PowerShell for Penetration Testing: Explore the capabilities of PowerShell for pentesters across multiple platforms
暫譯: 滲透測試的 PowerShell:探索 PowerShell 在多平台上對滲透測試者的能力
Blyth, Andrew, Murray, Campbell
- 出版商: Packt Publishing
- 出版日期: 2024-05-24
- 售價: $1,950
- 貴賓價: 9.5 折 $1,853
- 語言: 英文
- 頁數: 298
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1835082459
- ISBN-13: 9781835082454
-
相關分類:
Powershell
立即出貨 (庫存=1)
買這商品的人也買了...
-
$880$695
相關主題
商品描述
A practical guide to vulnerability assessment and mitigation with PowerShell
Key Features
- Leverage PowerShell's unique capabilities at every stage of the Cyber Kill Chain, maximizing your effectiveness
- Perform network enumeration techniques and exploit weaknesses with PowerShell's built-in and custom tools
- Learn how to conduct penetration testing on Microsoft Azure and AWS environments
- Purchase of the print or Kindle book includes a free PDF eBook
Book Description
PowerShell for Penetration Testing is a comprehensive guide designed to equip you with the essential skills you need for conducting effective penetration tests using PowerShell.
You'll start by laying a solid foundation by familiarizing yourself with the core concepts of penetration testing and PowerShell scripting. In this part, you'll get up to speed with the fundamental scripting principles and their applications across various platforms. You'll then explore network enumeration, port scanning, exploitation of web services, databases, and more using PowerShell tools. Hands-on exercises throughout the book will solidify your understanding of concepts and techniques. Extending the scope to cloud computing environments, particularly MS Azure and AWS, this book will guide you through conducting penetration tests in cloud settings, covering governance, reconnaissance, and networking intricacies. In the final part, post-exploitation techniques, including command-and-control structures and privilege escalation using PowerShell, will be explored. This section encompasses post-exploitation activities on both Microsoft Windows and Linux systems.
By the end of this book, you'll have covered concise explanations, real-world examples, and exercises that will help you seamlessly perform penetration testing techniques using PowerShell.
What you will learn
- Get up to speed with basic and intermediate scripting techniques in PowerShell
- Automate penetration tasks, build custom scripts, and conquer multiple platforms
- Explore techniques to identify and exploit vulnerabilities in network services using PowerShell
- Access and manipulate web-based applications and services with PowerShell
- Find out how to leverage PowerShell for Active Directory and LDAP enumeration and exploitation
- Conduct effective pentests on cloud environments using PowerShell's cloud modules
Who this book is for
This book is for aspiring and intermediate pentesters as well as other cybersecurity professionals looking to advance their knowledge. Anyone interested in PowerShell scripting for penetration testing will also find this book helpful. A basic understanding of IT systems and some programming experience will help you get the most out of this book.
Table of Contents
- Introduction to Penetration Testing
- Programming Principles in Power Shell
- Network Services and DNS
- Network Enumeration and Port Scanning
- The WEB, REST and SOAP
- SMB, Active Directory, LDAP, and Kerberos
- Databases: MySQL, PostgreSQL and MSSQL
- Email Services: Exchange, SMTP, IMAP, and POP
- PowerShell and FTP, SFTP, SSH and TFTP
- Brute Forcing in PowerShell
- PowerShell and Remote Control and Administration
- Using PowerShell in Azure
- Using PowerShell in AWS
- Command and Control
- Post-Exploitation in Microsoft Windows
- Post-Exploitation in Microsoft Linux
商品描述(中文翻譯)
**使用 PowerShell 進行漏洞評估與緩解的實用指南**
**主要特點**
- 在網路攻擊鏈的每個階段利用 PowerShell 的獨特功能,最大化您的效能
- 使用 PowerShell 的內建和自訂工具執行網路枚舉技術並利用弱點
- 學習如何在 Microsoft Azure 和 AWS 環境中進行滲透測試
- 購買印刷版或 Kindle 書籍可獲得免費 PDF 電子書
**書籍描述**
《PowerShell 進行滲透測試》是一本全面的指南,旨在為您提供使用 PowerShell 進行有效滲透測試所需的基本技能。
您將從熟悉滲透測試和 PowerShell 腳本的核心概念開始,打下堅實的基礎。在這部分,您將掌握基本的腳本原則及其在各種平台上的應用。接著,您將使用 PowerShell 工具探索網路枚舉、端口掃描、網路服務和數據庫的利用等內容。書中的實作練習將鞏固您對概念和技術的理解。擴展到雲計算環境,特別是 MS Azure 和 AWS,本書將指導您在雲端環境中進行滲透測試,涵蓋治理、偵查和網路複雜性。在最後一部分,將探討後利用技術,包括使用 PowerShell 的指揮與控制結構和權限提升。這一部分涵蓋了 Microsoft Windows 和 Linux 系統上的後利用活動。
在本書結束時,您將涵蓋簡明的解釋、實際案例和練習,幫助您無縫地使用 PowerShell 執行滲透測試技術。
**您將學到的內容**
- 熟悉 PowerShell 中的基本和中級腳本技術
- 自動化滲透任務,構建自訂腳本,征服多個平台
- 探索使用 PowerShell 識別和利用網路服務中的漏洞的技術
- 使用 PowerShell 訪問和操作基於網路的應用程式和服務
- 瞭解如何利用 PowerShell 進行 Active Directory 和 LDAP 的枚舉與利用
- 使用 PowerShell 的雲模組在雲環境中進行有效的滲透測試
**本書適合誰**
本書適合有志於成為滲透測試者的初學者和中級測試者,以及希望提升知識的其他網路安全專業人士。任何對於滲透測試的 PowerShell 腳本感興趣的人也會發現本書有幫助。對 IT 系統有基本了解和一些程式設計經驗將有助於您充分利用本書。
**目錄**
1. 滲透測試介紹
2. PowerShell 中的程式設計原則
3. 網路服務與 DNS
4. 網路枚舉與端口掃描
5. 網頁、REST 和 SOAP
6. SMB、Active Directory、LDAP 和 Kerberos
7. 數據庫:MySQL、PostgreSQL 和 MSSQL
8. 郵件服務:Exchange、SMTP、IMAP 和 POP
9. PowerShell 與 FTP、SFTP、SSH 和 TFTP
10. PowerShell 中的暴力破解
11. PowerShell 與遠端控制和管理
12. 在 Azure 中使用 PowerShell
13. 在 AWS 中使用 PowerShell
14. 指揮與控制
15. 在 Microsoft Windows 中的後利用
16. 在 Microsoft Linux 中的後利用