Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Offensive Security Pathway - Level 4 of 6
11 students

Offensive Security Pathway - Level 4 of 6

Offensive Security Colonel (OSC) - This will make you a hacker!
Created byJarno Baselier
Last updated 3/2025
English

What you'll learn

  • Explore more advanced web attacks, including SQL Injection, Cross-Site Request Forgery (CSRF), Remote File Inclusion (RFI), and Server-Side Request Forgery (SSR
  • Understand post-exploitation techniques to gather sensitive data, monitor user activities, and maintain access.
  • Master privilege escalation techniques on both Windows and Linux systems using tools like WinPEAS and LinPEAS.
  • Learn how to hack Active Directory environments through techniques like Kerberoasting, Pass-the-Hash, and Bloodhound exploitation.
  • Execute advanced network attacks, including Man-in-the-Middle (MITM), ARP spoofing, and DNS poisoning.
  • Discover specialized Windows and Linux hacking techniques targeting advanced and lesser-known attack vectors.
  • And more…

Course content

1 section53 lectures10h 33m total length
  • 4.1 Intro1:47
  • 4.2 Course Content1:57
  • 4.3 Web Proxy Tools and BurpSuite29:03
  • 4.4 Web Reconnaissance Tools7:55
  • 4.5 cURL8:30
  • 4.6 Basic Web Knowledge28:37
  • 4.7 Basic Website Enumeration17:54
  • 4.8 API Testing10:17
  • 4.9 Cross-Side Request Forgery5:38
  • 4.10 Server-Side Request Forgery3:28
  • 4.11 Cross-Site Scripting19:48
  • 4.12 Directory Traversal11:22
  • 4.13 File Inclusion - Local and Remote6:47
  • 4.14 PHP Wrappers6:13
  • 4.15 File Upload Vulnerabilities5:00
  • 4.16 Command Injection4:24
  • 4.17 SQL Injection47:11
  • 4.18 Active Directory Introduction11:00
  • 4.19 Active Directory Enumeration26:10
  • 4.20 Mapping Active Directory - Bloodhound30:47
  • 4.21 AD Password Spraying2:34
  • 4.22 AS-REP Roasting7:57
  • 4.23 Kerberoasting9:10
  • 4.24 DES-Based AS-REP Roasting and Kerberoasting12:31
  • 4.25 Golden & Silver Tickets16:25
  • 4.26 Pass the Hash and OverPass the Hash18:21
  • 4.27 Pass the Ticket4:00
  • 4.28 Relay NTLMv2 Hashes4:23
  • 4.29 TimeRoasting5:43
  • 4.30 Active Directory User Security Permissions12:28
  • 4.31 Unconstrained Delegation32:59
  • 4.32 Constrained Delegation23:13
  • 4.33 Resource-Based Constrained Delegation28:37
  • 4.34 Windows Privilege Escalation - Manual Enumeration23:49
  • 4.35 Windows Privilege Escalation - Automatic Enumeration tools & techniques13:24
  • 4.36 Windows Shadow Copies4:47
  • 4.37 Binary & DLL Hijacking14:45
  • 4.38 Unquoted Service Paths4:21
  • 4.39 Scheduled Tasks6:38
  • 4.40 Windows Exploits2:53
  • 4.41 Abusing Windows Privileges7:17
  • 4.42 Exploiting Microsoft Office Macro's15:29
  • 4.43 Abusing Microsoft Library Files and Shortcuts11:32
  • 4.44 Linux Privilege Escalation - Manual Enumeration23:14
  • 4.45 Linux Automatic Enumeration6:35
  • 4.46 SUID Programs and Linux Capabilities13:08
  • 4.47 Special Sudo Permissions5:36
  • 4.48 Exploiting Writeable Path2:05
  • 4.49 SSH Key Injection2:09
  • 4.50 Abusing SystemCTL1:54
  • 4.51 CRON Job Exploitation1:43
  • 4.52 System Kernel Vulnerabilities6:13
  • 4.53 Wrapping Up3:21

Requirements

  • To take this course, you need intermediate hacking knowledge. At a minimum, you should have completed the fundamentals covered in Levels 1-3 or have equivalent experience.

Description

Level 4, Offensive Security Colonel (OSC), propels your hacking skills to an advanced level by diving deep into web application vulnerabilities, post-exploitation techniques, and privilege escalation on both Windows and Linux. This chapter covers sophisticated web attacks like SQL Injection, Cross-Site Request Forgery (CSRF), Remote File Inclusion (RFI), and Server-Side Request Forgery (SSRF), giving you the tools to exploit web applications beyond basic vulnerabilities.


You’ll gain an understanding of post-exploitation strategies—what to do after you’ve compromised a system. This includes gathering sensitive data, monitoring user activities through keylogging, and maintaining persistence in compromised networks. Privilege escalation is crucial in offensive security, and this course will teach you how to elevate privileges on Windows and Linux systems using tools like WinPEAS and LinPEAS.


One of the highlights of this chapter is hacking Active Directory, a critical skill for those looking to specialize in network attacks. You’ll learn to map and exploit AD environments using techniques like Bloodhound, Kerberoasting, and Pass-the-Hash. Additionally, you’ll explore advanced network attacks, including MITM, ARP spoofing, and DNS poisoning.


This level is designed for those ready to tackle the most complex and rewarding challenges in offensive security.


Syllabus


  • Web Attacks: Deep dive into advanced web application vulnerabilities, including SQL Injection, Cross-Site Request Forgery (CSRF), Remote File Inclusion (RFI), and Server-Side Request Forgery (SSRF).

  • Post-Exploitation Techniques: Understanding how to gather sensitive information, keylog user activities, and establish persistence after gaining access.

  • Privilege Escalation Techniques: Learn how to escalate privileges on Windows and Linux systems using tools like WinPEAS and LinPEAS.

  • Hacking Active Directory: Techniques to map and exploit AD environments, including Bloodhound, Kerberoasting, Pass-the-Hash, and abusing misconfigurations.

  • Network Attacks (Advanced): Conducting advanced network attacks like Man-in-the-Middle (MITM), ARP spoofing, and DNS poisoning.

  • Specialized Windows Hacking: Advanced Windows exploitation techniques focusing on lesser-known attack vectors.

  • Specialized Linux Hacking: Exploiting specific Linux distributions and advanced configurations for maximum impact.

Who this course is for:

  • Security professionals and penetration testers looking to deepen their expertise in web application and network attacks.
  • Ethical hackers interested in post-exploitation techniques and privilege escalation on Windows and Linux systems.
  • IT specialists working in Active Directory environments who want to learn offensive tactics to secure their networks.
  • Red team members seeking advanced knowledge of network and OS-level exploitation techniques.
  • Cybersecurity enthusiasts with intermediate hacking knowledge, eager to master advanced exploitation strategies.
  • Web developers interested in understanding how attackers target web applications and how to defend against them.