Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
How to Test the Security of Networks and Services
- Penetration Testing – What is it?
- Penetration Test vs. Audit – similarities, differences, which is appropriate?
- Practical problems – what can go wrong?
- Scope of testing – what do we want to check?
- Sources of best practices and recommendations
Penetration Test – Reconnaissance
- OSINT – gathering information from public sources
- Passive and active methods of network traffic analysis
- Identification of services and network topology
- Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on testing
Penetration Test – Vulnerability Discovery
- Reconnaissance of systems and their versions
- Searching for vulnerabilities in systems, infrastructure, and applications
- Assessing vulnerabilities – i.e., "Will it hurt?"
- Sources of exploits and possibilities for their adaptation
Penetration Test – Attack and Gaining Control
- Types of attacks – how are they conducted and what are the consequences?
- Attacks using remote and local exploits
- Attacks on network infrastructure
- Reverse shell – how to manage the compromised system
- Privilege escalation – how to become an administrator
- Ready-made "hacking tools"
- Analysis of the compromised system – interesting files, saved passwords, private data
- Special cases: web applications, WiFi networks
- Social engineering – how to "break" a person when systems cannot be breached
Penetration Test – Log Clearing and Maintaining Access
- Logging and activity monitoring systems
- Cleaning logs and clearing traces
- Backdoor – how to leave an open entry point
Penetration Test – Summary
- Preparing the report and its structure
- Delivery and consultation of the report
- Verification of implemented recommendations
Requirements
- Familiarity with basic concepts of computer networks (IP addressing, Ethernet, basic services – DNS, DHCP) and operating systems
- Familiarity with Windows and Linux (fundamentals of administration, system terminal)
Target Audience
- Individuals responsible for network and service security,
- Network and system administrators who wish to learn about security testing methods
- All those interested in the subject.
28 Hours