Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
How to Hack The Box To Your OSCP (The Extra Boxes)
Rating: 4.8 out of 5(30 ratings)
1,727 students
Created byVonnie Hudson
Last updated 11/2022
English

What you'll learn

  • How to execute 20 MITRE ATT&CK Tools, Techniques and Procedures!
  • How to use over 30 modern attack tools!
  • How to setup the PERFECT modern hacking rig
  • How to finally FEEL like a confident cybersecurity professional

Course content

3 sections26 lectures4h 14m total length
  • VMWare Workstation5:14

    All the things start with VMWare Workstation! Yes, you can use VirtualBox... Yes, you can use VMWare Fusion,.. but why would you do that? VMWare Workstation is the most stable, mature hypervisor on the planet right now.  It's a proven solution for virtualization.  I've been using it for years so that's what we'll use in this course.  Strapped for cash? Don't worry - just download the trial and you'll be good to go. (for a month at least).  Let's do this baby!

  • Kali Linux8:03

    So you think you know how to setup Kali in VMWare Workstation eh? I STILL bet you'll learn something new in this lecture.  I got your back man - let's go!

  • Windows 11 Pro13:18

    Commando VM needs Windows to work.  Technically, it's only supported on Windows 10 but we're going to make it work in Windows 11.  But one problem: Windows 11 isn't simple to setup in VMWare Workstation.  It doesn't even exist in the OS drop down AND you need to use some abstruse registry hacks to make the magic happen!  But Alas! don't worry - your boy Vonnie Hudson has got your back.  I'll walk you through the setup process and show you it's not so painless (when you've got an expert holding your hand :)).

  • CommandoVM15:56

    CommandVM is the gold standard when it comes to offensive Windows distributions.  In this lecture, I'm going to walk you through the complicated and lengthy setup of this awesome attack platform.  I'll also help you carefully navigate through some rookie mistakes most people make and common pitfalls to avoid. 

  • Connecting CommandVM to HackTheBox via Kali Linux15:50

    Now we're going to setup a port forward on your Kali box so your VPN connection is shuttled through your Commando VM Windows Box.  Then we'll setup routing on the Commando VM so we can run Windows tools against the Hack The Box target!  It's a pretty cool setup.  I've also included some commands in the resource section so you can copy and paste :)

  • PimpMyKali + VSCode6:10

    PimpMyKali is the Kali setup that should have shipped with Kali.  We'll run the New VM setup and then watch the magic happen.

  • Oh My TMUX!7:50

    TMUX is the Terminal Multiplexer.  It's the leet way to manage tabs in the terminal.  In the past people would use Terminator or just open multiple tabs in the terminal.  That is NOT the modern way to hack.  You gotta look good doing it right?  So when your boss or girlfriend starts shoulder surfin' you look legit! hahah let's get it baby!

  • Docker + Rustscan7:38

    Now I'll show you the CORRECT way to install Docker in modern versions of Kali.  Hint: it has nothing to do with "apt install docker". lololz.  Yeah - why doesn't stuff have to be confusing these days??? Don't worry I got your back.  We're also going to install an awesome nmap wrapper known as rustscan.  It can speed up your scans by multiple times so you'll want to check this out... oh and did I mention it has colors!?!?? lol

  • FeroxBuster + Project Discovery (nuceli, naabu, httpx and subfinder)11:00

    Seriously?? TWO OF MY FAVORITE TOOLKITS! FeroxBuster and almost anything by ProjectDiscovery.  These are the best of the best when it comes to MODERN hacking.  Out with the old in with the new.  If you want to use modern tools against targets let me show you just how freggin' legit Ferox and the open source Project Discovery attack stack are.

  • Burp Community + Burp Browser + Wappalyzer4:44

    Say Goodbye to FoxyProxy and say Hi to Burp Browser.  Burp has finally perfected the in-built browser and it's now based on Chromium!  In this lecture I'll show you how to update Burp (two ways to do it), how to tweak the Burp Suite Community attack proxy and how to install the awesome Wappalyzer extension directly into the Burp Browser!  Let's go baby!

Requirements

  • HackTheBox VIP Account
  • Laptop

Description

Are you ready to feel the fun of KNOWING how to hack?

In this course you will learn how to build a modern hacking lab.

You'll learn how to master the latest tools and attacker tradecraft for compromise victim environments.

You'll finally feel the pleasure and freedom of knowing what you're talking about.

I had a BLAST creating this course for you guys and I'm so excited to share all the awesome with you.

In this course you will learn:


  • ping (for recon)

  • nmap

  • rustscan

  • whatweb + Wappalyzer

  • Burp Browser (why you should say NO to FoxyProxy!)

  • feroxbuster

  • kerbrute

  • ldp

  • ldapsearch

  • crackmapexec

  • smbclient

  • How to install Impact from scratch (because you know... it always breaks)

  • getTGT

  • GetUserSPNs

  • What the heck a SPN is anyway! You'll learn that - finally

  • hashcat

  • Silver Tickets

  • ticketer

  • How to manually convert passwords into NTLM hashes

  • SQL Commands

  • How to build a reverse shell in Powershell

  • rlwrap

  • netcat

  • iconv

  • xxd

  • base64

  • PEAS-ng (winPEAS)

  • Powershell Remoting

  • evil-winrm

  • Reverse Engineering .NET Binaries

  • Wireshark

  • Insecure Deserialization

  • ysoserial

  • JuicyPotatoNG

  • Persistence Mechanisms

  • Beyond Root: Threat Hunting the Attack

  • Beyond Root: Mitigations

Seriously! This is the best course I've ever made on hacking.  It's the combination of all my experience jam packed into one tiddy little course.

You'll also get:


  • Hacking links and resources

  • Complete commands to copy and paste directly into your terminal!

So what are you waiting for?

Why are you still reading?

Enroll now and change your life.

Let's go!

Who this course is for:

  • New SOC Analysts
  • New Penetration Testers
  • New Red Teamers
  • New Blue Team Defenders
  • Help Desk Analysts (wanting to get into cyber)
  • Network Admins, Sys Admins and Network Engineers (wanting to get into cyber)
  • Cybersecurity Managers (who want to know how the bad guy compromise environments)