Elan olunacaq
Əyani- Cədvəl
- Elan olunacaq
- Format
- Əyani
- Müddət
- 16 həftə · 128 saat
- Dil
- Məsləhətçi ilə təsdiqləyin
Hesab yarat və müraciət et
Pentest (PEN-200 / OSCP) is a 4-month hands-on cybersecurity training program focused on penetration testing and ethical hacking. Participants learn Linux and Windows privilege escalation, web application security testing, network pivoting, Active Directory exploitation, and OSCP-style attack techniques through practical labs and real-world scenarios. The program prepares learners for the OffSec OSCP certification and professional penetration testing roles.
Modullar sürətli baxış üçün yığcam qalır. Mövzularına baxmaq üçün istənilən modulu açın.
SearchSploit, Exploit-DB, GitHub-dan exploit tapmaq. Python/Bash exploit uyğunlaşdırma. Reverse shell növləri. Shell stabilization (pty, stty).
LinPEAS ilə enum. sudo -l + GTFOBins. SUID binaries. Cron job abuse. Insecure file permissions.
Capabilities, NFS misconfig, kernel exploit axtarışı. Credential harvesting (history, config faylları). John + Hashcat, zip2john, ssh2john (raport Target No1-2 əsaslı).
WinPEAS ilə enum. Service binary hijacking, unquoted service paths, DLL hijacking. icacls, sc qc, accesschk.
Token impersonation (SeImpersonatePrivilege). PrintSpoofer / GodPotato. Scheduled tasks, registry autoruns. Credential harvesting (SAM, Sticky Notes). xp_cmdshell → PrintSpoofer zənciri (raport Target No4).
SSH -L (local), -R (remote), -D (dynamic/SOCKS5). Proxychains konfiqurasiyası. socat relay. Daxili şəbəkəyə çatmaq niyə lazımdır.
Chisel reverse SOCKS5 tunnel (raport Target No4 tam axışı). netsh portproxy, plink.exe. Fayl transfer metodları: certutil, Python HTTP server, SMB share.
HTTP/HTTPS — request/response, metodlar, status kodlar. Burp Suite: Intercept, Repeater, Intruder. gobuster ilə directory/file enum. Veb servis fingerprinting.
SQL əsasları, manual aşkarlama. UNION-based, Error-based, Blind (time-based). MSSQL xp_cmdshell ilə OS command execution (raport Target No4). SQLmap OSCP-də qadağandır — hər şey Burp Repeater ilə manual.
File upload bypass (Content-Type, extension). PHP webshell. LFI — /etc/passwd, log poisoning ilə RCE. Command injection operatorları (;, &&, |, backtick).
WordPress plugin zəifliyi (gobuster + CVE). Default credentials. zip2john + exiftool + credential spray (raport Target No2 tam axışı). Veb shell → stable shell → privesc vektoru.
AD strukturu (Domain, DC, OU, GPO, Trust). NTLM + Kerberos axışı. net / PowerView ilə manual enum (user, group, SPN, share). BloodHound giriş.
Kerberoasting: SPN→TGS→hashcat (-m 13100). AS-REP Roasting: pre-auth disabled→hash. Pass-the-Hash: impacket-psexec / evil-winrm. BloodHound attack path analizi.
psexec, wmiexec, smbexec, evil-winrm. CrackMapExec ilə credential spray. secretsdump: SAM, LSA, NTDS dump. Domain Admin ilə DC-yə psexec (raport Target No5 tam axışı).
OSCP formatı: 3 standalone (60pt) + AD set (40pt). Zaman strategiyası. Stuck olduqda nə etmək. Bonus bal (+10pt lab report). Mock imtahan: AD set + 2 standalone.
Kali Linux quraşdırma, VPN, lab mühiti. Nmap flagları (-p-, -A, -sV, NSE). SMB enum (enum4linux, smbclient).
Yalnız cari, açıq qruplar göstərilir.
“The program helped me connect individual skills into the way real teams design, build and deliver software.”
Ingress icmasından real məzun hekayələrinə baxın.
Məzun nəticələrini kəşf etWe use one Portal account for applications, assessments and future learning progress. You will not need to email your details or select the training again.
Əvvəlcə sualınız var? Məsləhətçi ilə danışınPortal hesabınızı yaradın və ya daxil olunƏlaqə məlumatlarınız vahid tələbə profilinə bağlı qalır.
Müraciət məlumatlarınızı təsdiqləyinPenetration Testing & Ethical Hacking (PEN-200 / OSCP) əvvəlcədən seçilib.
Müraciətinizi göndərinQəbul komandası müraciəti dərhal alır və Portal vasitəsilə əlaqə saxlaya bilər.
SEÇİLMİŞ TƏLİMPenetration Testing & Ethical Hacking (PEN-200 / OSCP)Əyani
Ingress Portalda davam et Artıq qeydiyyatdan keçmisiniz? Portal daxil olmağınıza imkan verəcək.