Windows & AD Pentesting - Hands-on Lab Scenarios

所在平台: Udemy

课程主页: https://www.udemy.com/course/windows-ad-pentesting-hands-on-lab-scenarios/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**课程名称:** Windows & AD Pentesting - 实操实验场景 **课程概述:** 这是一门面向初级到中级安全专业人士和爱好者的课程,旨在深化对 Windows 和 Active Directory (AD) 安全的理解。课程内容 100% 专注于 Windows,深入探讨 Windows 和 AD 的完整渗透测试生命周期。 课程将引导学员学习红队和道德黑客的技术战术(TTPs),并通过一个模拟企业网络的 Windows 网络演习环境(Kinetic)展示真实世界的场景。Kinetic 由 SlayerLabs 提供,包含 25 个 Windows 虚拟机,划分为 5 个域和 6 个子网,专为渗透测试设计。 本课程和网络演习的目标是为学员提供 Windows 和 AD 安全的高层次技术概述,以及真实的场景和学习机会,帮助他们熟练掌握 Windows AD 渗透测试。学员将有机会亲自动手,完成从侦察到后渗透的整个过程。 课程内容精炼,仅涵盖 Windows 相关主题。学员应具备基础的进攻安全、道德黑客和渗透测试 TTPs 知识。例如,虚拟机设置、网络基础知识或 Kali 工具安装等基本内容将不予讲解。 每个主题都深入技术层面,提供命令行示例和详细解释。主题包括但不限于: * **域枚举:** 使用 BloodHound, PowerView, ldapsearch 和 Dsquery。 * **初始漏洞利用:** AS-REP Roasting, Kerberoasting, Follina, Sharpoint Exploits, 和密码喷洒。 * **权限提升:** 使用 WinPEAS, 存在的第三方凭据,以及 AlwaysInstallElevated。 * **后渗透:** 如 Golden Ticket 攻击, Pass-the-Ticket, Overpass-the-Hash, Pass-the-Hash, NTLM 和 MsCache 哈希的抓取与破解,以及 DPAPI。 课程主要使用 Kali Linux,同时也利用 Slayer Labs Kinetic 演习环境中的 Windows 目标作为跳板机,通过 WinRM 和 SMB 等内置服务进行操作。学员应熟悉 Kali Linux 以及 Linux 和 Windows 命令行。课程中大多数命令会提供下载资源。常用的 Kali 工具包括 Impacket Suite, CrackMapExec, Evil-Winrm 和 Metasploit。

课程评论(0条)

课程详情

This 2023 course is targeted for Beginner to Intermediate security professionals and enthusiasts who want to learn more about Windows and Active Directory security. Topics covered are 100% Windows related and dive into the full pentesting lifecycle of Windows and Active Directory.The course guides the student through red team and ethical hacking TTP's while showcasing real-world scenarios on a Windows cyber-range which mimics a corporate network. The cyber-range, Kinetic is hosted by SlayerLabs and contains 25 Windows VM's with 5 Domains and 6 subnets all engineered to exploit!The mission of this course and cyber-range is to provide the user with a technical high-level overview of Windows and Active Directory security, along with realistic scenarios and learning opportunities to become proficient in Windows AD Pentesting. The goal is to provide real-world scenarios so the student can get hands-on keyboard and start running through the entire process from Reconnaissance to Post-Exploitation.The course has been designed to trim the fat and only covers Windows related topics. With that, the student is expected to know basic TTP's in relation to offensive security, ethical hacking and pentesting. For example - covering how to setup a VM in VirtualBox, explaining the basics of networking or installing additional tools on Kali will not be covered.Each topic dives into the technical side, providing command-line examples and explanations along the way. Topics covered (but are not limited to):Domain Enumeration with BloodHound, PowerView, ldapsearch and Dsquery.Initial Exploitation of AS-REP Roasting, Kerberoasting, Follina, Sharpoint Exploits, and Password Spraying.PrivEsc with WinPEAS, Saved 3rd party creds, and AlwaysInstallElevated.Post-Exploitation using Golden Ticket attacks, Pass-the-Ticket, Overpass-the-Hash, Pass-the-Hash, Dumping & Cracking NTLM & MsCache hashes and DPAPI. Course content uses Kali the majority of the time, but also uses Slayer Labs Kinetic range Windows targets as jump boxes, utilizing built-in services such as WinRM and SMB. Students should be comfortable using Kali Linux along with Linux and Windows command-line. Majority of the commands used throughout this course are provided as a downloadable resource once purchased. Common tools used on Kali are Impacket Suite, CrackMapExec, Evil-Winrm and Metasploit.

课程标签

0人关注该课程

主题相关的课程