Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- Overview of Kali Linux
- Installation and configuration of Kali Linux
- Usage and system updates for Kali Linux
Penetration Testing Standards and Classification
- Open Web Application Security Project (OWASP)
- Licensee Penetration Testing (LPT)
- White box and black box testing approaches
- Distinguishing between penetration testing and vulnerability assessment
Advanced Penetration Methodology
- Defining the target framework and scope
- Gathering client requirements
- Developing a checklist for the test plan
- Defining test boundaries through profiling
- Implementing advanced penetration testing with Kali Linux
Information Discovery
- Advanced techniques for Hacking Google
- Collecting DNS and 'who' information
- Gathering routing and network information
- Comprehensive information gathering strategies
Scanning and Enumerating Targets
- Advanced network scanning techniques
- Scanning TCP and UDP ports
- Stealth port scanning methods
- Packet crafting using Hping
- Nmap scanning and plugin utilization
- Active and passive banner and system OS enumeration
- Enumerating users, groups, and shared resources
- Enumerating DNS resource records and network devices
Vulnerability Assessment Tools
- Nessus
- OpenVAS
Target Exploitation
- Setting up Metasploit
- Exploitation techniques using Metasploit
- Managing Meterpreter sessions
- VNC exploitation
- Stealing password hashes
- Adding custom modules to Metasploit
- Utilizing the Immunity debugger
- Writing custom exploits
Privilege Escalation and Access Maintenance
- Cracking password hashes
- Cracking telnet, SSH, and FTP passwords
- Using Metasploit post-exploitation modules
- Protocol tunneling
- Proxy configuration
- Installing persistent backdoors
Advanced Sniffing
- ARP poisoning
- DHCP starvation
- MAC flooding
- DNS poisoning
- Sniffing credentials from secured websites
DoS Attacks
- Syn attacks
- Application request flood attacks
- Service request floods
- Service attacks causing permanent denial
Penetration Testing
- Web penetration testing
- Wireless penetration testing
Exploitation and Client-Side Attacks
- Exploiting browser vulnerabilities
- Buffer overflow techniques
- Fuzzing
- Fast-track hacking
- Phishing for passwords
- Generating backdoors
- Java applet attacks
Firewall Testing
- Firewall overview
- Testing firewalls and ports
- Rules and guidelines for firewall testing
Management and Reporting
- Documentation and result verification
- Dradis framework
- Magic tree and Maltego
- Data collection and evidence management
- Report types and presentation strategies
- Post-testing procedures
Summary and Next Steps
Requirements
- Familiarity with basic Kali Linux operations for penetration testing.
- Foundational understanding of Linux/Unix systems and networking concepts.
- Awareness of common network vulnerabilities.
Target Audience
- Ethical hackers
- Penetration testers
- Security engineers
- IT professionals
21 Hours