security cybersecurity

职业转向者实验室 — 构建你将在其上学习的机器

从一台什么都没有装的笔记本电脑开始,构建你将在其上学习的机器。一个虚拟机管理程序、一个 Kali 虚拟机、快照、从零开始的 Linux,以及一份从零开始重建所有这些的书面流程。仅限实验室构建和基础知识 — 这里没有任何内容教你如何攻击任何东西。

  • trending_upBeginner
  • schedule7h 7m
  • menu_book12 节课程
  • publicEnglish
  • workspace_premiumBasic
职业转向者实验室 — 构建你将在其上学习的机器

课程概述

没有人通过阅读来学习安全。你需要一台可以随意破坏的机器,而且这台机器必须无法接触到任何重要的东西。这就是你在这里构建的。 它从任务管理器中的一行开始,因为如果那一行说的是错的,这段中的其他一切都不会工作,再多的重装也救不了。然后是虚拟机管理程序,然后是从安装镜像用 Debian 13 配置文件安装的 Kali,二十五吉字节和引导式分区,你自己设置的密码,以及在你接触任何东西之前的第一个快照。 早期的课程之一是设计成会失败的。如果你在 Apple Silicon 笔记本电脑上,你会下载错误的镜像,从它构建一台机器,然后得到

课程大纲 · 4 个模块

lock解锁权限内容
  1. 01 机器之前的机器
    3 节课程·1h 31m

    在看第一个视频之前先读这个。第一课中不会安装任何东西——你需要从自己的机器上读出五个数字并记下来。这听起来很基础,但这正是每个人都跳过的步骤,跳过它就是导致前两课失败的原因。你记下的其中一个数字就是会打破第 1.3 课的那个数字。

  2. 02 构建它
    3 节课程·1h 37m

    你有意拒绝简易安装。向导为你做出五个决定,你将在面试中被要求为这些决定进行辩护,而认真看一遍问题和忽略问题之间的区别,就是拥有一个实验室和拥有别人给你的东西之间的区别。该模块在你安装任何东西之前就结束了,因为快照优先。

  3. 03 生活在其中
    3 节课程·1h 42m

    本模块中的所有内容都是检查——只读命令,不改变任何东西——这也是在运维角色中首月工作的准确描述。在每堂课前进行快照。唯一一次改变数百个文件的课是 3.2,这正是你在 2.3 中编写的规则所针对的情况。

  4. 04 丢失和恢复
    3 节课程·2h 17m

    快照可以保护你免受更改影响。备份可以保护你免受机器消失的影响,快照存在于机器所在的同一文件夹中,所以它们会随之而去。你需要把机器备份到其他地方,通过恢复副本来验证它,不开浏览器根据自己的笔记重建机器,并计时整个过程。在开始前预测你的重建时间并记录下来。每个人的预测都偏低,偏低的幅度大致相同。

常见问题

我将在 职业转向者实验室 — 构建你将在其上学习的机器 中学到什么?
从一台什么都没有装的笔记本电脑开始,构建你将在其上学习的机器。一个虚拟机管理程序、一个 Kali 虚拟机、快照、从零开始的 Linux,以及一份从零开始重建所有这些的书面流程。仅限实验室构建和基础知识 — 这里没有任何内容教你如何攻击任何东西。
我需要有先前的经验吗?
不需要 — 职业转向者实验室 — 构建你将在其上学习的机器 从基础开始,适合初学者。
职业转向者实验室 — 构建你将在其上学习的机器 需要多长时间?
职业转向者实验室 — 构建你将在其上学习的机器 包含 4 个模块和 12 节课程。您可以按自己的速度学习。
我如何获得访问权限?
职业转向者实验室 — 构建你将在其上学习的机器 包含在任何付费订阅中。

更多 网络防御 课程

Am I Too Late? — The Honest Map Into Cyber
Beginner Am I Too Late? — The Honest Map Into Cyber The four questions people actually ask before they book: is forty too late, do I need to code, what do I need before I start, and which certificate. Answered plainly, with a role map, real first-year pay, and a written plan you leave with.
The Kid Who Wants To Hack
Intermediate The Kid Who Wants To Hack You want to know how attacks work. Fine. This segment teaches you to see them — in a domain record, in a DNS lookup, in a log file — and to build a tool that scores a link before anyone clicks it. Nothing here teaches you to attack anything, and by the end you will understand why that is the expensive skill.
SOC Tier 1 — the job, done from the ticket in
Intermediate SOC Tier 1 — the job, done from the ticket in Six tickets, handed to you cold, in the order and the format a real shift hands them over. You decide what matters first and then defend the decision. Analysis and defence only — nothing here teaches you to attack anything.
The CV and the Application
Beginner The CV and the Application One page, built for somebody entering security without a security job history. Six adverts read line by line, the artefact put where a job history would go, the write-up marked, and the funnel tracked honestly — including what sixty rejections do and do not tell you.
What a Family Should Actually Lock Down
Beginner What a Family Should Actually Lock Down Your child's accounts are not the attack surface of your household. Yours are. Four sessions at the kitchen table that produce one written record: which accounts exist, which one recovers all the others, who actually has access to what, and what to do first on a bad day. No software to install, nothing technical to know, and not one password written down anywhere.
Microsoft SC-200 — The Analyst's Exam, From the Log Up
Intermediate Microsoft SC-200 — The Analyst's Exam, From the Log Up The SOC analyst's certification, taught from the log up: the query language from nothing on data shaped like real tickets, what a detection rule, incident and entity are made of, and the four scenario shapes the exam keeps reusing — with every query actually run and every error real. An independent course, not affiliated with or endorsed by Microsoft.