Pentesting Primer 101 - Hands-on Lab Scenarios

所在平台: Udemy

课程主页: https://www.udemy.com/course/slayerlabs-pentesting-primer-101/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:Pentesting Primer 101 - 动手实验场景 课程概述:这门2023年的课程专为初级安全专业人士和有兴趣的爱好者设计,旨在更加深入地了解渗透测试和红队作战,配合实际案例。课程涵盖了攻防安全的基础知识,并详细介绍了渗透测试的整个生命周期,从信息收集到后期利用。课程通过现实世界的网络攻击场景,带领学生学习红队和道德黑客的技术与战术,使用仿目标网络的网络实验室Neotek。 Neotek由Slayer Labs托管,包括11个专为易受攻击而设计的Windows和Linux虚拟机。课程围绕Neotek Campaign展开,以情节为基础,为攻击者提供提示和针对性的指导。完成课程后,学生能够掌控所有11个Neotek范围目标。本课程及网络实验室的使命是为用户提供道德黑客的高水平技术概述,以及 realistic 的场景和学习机会,以便在渗透测试的基础知识上变得熟练。 课程目标是提供真实的场景,让学生亲自操作,从信息收集到后期利用的整个过程中都能实战演练。课程设计精简内容,期望学生在实践实验室时能够暂停、重看或进行额外的研究,前提是学生已经了解与攻防安全、道德黑客和渗透测试相关的基本工具和技术。如虚拟机的设置、网络基础知识或Kali工具的安装不会在课程中覆盖。 每个主题深入技术细节,提供命令行示例和解释。课程内容主要涵盖但不限于:使用Nmap脚本和Metasploit进行信息收集;通过公开的Exploit-DB概念证明进行初步利用,Web应用和易受攻击服务的利用,以及使用Hydra和CrackMapExec的暴力破解;使用LinPEAS、WinPEAS进行特权提升、凭证收集、Metasploit后模块和数据包嗅探;通过Mimikatz和John the Ripper收集和破解Linux和Windows哈希,收集SSH密钥、文件传输和建立隧道。 课程大多数使用Kali,结合Slayer Labs的Neotek范围目标进行情报收集和作为跳板,利用内置服务如Nmap和SSH端口转发。学生应熟悉Kali Linux及Linux和Windows的命令行操作。尽管该课程对渗透测试友好,学员应具备IT基础知识和安全基本概念。

课程评论(0条)

课程详情

This 2023 course is targeted for Beginner security professionals and enthusiasts who want to learn more about Penetration Testing and Red Teaming with practical examples. Topics cover the basics of offensive security and dive into the full pentesting lifecycle from Enumeration to Post-Exploitation.The course guides the student through red team and ethical hacking TTP's while showcasing real-world scenarios on a cyber-range which mimics a target network. The cyber-range, Neotek is hosted by Slayer Labs and contains 11 Windows and Linux VM's all engineered to exploit! The course walks through the Neotek Campaign which is stroyline-based, providing hints and targeted directions to the attacker. Completing the course will allow you to own all 11 Neotek range targets!The mission of this course and cyber-range is to provide the user with a technical high-level overview of ethical hacking, along with realistic scenarios and learning opportunities to become proficient in the basics of Pentesting. The goal is to provide real-world scenarios so the student can get hands-on keyboard and start running through the entire process from Enumeration to Post-Exploitation.The course has been designed to trim the fat with the expectation that students can pause, re-watch or do additional research if they are following along hands-on in the labs. With that, the student is expected to know basic tools and TTP's in relation to offensive security, ethical hacking and pentesting. For example - covering how to setup a VM in VirtualBox, explaining the basics of networking or installing additional tools on Kali will not be covered.Each topic dives into the technical side, providing command-line examples and explanations along the way. Topics covered (but are not limited to):Enumeration with Nmap scripts and Metasploit.Initial Exploitation with public Exploit-DB proofs of concepts, WebApp and vulnerable service exploitation & Brute Forcing with Hydra and CrackMapExec.PrivEsc with LinPEAS, WinPEAS, Credential Harvesting, Metasploit Post Modules & Packet Sniffing.Post-Exploitation by Collecting and Cracking Linux and Windows hashes with Mimikatz and John the Ripper, Harvesting SSH Keys, Transferring Files & Establishing Tunnels.Course content uses Kali the majority of the time, but also uses Slayer Labs Neotek range targets for intel collection and as jump boxes, utilizing built-in services such as Nmap and SSH portforwarding. Students should be comfortable using Kali Linux along with Linux and Windows command-line. This course is Begineer-friendly in relation to Penetration Testing, however the student should have prior knowledge in IT fundamentals and Security essentials.

课程标签

0人关注该课程

主题相关的课程