|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/practical-threat-hunting/
课程评论:没有评论
课程名称:实用网络威胁猎捕 课程概述:在本课程中,学员将学习如何进行威胁猎捕和妥协评估。第一模块中,我创建了一个真实攻击场景作为对手模拟,并在演示实验室中进行讲解。我向学生介绍了网络威胁情报的来源和类型,以及基本定义和术语,如指标(IOC)、技术、战术和程序(TTP)、网络攻击链模型和事件响应步骤。我批评了安全设备的能力,以解释为什么我们需要监控和安全信息事件管理(SIEM)基础设施。 在第二模块中,我提供了关于真实攻击技术的理论知识,例如SQL注入、缓冲区溢出利用代码、SSH隧道方法等。我教学生如何收集完整的pcap流量以及分析应使用的工具。在这一模块中,我分析隧道、枢轴点、网络攻击、远程代码执行利用、Web Shell及从pcap文件中提取的网络攻击流量,并分享我的真实分析经验。 第三模块中,我首先理论介绍Windows基本进程、进程注入、空洞技术及相关工具,PE注入和线程注入的技术与工具。然后,我教授学生如何提取内存样本以进行内存取证,并分析Stuxnet攻击、Cridex、Zeus、Darkcomet Rat的内存映像及DLL注入事件的内存映像。 在第四模块中,我在ELK平台上执行威胁猎捕。首先,我解释用于猎捕的常见事件ID号,并分析一个真实的场景。我检测到恶意Word文档、HTA文件、未签名的EXE文件、VBS文件等。我教授如何检测和调查隧道方法、持久性方法(如注册表、服务、计划任务等)。我们在攻击实验室中使用一些技术,如lolbas,并通过MITRE框架进行调查和映射。课程中还包含谷歌快速响应和Osquery的使用及实验。 重要说明:我的Udemy培训仅包含视频,不共享内存映像、pcap和虚拟机。我正在云端创建实验室环境,完成后会另行通知并可单独购买。
In this course students will learn counducting threat hunting and compromise assessment. In the first module I created a real life attack scenerio as an adversary simulation in a demo lab. I lecture to my students about cyber threat intelligence sources and types, basic definition and terms like IOC, TTP, Cyber Kill Chain Model, Incident Response Steps. I critisize security devices capabilities for explaining why we need monitoring and SIEM infrastructure. In the second module I give you therotical knowledge about real attack techniques like SQL Injection, Buffer OverFlow Exploit Codes, SSH tunneling methods and more.I teach to my students how to collect full pcap traffic and which tools should be used for analysing. In module two I analysis tunnels, pivot points, web attacks, Remote Code Execution Exploits, Web Shells and Web attacks traffic from pcap files and I share my real world analysis experince with my students. In third module, First I present the fundamental windows processes and process injections, hollowing techniques and tools, pe injection and thread injection techniques and tools as theoritically. Then I teach you dumping memory samples for memory forensic and I analyze Stuxnet attack's memory image, Cridex, Zeus, Darkcomet Rat's Memory images and DLL injection event's memory image. In fourth module I perform therat hunting over ELK. First I explain the event id numbers which are used common for hunting and I analyze a real life scenerio. I detected malicious word documents, hta files, unsigned exe files, vbs files and more. I teach you how to detect and investigate tunneling methods, persistency methods like registeries, services, schedule tasks. Some techniques are used like lolbas in attack lab and we investigate and map them by using MITRE framework. Google Rapid Response And Osquery usage and labs are performed by me. Important Note: My Udemy Training only includes the videos. Memory images, pcaps and virtual machines aren't shared in Udemy. I am creating lab environment in a different platform in Cloud and when I complete the Lab network in cloud I will announce and You can purchase separately from this.