ที่มา
หลังจากจบ Alchemy (OT/ICS) และ Zelphyr ผมตัดสินใจลอง Dante ซึ่งเป็น Pro Lab ระดับ entry ที่ HackTheBox แนะนำสำหรับคนเตรียมสอบ OSCP

Dante คืออะไร
Dante คือ enterprise network จำลองที่มีหลายเครื่องกระจายอยู่ใน network segment หลายวง ต่างจาก HTB machine ทั่วไปที่ทำทีละเครื่อง Dante บังคับให้คิดแบบ attacker จริงๆ ที่ต้องเคลื่อนตัวผ่านระบบขององค์กร ตั้งแต่ enumerate, pivot, escalate จนถึง domain dominance
ครอบคลุม:
- Web Application Attacks
- Linux & Windows Privilege Escalation
- Active Directory Exploitation
- Lateral Movement
- Pivoting & Tunneling
เหมาะกับใคร
- มีพื้นฐาน Linux/Windows privesc มาบ้างแล้ว
- เข้าใจ Active Directory เบื้องต้น
- กำลังเตรียมสอบ OSCP
- ฝึก Metasploit
LAB ด้วยรวม
LAB โดยรวยจะมี ทั้งหมด 3 วง ซึ่งเราต้อง enum หาเอง
Segment I
จะมี Website อยู่เว็บเดียวเป็นพวกแรแกที่จะทำให้เรา Foothold ก่อนเข้าระบบ
- ฝึก Webexploit — wordpress
Segment II
จะมีหลายเครื่องมาก ซึ่งเราต้อง Enum หาเอง จะเป็น Windows สลับกับ Linux มี DC 1 ตัว แต่จะไม่ต่อกับ Workstation ตัวอื่นนะ
- AD-exploitation
- Webexploit
- Escalation
- Enum**
- metasploit
Segment III
โซนนี้จะมี DC อีกตัวซึ่งต้อง Enum หาเองหรือลองหาดูบน DC จะเป็น DC อีกเครื่อง Linux 2 ตัว
- AD-exploitation
- metesploit
Tool ส่วนใหญ่จะแนะนำให้ใช้ metesploit นะครับทั้ง pivot , meterpreter shell **
เพราะบางข้อใช้ metasploit จะสะดวกหรือบังคับ XD
Dante ไม่ได้สอนแค่ exploit — มันสอนให้คิด methodology
Enumerate → Foothold → Escalate → Pivot → Repeat
หลังจบ Dante คุณจะมองงาน pentest เป็น process และได้ฝึกระบบที่จำลองเหมือน เครื่องขององค์กร องค์กรนึงเลย
โดยรวมก็สนุกดีครับ ต้องลองเพราะ Beginner Friendly
Certificate
| munpao59