|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/practical-nessus-vulnerability-scanning/
课程评论:没有评论
课程名称:实用Nessus漏洞扫描 课程概述: 欢迎来到实用Nessus漏洞扫描课程!这是一个全面、实践性强的课程,旨在教会你如何有效使用Tenable Nessus这一行业领先的漏洞扫描工具。无论你是网络安全初学者、网络管理员,还是准备 CEH、Security+ 或 OSCP 认证的安全分析师,本课程将帮助你建立识别、评估和报告各种环境下漏洞的实用技能。 你将通过建立真实的实验室环境,配置易受攻击的目标,并进行有凭据和无凭据的扫描,获得实践经验。该课程将装备你分析和缓解各种操作系统和网络设备中的漏洞的实际技能。 适合对象: - 希望提升技能的网络安全学生和 IT 专业人士 - 道德黑客、SOC 分析师和渗透测试人员 - 希望增强组织安全性的网络/系统管理员 - 任何希望通过实际案例学习 Nessus 的人 课程内容: 1. 引言与基础知识:理解漏洞和漏洞管理的核心概念,学习漏洞处理生命周期、常见漏洞和暴露(CVE),以及如何使用常见漏洞评分系统(CVSS)解读风险。同时深入了解Nessus生态系统及其产品版本和许可选项。 2. 使用EVE-NG建立实验室环境:通过设置完整的虚拟实验室,安装和配置Kali Linux、交换机、Nessus实验室映像和防火墙,获得实践经验,模拟真实的网络拓扑。 3. 安装Nessus:获得逐步指导,学习如何获取Nessus Essentials许可证,并在Windows 11、Ubuntu Linux和Kali Linux等多个平台上安装Nessus。熟悉其特点和导航的Web界面。 4. 扫描与分析:掌握Nessus扫描的详细课程,包括扫描模板、严重性级别和不同的扫描方法。执行ping唯一和主机发现等发现扫描,了解凭据和无凭据扫描之间的关键区别。 5. 高级扫描:通过复杂的扫描技术提升技能,包括Active Directory、FortiGate防火墙和Cisco交换机的漏洞评估。探索适用于大型和多样化网络的动态扫描。 完成本课程后,你将能够自信地使用Nessus进行漏洞评估,准确解读结果,并将在真实安全环境中应用你的技能。
Course Description:Are you ready to master one of the most powerful tools in vulnerability assessment?Welcome to Practical Nessus Vulnerability Scanning - a comprehensive, hands-on course designed to teach you how to effectively use Tenable Nessus, the industry-leading vulnerability scanner used by cybersecurity professionals around the world.Whether you're a cybersecurity beginner, network administrator, or a security analyst preparing for certifications like CEH, Security+, or OSCP, this course will help you build real-world skills to identify, assess, and report vulnerabilities in any environment.You'll gain hands-on experience by building a real-world lab using EVE-NG, configuring vulnerable targets, and performing both credentialed and non-credentialed scans. This course equips you with practical skills to identify, analyze, and mitigate vulnerabilities across a variety of operating systems and network devices.Who This Course is For:Cybersecurity students and IT professionals looking to upskillEthical hackers, SOC analysts, and penetration testersNetwork/system admins who want to enhance their organization's securityAnyone interested in learning Nessus through real-world, practical examplesWhat You'll Learn:Introduction & Fundamentals:Start by understanding the core concepts of vulnerabilities and vulnerability management. Learn about the lifecycle of vulnerability handling, common vulnerabilities and exposures (CVE), and how to interpret risk using the Common Vulnerability Scoring System (CVSS). Dive into the Nessus ecosystem, exploring its product editions and licensing options.Lab Environment Setup with EVE-NG:Gain practical experience by setting up a full virtual lab environment using EVE-NG. You'll install and configure Kali Linux, switches, Nessus lab images, and firewalls to simulate a realistic network topology - the perfect playground to test and scan.Installing Nessus:Get step-by-step guidance on obtaining the Nessus Essentials license and installing Nessus on multiple platforms, including Windows 11, Ubuntu Linux, and Kali Linux. Explore the web interface to get comfortable with its features and navigation.Scanning & Analysis:Master Nessus scanning with detailed lessons on scan templates, severity levels, and different scanning methods. Perform discovery scans like ping-only and host discovery, as well as OS identification. Understand the critical difference between credentialed and non-credentialed scans through practical labs.Advanced Scanning:Advance your skills with complex scanning techniques including Active Directory, FortiGate firewalls, and Cisco switches vulnerability assessments. Explore dynamic scans tailored for large and diverse networks.By the end of this course, you'll confidently perform vulnerability assessments using Nessus, interpret results accurately, and apply your skills in real-world security environments.