Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
How to Test the Security of Networks and Services
- Penetration testing – what is it?
- Penetration testing vs. auditing – similarities, differences, and which is appropriate?
- Practical challenges – what can go wrong?
- Scope of testing – defining what needs to be verified.
- Sources of best practices and recommendations.
Penetration Testing – Reconnaissance
- OSINT – gathering information from public sources
- Passive and active methods of network traffic analysis
- Identification of services and network topology
- Security systems (firewalls, IPS/IPS systems, WAF, etc.) and their impact on testing
Penetration Testing – Vulnerability Discovery
- System reconnaissance and version identification
- Discovering vulnerabilities in systems, infrastructure, and applications
- Vulnerability assessment – determining severity and impact
- Sources of exploits and options for their adaptation
Penetration Testing – Attack and Control
- Types of attacks – execution methods and resulting impacts
- Attacks using remote and local exploits
- Attacks on network infrastructure
- Reverse shells – managing the compromised system
- Privilege escalation – becoming an administrator
- Pre-built 'hacking tools'
- Analysis of the compromised system – interesting files, stored passwords, private data
- Special cases: web applications and WiFi networks
- Social engineering – exploiting human error when systems cannot be broken
Penetration Testing – Trace Elimination and Persistence
- Logging systems and activity monitoring
- Log cleaning and trace elimination
- Backdoors – maintaining persistent access
Penetration Testing – Summary
- Report preparation and structure
- Report handover and consultation
- Verification of implemented recommendations
Requirements
- Familiarity with fundamental concepts of computer networks (IP addressing, Ethernet, basic services – DNS, DHCP) and operating systems
- Proficiency with Windows and Linux (administration basics, system terminal)
Target Audience
- Individuals responsible for network and service security,
- Network and system administrators seeking to learn security testing methods,
- Anyone interested in the subject.
28 Hours