Antivirus Evasion - Process Injection and Migration

所在平台: Udemy

课程主页: https://www.udemy.com/course/process-injection-and-migration-av-evasion/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:抗病毒逃避 - 进程注入与迁移 课程概述:本课程提供了对进程注入和进程迁移技术的全面研究,这些技术是理解先进恶意软件行为和渗透测试的关键。参与者将探讨攻击者如何使用这些技术执行恶意代码、绕过安全措施并规避检测。课程涵盖一系列关键技术,包括经典进程注入、进程空洞化、解除杀毒软件钩子以及使用PerunsFart解除ntdll.dll钩子等。这些方法使攻击者能够隐秘地操作和劫持合法进程。 学生们还将学习高级概念,如区段映射,通过操纵内存区域实现隐秘代码执行,以及线程上下文操作以劫持线程执行。此外,参与者将探讨异步过程调用(APC),这使得攻击者能够在目标进程中排队代码执行,进一步增强他们的隐秘技术工具包。课程强调理解这些技术在实际攻击中的应用,以及防御者如何检测和缓解这些攻击。 通过动手实验和案例研究,学生将获得这些技术的攻击性使用和防御措施(如行为监控和内存分析)的实际经验。课程还将探讨使用现代工具和方法(如先进的终端检测与响应系统,EDR)进行检测策略。 课程结束时,参与者将深入理解进程注入与迁移,为防御这些复杂的攻击方法做好准备。 先决条件:对操作系统、编程和网络安全基础知识的基本了解。

课程评论(0条)

课程详情

This course provides a comprehensive study of process injection and process migration techniques, essential for understanding advanced malware behavior and penetration testing. Participants will explore how attackers use these techniques to execute malicious code, bypass security measures, and evade detection.The course covers a range of key techniques, including Classic Process Injection, Process Hollowing, Unhooking AV Hooks, and Unhooking AV ntdll.dll using PerunsFart. These methods allow attackers to stealthily manipulate and hijack legitimate processes. Students will also learn advanced concepts such as Section Mapping, where memory regions are manipulated for stealthy code execution, and Thread Context manipulation to hijack thread execution.Additionally, participants will explore Asynchronous Procedure Calls (APCs), which allow attackers to queue code execution within a target process, adding to their toolkit of stealth techniques. Emphasis will be placed on understanding how these techniques are used in real-world attacks and how defenders can detect and mitigate them.Through hands-on labs and case studies, students will gain practical experience in both the offensive use of these techniques and defensive measures, such as behavioral monitoring and memory analysis. The course will also explore detection strategies using modern tools and methodologies like advanced endpoint detection and response (EDR) systems.By the end, participants will have a deep understanding of process injection and migration, equipping them to defend against these sophisticated attack methods.Prerequisites: Basic knowledge of operating systems, programming, and cybersecurity fundamentals.

课程标签

0人关注该课程

主题相关的课程