|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/python-digital-forensics-binary-exploits-with-python/
课程评论:没有评论
**Coursera 课程总结:Python:数字取证与二进制漏洞利用** 本课程由 Daryl Bennett 和 Sam Bowne 共同教授,旨在教授学员如何利用 Python 进行高效的网络调查和取证分析。课程内容全面,分为两个主要部分: **第一部分:Python 数字取证 (Python Digital Forensics)** * **网络取证基础:** 学习如何读取、排序和嗅探原始数据包,以及分析网络流量,这是任何调查的关键环节。 * **系统分析工具:** 掌握在 Windows 和 GNU/Linux 环境下进行全面调查所需的 Python 工具。 * **二进制文件分析:** 学习如何解析 PE 和 ELF 二进制文件中的数据。 * **易失性内存分析:** 了解获取和分析易失性内存镜像的最佳工具,以揭示系统运行时的详细信息。 * **攻击者视角:** 学习如何运用 Python 进行枚举、漏洞利用和数据渗出,以“像攻击者一样思考”。 **第二部分:Python 二进制漏洞利用 (Binary Exploits with Python)** * **二进制漏洞概念:** 理解二进制漏洞是如何被利用的,例如绕过密码或产品密钥验证,以及注入特洛伊木马代码。 * **漏洞利用开发流程:** 实践完整的漏洞利用开发过程,包括寻找漏洞、在调试器中分析崩溃、创建精心构造的攻击以及在 Windows 和 Linux 上实现远程代码执行。 * **调试与利用:** 学习使用 gdb 调试器分析 Linux 可执行文件,并利用 Python 进行漏洞利用。在 Windows 环境下,则使用 Immunity debugger 和 Python。 **作者简介:** * **Daryl Bennett:** 美国空军网络空间威胁模拟团队经理,拥有丰富的攻防安全经验,专注于风险分析和网络空间系统安全。 * **Sam Bowne:** 自2000年起在旧金山城市学院教授计算机网络和安全课程,并在多个知名安全会议上发表演讲和进行实践操作。 通过本课程,学员将能够熟练运用 Python 进行复杂的数字取证任务,并掌握二进制漏洞的原理和利用技术,从而在网络安全领域具备更强的实战能力。
Python is uniquely positioned as a programming language to perform cyber investigations and perform forensic analysis. Unleash the power of Python by using popular libraries and Python tools to help you create efficient and thorough forensics investigations.This learning paths follows a practical approach & can be of utmost importance as it guides you to read, sort, and sniff raw packets and also analyze network traffic. You will learn various tools required to perform a complete investigation with the utmost efficiency in both Windows and GNU/Linux environments with Python. It then explains binary exploits that allow you to skip past unwanted code, such as the password or product key tests, and add Trojan code. You will perform the exploit development process: finding a vulnerability, analyzing a crash in a debugger, creating a crafted attack, and achieving remote code execution on Windows and Linux. By the end of the course, you will be able to make the most of Python processes and tackle varied, challenging, forensics-related problems. So, grab this course and think like an attacker!Contents and OverviewThis training program includes 2 complete courses, carefully chosen to give you the most comprehensive training possible.The first course, Python Digital Forensics starts with network forensics, an important aspect of any investigation. You will learn to read, sort, and sniff raw packets and also analyze network traffic. These techniques will help you drive your host analysis. You will learn about tools you'll need to perform a complete investigation with the utmost efficiency in both Windows and GNU/Linux environments with Python. Next, you will learn more advanced topics such as viewing data in PE and ELF binaries. It's vital to analyze volatile memory during an investigation as it provides details about what is actually running on a given system. So, you will learn the best tools to obtain and analyze volatile memory images. Finally, you will learn how to use Python in order to think like an attacker. You will complete enumeration, exploitation, and data exfiltration. By the end of the course, you will be able to make the most of Python processes and tackle varied, challenging, forensics-related problems. So, grab this course and think like an attacker!The second course, Binary Exploits with Python takes you through explaining binary exploits that allow you to skip past unwanted code, such as the password or product key tests, and add Trojan code. You will perform the exploit development process: finding a vulnerability, analyzing a crash in a debugger, creating a crafted attack, and achieving remote code execution on Windows and Linux. You will use the gdb debugger to analyze Linux executables and Python code to exploit them. On Windows, you'll use the Immunity debugger and Python.About the Authors: Daryl Bennett is a manager of a Cyberspace Threat Emulation team with the United States Air Force, where he leads military and civilian members in the employment and execution of offensive security on order to audit the security of network infrastructures. He is a key operator, focusing on risk analysis and the overall security posture of cyberspace systems. Additionally, he has 5+ years' experience working in the open-source community. He is a development specialist in a wide range of domains, including GNU/Linux applications, Android mobile, and autonomous systems. He is passionate about sustaining, developing, and implementing both current and new technologies while practicing analytical problem-solving and learning as much as possible in the process.Sam Bowne has been teaching computer networking and security classes at City College San Francisco since 2000. He has given talks and hands-on at DEFCON, HOPE, B-Sides SF, B-Sides LV, BayThreat, LayerOne, Toorcon, and many other schools and conferences. Credentials: Ph.D., CISSP, DEF CON Black-Badge Co-Winner