICS的培训平台几乎不存在,或者以收费超过1000欧元的无聊研讨会形式出现。 在本研讨会上,您将学习Kali和其他开源工具的渗透测试工具,并可以在6个互动的工业控制器模拟中进行实践。当然,这些模拟并不完美,因此我将向您展示在两个真实PLC上使用的工具和技术。该研讨会具有很高的实践性,鼓励您积极参与!有超过30个激动人心的任务等待着您,让您逐步深化技能。 重要提示:ICS的渗透测试与传统IT世界的渗透测试不可同日而语。工业设施需要持续运行,几乎没有厂商愿意冒着生产停顿的风险。通常,安全测试在最低或第二低的攻击性水平下进行。因此,如果您希望通过缓冲区溢出、内核漏洞、权限升级和root shell来控制设备,那么您来错地方了。 如果您对ICS的安全分析感兴趣并且已经具备了一定的工业网络安全基础,那么这个课程正适合您!目前正在为(CEH)认证伦理黑客学习的朋友们,请注意:从v12版本开始,OT知识是必需的!本课程提供了一个动手实践的入门,帮助您理解OT硬件的典型漏洞! 想了解如何保护ICS/OT设备吗?欢迎加入我的课程《评估与保护工业控制系统》。 请注意,使用的软件不是我开发的。在遇到问题时,我只能提供有限的帮助,请联系软件发布者以获取支持。安装说明已根据我所知尽力而为,但安装的责任在于参与者。
Hacking ICS/OT on shodan or in your own company? Better not!I believe that the best way to learn is with practical experience. ICS/OT Security is a new and important skill for all technicians and engineers working on industrial control systems. There are quite a few open source tools that can be used to investigate the cyber security of industrial control systems, but unfortunately there is no suitable training opportunity.For learners of IT pentesting, there are plenty of opportunities like HackTheBox or VulnHub, where pentest tools and hacking skills can be tried out. Training platforms with ICS focus either don't exist or come in the form of a boring seminar with over 1000€ participation fee.In this workshop you will learn important pentest tools from Kali and open source tools and you can try them out in 6 interactive simulations of industrial controllers. Of course the simulations are not perfect, so I will show you the tools and techniques on two real PLCs.The workshop has a high practical part and encourages you to participate! There are more than 30 exciting tasks waiting for you, with which you can deepen your skills bit by bit!Important: The pentesting of ICS cannot be compared to the typical pentesting of the IT world. Industrial plants need to be continuously available and hardly any plant operator wants to risk a production stop. Typically, security testing is performed at the lowest or second lowest aggressiveness level. So if you are hoping to pwn your device with buffer overflows, kernel exploits, privilege escalation and root shells, you are in the wrong place.Are you interested in security analysis of ICS and do you already have basic knowledge of industrial cyber security? Then this is the right place for you!Are you currently studying for the (CEH) Certified Ethical Hacker? From v12 on knowledge in OT is required! This course offers you a hands-on introduction to understand the typical vulnerabilities of OT hardware!Curious about safeguarding of ICS/OT devices? Join my course Assessing and Protecting Industrial Control Systems.Please note that the software used is not mine. I can only offer limited assistance in case of problems. Please contact the publisher of the software for help. The installation instructions were created to the best of my knowledge, but the responsibility for the installation lies with the participants.