Share E-Book

渗透测试实战第三版(红队版) (it-ebooks)(Z-Library)

Author

Rating No ratings yet

Log in to rate

Science
Language English

No Description

Format EPUB
Size 19.2 MB
205
Views

AI Guide

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

Full assistant
AI guide
【One-Line Pitch】 A hands-on red-team playbook that walks you through a full adversary simulation—from building C2 infrastructure and evading antivirus to Active Directory exploitation and reporting—for security practitioners who already know the basics and want to operate like a real threat actor. 【Book Arc】 - **Opening (~0%–10%)**: Frames the red-team mindset versus traditional pentesting, sets up the fictional "Cyber Space Kittens" engagement, and covers legal/authorization warnings plus the assumed-breach exercise concept. - **Early (~10%–30%)**: Builds the attack infrastructure—VPS setup, Metasploit, Cobalt Strike, PowerShell Empire, dnscat2, and other C2 frameworks—and introduces MITRE ATT&CK as the planning backbone. - **Middle (~30%–55%)**: Moves into reconnaissance and initial access: environment probing, scan diffing, cloud scanning, subdomain discovery, then web exploitation (XSS, NoSQL injection, deserialization, SSRF, XXE) and network footholds via Responder, CrackMapExec, and credential harvesting. - **Late (~55%–80%)**: Covers post-exploitation depth—privilege escalation on Windows and Linux, lateral movement (Pass-the-Hash, DCOM, RDP tunneling), Active Directory/Kerberos abuse, BloodHound, and social engineering (phishing, macro/DDE payloads, domain lookalikes). - **Ending (~80%–100%)**: Closes with physical access attacks (LAN Turtle, Bash Bunny), AV/network evasion and custom malware development, automation, password cracking, and post-engagement analysis and reporting. 【Key Takeaways】 - **Red teaming differs from pentesting in goal, not just tools** (Opening): the focus shifts from finding vulnerabilities to testing detection and response, measured by metrics like time-to-detect (TTD) and time-to-mitigate (TTM). - **Infrastructure is a first-class concern** (Early): reusable, redirectable C2 setups using domain fronting and CDNs let you survive takedowns and blend traffic with legitimate services. - **C2 diversity matters** (Early): frameworks like Cobalt Strike, Empire, and dnscat2 each solve different problems—SMB beacons for internal pivoting, DNS tunneling for restricted egress. - **Web exploitation remains a primary entry vector** (Middle): the book walks through XSS variants, NoSQL injection, deserialization, template injection, SSRF, and XXE with practical lab scenarios. - **Credential access drives lateral movement** (Late): Responder, CrackMapExec, Pass-the-Hash, and SPN enumeration form the chain from a single foothold to domain-wide compromise. - **Active Directory is the endgame** (Late): BloodHound/SharpHound mapping, DCOM abuse, and domain controller hash dumping show how attackers escalate from workstation to domain. - **Evasion requires custom tooling** (Ending): recompiling Meterpreter, code caves, PowerShell obfuscation, and application whitelist bypasses are presented as necessary skills, not optional extras. - **Reporting and metrics close the loop** (Ending): the book emphasizes translating red-team activity into actionable data for defenders, not just a list of exploited hosts. 【Reading Tips】 - **Deep-read the infrastructure and evasion chapters** (Early and Ending): these are the most reusable and hardest to improvise; skim the tool installation steps if you already have a lab. - **Treat the labs as mandatory practice**: the book is explicitly exercise-driven; reading without reproducing the scenarios will not build the muscle memory it aims for. - **Expect a steep curve on Active Directory and Kerberos**: if you lack AD fundamentals, pause and study those before the lateral movement chapters. - **Use MITRE ATT&CK as a companion map**: keep the matrix open while reading to see how each technique fits into a broader TTP taxonomy. - **Re-read after a gap**: the author himself notes that two or three passes with digestion time in between are typical for absorbing the material. 【Coverage Limits】 This guide is based on stratified excerpts covering the table of contents, introduction, and early-to-middle chapters; later chapters on physical attacks, evasion, and reporting are summarized from headings and brief fragments, so specific techniques and lab details in those sections are not fully represented.

Passage locations

Excerpt 1
文件 1.8.2.1 非宏的 Office 文件 —— DDE 1.8.2.2 隐藏的加密 payload 1.8.2.3 利用社会工程学攻破内网 Jenkins 1.8.3 本章总结 1.8.4 第6章 短传——物理访问攻击 1.9 ID 卡复制器 1.9.1 绕过入口点的物理工具 1.9.2 LAN Turt...
View in text
Excerpt 2
看看他们的防御团队是否能够发现或阻止你。 你要决定用什么类型的 TTP(战术策略,威胁情报和恶意程序)去进行你的工作呢?在这场战斗中,你前期需要做大量的信息收集工作,去观察寻找他们外部基础设施的薄弱点,社工他们公司的员工,提升你的权限,获取内部网络的信息,在整个内网中进行漫游,并且能够最终窃取有关 KITT-3n...
View in text
Excerpt 3
d-keywords=books”; 主机 header 设置为 Amazon: header “Host” “www.amazon.com”; 甚至一些自定义服务器的 header 也从 C2 服务器发回: header “x-amz-id-1” “THKUYEZKCKPGY5T42PZT”; header “...
View in text
Excerpt 4
ershell.exe,而是在 powershell 运行空间环境(.NET)中运行 powershell 命令和函数。它包含了大量的 PowerShell 攻击模块和二进制文件,使后期利用过程变得更加容易。我们尝试的是建立一个‘一体化’的后渗透利用工具,我们可以使用它来绕过所有保护措施(至少是其中一些),p0w...
View in text

Recommended for You

Loading recommended books...
Failed to load, please try again later

Tip the Site

Scan the WeChat Pay or Alipay code to tip. No login required.

WeChat Pay
Alipay
← Back to List