security cybersecurity

轉職者實驗室——打造你將在其上學習的機器

從一台目前什麼都沒有的筆電開始,打造你將在其上學習的機器。一個虛擬機器監控程式、一台 Kali 虛擬機器、快照、從零開始的 Linux,以及一份從無到有重建所有這一切的書面程序。只包含實驗室構建和基礎——這裡沒有任何東西教你如何攻擊任何東西。

  • trending_upBeginner
  • schedule7h 7m
  • menu_book12 堂課程
  • publicEnglish
  • workspace_premiumBasic
轉職者實驗室——打造你將在其上學習的機器

課程簡介

沒有人靠閱讀來學習安全。你需要一台你被允許毀壞的機器,而且它必須是一台無法接觸任何重要東西的機器。這就是你在這裡要打造的。 它從工作管理員中的一行開始,因為如果那一行顯示錯誤的內容,那麼這個部分中沒有其他東西會運作,再怎麼重新安裝也沒用。然後是虛擬機器監控程式,然後是從安裝映像以 Debian 13 配置檔建立的 Kali,二十五 GB 和引導式分割區、你自己設定的密碼,以及在你接觸任何東西之前的首次快照。 早期的課程之一是設計來失敗的。如果你在 Apple Silicon 筆電上,你會下載錯誤的映像、從它建立一台機器,然後收到「找不到可開機的裝置」——然後學會在下載任何東西之前先檢查你自己的機器是什麼,這是一個習慣在這個部分會再出現兩次,並且在你的整個職業生涯中都會回來。一位來自新聞業的轉職者為了完全相同的原因損失了整整一節課。 然後是 Linux,為了從未使用過它的人。虛擬機器實際上是什麼。為什麼在 Windows 旁邊安裝 Linux 會造成問題,以及開機載入程式與此有什麼關係。為什麼 GNOME 和 KDE 不是 Linux。檔案住在哪裡、軟體從何而來、誰被允許讀什麼,以及如何找出你不在時機器做了什麼。 它以她的方式結束:整台機器遺失,重建變成了課程。你將機器備份到不在你筆電上的地方,然後關閉瀏覽器從你自己的筆記重建它,並對兩者進行計時。然後你編寫回滾變更的指令碼,以及意味著這一切都不在你腦袋裡的運行手冊。 你完成時有了自己的機器、自己的快照紀律,以及一份陌生人可以據此重建整個系統的文件。 每個實驗室都遵循相同的常設規則,它們不是裝飾:先獲得許可、尊重範圍、絕不生產環境、總是預備環境。

課程大綱 · 4 個單元

lock隨存取權限解鎖
  1. 01 機器前的機器
    3 堂課程·1h 31m

    在看第一支影片之前冷讀這個。第一堂課不會安裝任何東西——你只是從自己的機器上讀出五個數字並寫下來。聽起來微不足道,但這就是每個人都會跳過的步驟,而跳過它正是前兩堂課失敗的原因。你寫下的其中一個數字就是在第 1.3 課中造成問題的那個。

  2. 02 建置它
    3 堂課程·1h 37m

    你刻意拒絕簡易安裝。精靈會為你做出五個決定,你在面試中會被要求為這些決定辯護,而看一次問題與跳過問題的差別,就是擁有實驗室和擁有別人給你的東西之間的差異。模組在你安裝任何東西之前結束,因為快照優先。

  3. 03 活在其中
    3 堂課程·1h 42m

    這個模組中的所有內容都是檢視——只讀命令,不改變任何東西——這也恰好描述了運維角色的前一個月。在每堂課前拍快照。唯一一次性改變數百個檔案的課程是 3.2,那正好是你在 2.3 寫的規則所針對的情況。

  4. 04 失去它,重新得到它
    3 堂課程·2h 17m

    快照可以保護你免於變更。備份可以保護你免於機器不復存在,而快照存放在與機器相同的資料夾中,所以它們會隨著機器一起移動。你將在其他地方備份機器,透過還原來驗證副本,不開啟任何瀏覽器從自己的筆記重新建置機器,並計時所有操作。在開始之前預測你的重新建置時間並記錄預測。每個人預測的時間都偏低,偏差大致相同。

常見問題

我將在 轉職者實驗室——打造你將在其上學習的機器 中學到什麼?
從一台目前什麼都沒有的筆電開始,打造你將在其上學習的機器。一個虛擬機器監控程式、一台 Kali 虛擬機器、快照、從零開始的 Linux,以及一份從無到有重建所有這一切的書面程序。只包含實驗室構建和基礎——這裡沒有任何東西教你如何攻擊任何東西。
我需要事先具備經驗嗎?
不需要——轉職者實驗室——打造你將在其上學習的機器 從基礎開始,適合初學者。
轉職者實驗室——打造你將在其上學習的機器 需要多長時間?
轉職者實驗室——打造你將在其上學習的機器 包含 4 個單元和 12 堂課程。你可以按自己的進度學習。
我如何取得存取權限?
轉職者實驗室——打造你將在其上學習的機器 包含在任何付費訂閱方案中。

網路防禦 中的更多內容

Am I Too Late? — The Honest Map Into Cyber
Beginner Am I Too Late? — The Honest Map Into Cyber The four questions people actually ask before they book: is forty too late, do I need to code, what do I need before I start, and which certificate. Answered plainly, with a role map, real first-year pay, and a written plan you leave with.
The Kid Who Wants To Hack
Intermediate The Kid Who Wants To Hack You want to know how attacks work. Fine. This segment teaches you to see them — in a domain record, in a DNS lookup, in a log file — and to build a tool that scores a link before anyone clicks it. Nothing here teaches you to attack anything, and by the end you will understand why that is the expensive skill.
SOC Tier 1 — the job, done from the ticket in
Intermediate SOC Tier 1 — the job, done from the ticket in Six tickets, handed to you cold, in the order and the format a real shift hands them over. You decide what matters first and then defend the decision. Analysis and defence only — nothing here teaches you to attack anything.
The CV and the Application
Beginner The CV and the Application One page, built for somebody entering security without a security job history. Six adverts read line by line, the artefact put where a job history would go, the write-up marked, and the funnel tracked honestly — including what sixty rejections do and do not tell you.
What a Family Should Actually Lock Down
Beginner What a Family Should Actually Lock Down Your child's accounts are not the attack surface of your household. Yours are. Four sessions at the kitchen table that produce one written record: which accounts exist, which one recovers all the others, who actually has access to what, and what to do first on a bad day. No software to install, nothing technical to know, and not one password written down anywhere.
Microsoft SC-200 — The Analyst's Exam, From the Log Up
Intermediate Microsoft SC-200 — The Analyst's Exam, From the Log Up The SOC analyst's certification, taught from the log up: the query language from nothing on data shaped like real tickets, what a detection rule, incident and entity are made of, and the four scenario shapes the exam keeps reusing — with every query actually run and every error real. An independent course, not affiliated with or endorsed by Microsoft.