Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
How to test the security of networks and services
- Penetration testing – what is it?
- Penetration testing versus audit – similarities, differences, and what is appropriate?
- Practical issues – what can go wrong?
- Scope of testing – what do we want to check?
- Sources of best practices and recommendations.
Penetration testing – reconnaissance
- OSINT – obtaining information from open sources.
- Passive and active methods of network traffic analysis.
- Identification of services and network topology.
- Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on testing.
Penetration testing – vulnerability discovery
- Discovery of systems and their versions.
- Searching for vulnerabilities in systems, infrastructure, and applications.
- Vulnerability assessment – what are the impacts?
- Exploit sources and customization possibilities.
Penetration testing – attack and takeover of control
- Types of attacks – how are they conducted and what are their outcomes?
- Attacks using remote and local exploits.
- Attacks on network infrastructure.
- Reverse shell – managing a compromised system.
- Privilege escalation – how to become an administrator.
- Ready-made "hacking tools".
- Analysing a compromised system – interesting files, saved passwords, private data.
- Special cases: web applications, Wi-Fi networks.
- Social engineering – how to "break" a person if systems cannot be breached?
Penetration testing – covering tracks and maintaining access
- Logging systems and activity monitoring.
- Log clearing and covering tracks.
- Backdoor – how to leave yourself an open entry point.
Penetration testing – summary
- Report preparation and its structure.
- Report handover and consultation.
- Verification of recommendation implementation.
Requirements
- Knowledge of basic computer networking topics (IP addressing, Ethernet, core services – DNS, DHCP) and operating systems.
- Familiarity with Windows and Linux (basic administration, system terminal).
Target Audience
- Personnel responsible for network and service security;
- Network and system administrators wishing to learn security testing methods;
- Anyone interested in the subject.
28 Hours