ENGLISH

How to Hack Like a Legend: Breaking Windows - Early Access Edition

Book information

Publisher
No Starch Press
Year
2022
ISBN
9781718501508, 9781718501515, 2022934645
Language
english
Format
PDF
Filesize
6 MB (5965938 bytes)
Pages
208\208
Time added
2022-08-27 01:32:21

Description

Tag along with a master hacker on a truly memorable attack. From reconnaissance to infiltration, you’ll experience their every thought, frustration, and strategic decision-making first-hand in this exhilarating narrative journey into a highly defended Windows environment driven by AI. Step into the shoes of a master hacker and break into an intelligent, highly defensive Windows environment. You’ll be infiltrating the suspicious (fictional) offshoring company G & S Trust and their hostile Microsoft stronghold. While the target is fictional, the corporation’s vulnerabilities are based on real-life weaknesses in today’s advanced Windows defense systems. You’ll experience all the thrills, frustrations, dead-ends, and eureka moments of the mission first-hand, while picking up practical, cutting-edge techniques for evading Microsoft’s best security systems.   The adventure starts with setting up your elite hacking infrastructure complete with virtual Windows system. After some thorough passive recon, you’ll craft a sophisticated phishing campaign to steal credentials and gain initial access. Once inside you’ll identify the security systems, scrape passwords, plant persistent backdoors, and delve deep into areas you don’t belong. Throughout your task you’ll get caught, change tack on a tee, dance around defensive monitoring systems, anddisable tools from the inside. Spark Flow’s clever insights, witty reasoning, andstealth maneuvers teach you to be patient, persevere, and adapt your skills at the drop of a hat.   You’ll learn how to: Identify and evade Microsoft security systems like Advanced Threat Analysis,QRadar, MDE, and AMSISeek out subdomains and open ports with Censys, Python scripts, and other OSINT toolsScrape password hashes using KerberoastingPlant camouflaged C# backdoors and payloadsGrab victims’ credentials with more advanced techniques like reflection anddomain replication  Like other titles in the How to Hack series, this book is packed with interesting tricks, ingenious tips, and links to useful resources to give you a fast-paced, hands-on guide to penetrating and bypassing Microsoft security systems. Brief Contents Contents in Detail Introduction How This Book Works The Vague Plan Part I: Starting Blocks Chapter 1: Bending But Never Breaking Infrastructure Requirements Front-line Practical Configuration Attack Server C2 Server Resources Chapter 2: Buried Alive Establishing Contact Scouring the Web Finding the Weak Links Resources Chapter 3: Pitching a Curveball Stealing the Look Unearthing Subdomains Phishing Foes Spam Filters Email Sandboxes Antivirus Credential Harvesting Chapter 4: Perfecting the Hook Recycling Domains Manipulating Headers Routing Emails Setting Up the Sender Policy Framework Generating a Public Key for DKIM Baiting the Hook Building the Site Diverting the Analysts User Hunting Resources Part II: First Dive In Chapter 5: Prison Break Diving In Server Recon Automating Our Recon A Custom PowerShell Wrapper Building an MSBuild Project Unrestricted PowerShell Resources Chapter 6: Busting In and Getting Busted! Planting Our PowerShell Microsoft Base Code Interactive Mode Loading the PowerView Script Deeper Recon Inspecting the Data Gauging the Security Impersonating Users Resources Chapter 7: Know Thy Enemy Investigating the Crime Scene Revealing the Enemy Resources Part III: Back to the Arena Chapter 8: Through Logs and Fire Password Roulette Devising a Strategy Neutering Script Block Logging The Power of Self-Inspection Bypassing String Matches Resources Chapter 9: Russian Roulette Camouflage Identifying Services Attacking the Database Kerberos Unraveled Kerberoasting Databases Cracking Passwords Resources Chapter 10: Finally Free Raw SQL Mimikatz: Windows’ Magic Wand Executing Mimikatz Combating AMSI Identifying the Culprit Evading String Matching The Final Script Executing the Script Harvesting Our Spoils Resources Chapter 11: Defeating the Machines Exploring the Virtual Desktop Bypassing MDE Accessing LSASS Extracting the Credentials Defeating MDE Process Protection Gaining Trust Thread Injection Alternative Routes Resources Chapter 12: Perfecting the Backdoor The Development Structure Planting a Backdoor Setting the Snare Checking Our Surroundings Calling for the Payload Reworking the Empire Agent The Core of Our Backdoor Hijacking Commits Resources Part IV: Salvation Chapter 13: Hunting for Data Scoping Out the Defenses Gathering Intel Hunting for Data Privilege Check Persisting Raiding the Hive Gaining Trust Taking Credentials Resources Chapter 14: Jackpot Pivoting Cracking the Vault Closing Thoughts Resources

Similar books