Get in Touch

Course Outline

Introduction

  • Overview of the Kali Linux distribution
  • Installation and configuration of Kali Linux
  • Usage and updating procedures for Kali Linux

Penetration Testing Standards and Classification

  • Open Web Application Security Project (OWASP)
  • Licensee Penetration Testing (LPT)
  • White box and black box testing approaches
  • Distinguishing between penetration testing and vulnerability assessment

Advanced Penetration Methodology

  • Defining the target framework and scope
  • Gathering and analyzing client requirements
  • Developing a checklist for the test plan
  • Profiling and defining test boundaries
  • Executing advanced penetration testing using Kali Linux

Information Discovery

  • Search engine hacking techniques
  • Collecting DNS and WHOIS information
  • Gathering route and network topology data
  • Aggregating comprehensive reconnaissance information

Scanning and Enumerating Target

  • Advanced network scanning techniques
  • Port and UDP port scanning
  • Stealth port scanning methodologies
  • Packet crafting utilizing Hping
  • Nmap scanning and leveraging plug-ins
  • Active and passive banner grabbing and OS enumeration
  • Enumerating users, groups, and shared resources
  • Enumerating DNS resource records and network devices

Vulnerability Assessment Tools

  • Nessus
  • Open Vas

Target Exploitation

  • Setting up Metasploit
  • Executing exploitation with Metasploit
  • Managing Meterpreter sessions
  • VNC exploitation techniques
  • Capturing password hashes
  • Integrating custom modules into Metasploit
  • Utilizing the Immunity Debugger
  • Developing exploits

Privilege Escalation and Access Maintenance

  • Cracking password hashes
  • Cracking credentials for telnet, ssh, and FTP
  • Leveraging Metasploit post-exploitation modules
  • Protocol tunneling methods
  • Configuring proxy servers
  • Installing persistent backdoors

Advanced Sniffing

  • ARP poisoning
  • DHCP starvation
  • MAC flooding
  • DNS poisoning
  • Capturing credentials from secured websites

DoS Attacks

  • SYN flood attacks
  • Application request flood attacks
  • Service request flooding
  • Permanent denial of service attacks

Penetration Testing

  • Web application penetration testing
  • Wireless network penetration testing

Exploitation and Client-Side Attacks

  • Exploiting browser vulnerabilities
  • Buffer overflow techniques
  • Fuzzing strategies
  • Fast-track hacking methods
  • Phishing for credentials
  • Generating backdoors
  • Java applet attacks

Firewall Testing

  • Firewall fundamentals and overview
  • Testing firewall rules and open ports
  • Best practices for firewall testing

Management and Reporting

  • Documentation and result verification
  • Utilizing the Dradis framework
  • Using Magic Tree and Maltego
  • Data collection and evidence management
  • Types of reports and effective presentation
  • Post-testing procedures

Summary and Next Steps

Requirements

  • Familiarity with using Kali Linux for penetration testing tasks
  • Foundational understanding of Linux/Unix systems and networking concepts
  • Knowledge of common network vulnerabilities

Target Audience

  • Ethical hackers
  • Penetration testers
  • Security engineers
  • IT professionals
 21 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories