Get in Touch

Course Outline

Introduction

  • Overview of Kali Linux
  • Installation and configuration of Kali Linux
  • Usage and system updates for Kali Linux

Penetration Testing Standards and Classification

  • Open Web Application Security Project (OWASP)
  • Licensee Penetration Testing (LPT)
  • White box and black box testing approaches
  • Distinguishing between penetration testing and vulnerability assessment

Advanced Penetration Methodology

  • Defining the target framework and scope
  • Gathering client requirements
  • Developing a checklist for the test plan
  • Defining test boundaries through profiling
  • Implementing advanced penetration testing with Kali Linux

Information Discovery

  • Advanced techniques for Hacking Google
  • Collecting DNS and 'who' information
  • Gathering routing and network information
  • Comprehensive information gathering strategies

Scanning and Enumerating Targets

  • Advanced network scanning techniques
  • Scanning TCP and UDP ports
  • Stealth port scanning methods
  • Packet crafting using Hping
  • Nmap scanning and plugin utilization
  • Active and passive banner and system OS enumeration
  • Enumerating users, groups, and shared resources
  • Enumerating DNS resource records and network devices

Vulnerability Assessment Tools

  • Nessus
  • OpenVAS

Target Exploitation

  • Setting up Metasploit
  • Exploitation techniques using Metasploit
  • Managing Meterpreter sessions
  • VNC exploitation
  • Stealing password hashes
  • Adding custom modules to Metasploit
  • Utilizing the Immunity debugger
  • Writing custom exploits

Privilege Escalation and Access Maintenance

  • Cracking password hashes
  • Cracking telnet, SSH, and FTP passwords
  • Using Metasploit post-exploitation modules
  • Protocol tunneling
  • Proxy configuration
  • Installing persistent backdoors

Advanced Sniffing

  • ARP poisoning
  • DHCP starvation
  • MAC flooding
  • DNS poisoning
  • Sniffing credentials from secured websites

DoS Attacks

  • Syn attacks
  • Application request flood attacks
  • Service request floods
  • Service attacks causing permanent denial

Penetration Testing

  • Web penetration testing
  • Wireless penetration testing

Exploitation and Client-Side Attacks

  • Exploiting browser vulnerabilities
  • Buffer overflow techniques
  • Fuzzing
  • Fast-track hacking
  • Phishing for passwords
  • Generating backdoors
  • Java applet attacks

Firewall Testing

  • Firewall overview
  • Testing firewalls and ports
  • Rules and guidelines for firewall testing

Management and Reporting

  • Documentation and result verification
  • Dradis framework
  • Magic tree and Maltego
  • Data collection and evidence management
  • Report types and presentation strategies
  • Post-testing procedures

Summary and Next Steps

Requirements

  • Familiarity with basic Kali Linux operations for penetration testing.
  • Foundational understanding of Linux/Unix systems and networking concepts.
  • Awareness of common network vulnerabilities.

Target Audience

  • Ethical hackers
  • Penetration testers
  • Security engineers
  • IT professionals
 21 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories