محتوای ارائه شده توسط Brian Johnson. تمام محتوای پادکست شامل قسمتها، گرافیکها و توضیحات پادکست مستقیماً توسط Brian Johnson یا شریک پلتفرم پادکست آنها آپلود و ارائه میشوند. اگر فکر میکنید شخصی بدون اجازه شما از اثر دارای حق نسخهبرداری شما استفاده میکند، میتوانید روندی که در اینجا شرح داده شده است را دنبال کنید.https://fa.player.fm/legal
Player FM - برنامه پادکست
با برنامه Player FM !
با برنامه Player FM !
7MS #456: Certified Red Team Professional - Part 4
Manage episode 285900870 series 2540717
محتوای ارائه شده توسط Brian Johnson. تمام محتوای پادکست شامل قسمتها، گرافیکها و توضیحات پادکست مستقیماً توسط Brian Johnson یا شریک پلتفرم پادکست آنها آپلود و ارائه میشوند. اگر فکر میکنید شخصی بدون اجازه شما از اثر دارای حق نسخهبرداری شما استفاده میکند، میتوانید روندی که در اینجا شرح داده شده است را دنبال کنید.https://fa.player.fm/legal
Hello friends! Today, Joe (Gh0sthax) and I complete our series on CRTP - Certified Red Team Professional - a really awesome pentesting training and exam based squarely on Microsoft tools and tradecraft. Specifically, Joe and I talk about:
- We don't think the training/exam is for beginners, despite how its advertised
- Both the lab PDF and PowerPoint have their own quirks - which may ultimately be teaching us not to be copy-and-paste jockeys, and instead build our own study guides and cheat sheets
- Don't let the training give you the idea that most pentests have a super fast escalation path to DA (ok yes sometimes they do, but usually we spend a LOT of hours working on escalation!)
- Watch the walkthrough videos. We repeat: WATCH THE WALKTHROUGH VIDEOS!
- Although not required, we highly recommend capturing all the flags laid out for you in the lab environment
- Know how to privesc - using multiple tools/methods
- It would be to your advantage to understand how to view/manipulate Active directory information in multiple ways
- You start the exam with no tools. So how will you be ready to upload/download tools into the exam environment so you make the most of your exam time?
- Tool X might give you wrong results - or none at all - in the lab. Do you have a backup tool Y and Z that can serve the same purpose?
- You want to be very good at Kerberos ticket crafting!
- Know all the mimikatz commands and switches and when to apply them
696 قسمت
Manage episode 285900870 series 2540717
محتوای ارائه شده توسط Brian Johnson. تمام محتوای پادکست شامل قسمتها، گرافیکها و توضیحات پادکست مستقیماً توسط Brian Johnson یا شریک پلتفرم پادکست آنها آپلود و ارائه میشوند. اگر فکر میکنید شخصی بدون اجازه شما از اثر دارای حق نسخهبرداری شما استفاده میکند، میتوانید روندی که در اینجا شرح داده شده است را دنبال کنید.https://fa.player.fm/legal
Hello friends! Today, Joe (Gh0sthax) and I complete our series on CRTP - Certified Red Team Professional - a really awesome pentesting training and exam based squarely on Microsoft tools and tradecraft. Specifically, Joe and I talk about:
- We don't think the training/exam is for beginners, despite how its advertised
- Both the lab PDF and PowerPoint have their own quirks - which may ultimately be teaching us not to be copy-and-paste jockeys, and instead build our own study guides and cheat sheets
- Don't let the training give you the idea that most pentests have a super fast escalation path to DA (ok yes sometimes they do, but usually we spend a LOT of hours working on escalation!)
- Watch the walkthrough videos. We repeat: WATCH THE WALKTHROUGH VIDEOS!
- Although not required, we highly recommend capturing all the flags laid out for you in the lab environment
- Know how to privesc - using multiple tools/methods
- It would be to your advantage to understand how to view/manipulate Active directory information in multiple ways
- You start the exam with no tools. So how will you be ready to upload/download tools into the exam environment so you make the most of your exam time?
- Tool X might give you wrong results - or none at all - in the lab. Do you have a backup tool Y and Z that can serve the same purpose?
- You want to be very good at Kerberos ticket crafting!
- Know all the mimikatz commands and switches and when to apply them
696 قسمت
همه قسمت ها
×به Player FM خوش آمدید!
Player FM در سراسر وب را برای یافتن پادکست های با کیفیت اسکن می کند تا همین الان لذت ببرید. این بهترین برنامه ی پادکست است که در اندروید، آیفون و وب کار می کند. ثبت نام کنید تا اشتراک های شما در بین دستگاه های مختلف همگام سازی شود.