Get in Touch

Course Outline

How to Test the Security of Networks and Services

  • Penetration Testing – What is it?
  • Penetration Test vs. Audit – similarities, differences, which is appropriate?
  • Practical problems – what can go wrong?
  • Scope of testing – what do we want to check?
  • Sources of best practices and recommendations

Penetration Test – Reconnaissance

  • OSINT – gathering information from public sources
  • Passive and active methods of network traffic analysis
  • Identification of services and network topology
  • Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on testing

Penetration Test – Vulnerability Discovery

  • Reconnaissance of systems and their versions
  • Searching for vulnerabilities in systems, infrastructure, and applications
  • Assessing vulnerabilities – i.e., "Will it hurt?"
  • Sources of exploits and possibilities for their adaptation

Penetration Test – Attack and Gaining Control

  • Types of attacks – how are they conducted and what are the consequences?
  • Attacks using remote and local exploits
  • Attacks on network infrastructure
  • Reverse shell – how to manage the compromised system
  • Privilege escalation – how to become an administrator
  • Ready-made "hacking tools"
  • Analysis of the compromised system – interesting files, saved passwords, private data
  • Special cases: web applications, WiFi networks
  • Social engineering – how to "break" a person when systems cannot be breached

Penetration Test – Log Clearing and Maintaining Access

  • Logging and activity monitoring systems
  • Cleaning logs and clearing traces
  • Backdoor – how to leave an open entry point

Penetration Test – Summary

  • Preparing the report and its structure
  • Delivery and consultation of the report
  • Verification of implemented recommendations

Requirements

  • Familiarity with basic concepts of computer networks (IP addressing, Ethernet, basic services – DNS, DHCP) and operating systems
  • Familiarity with Windows and Linux (fundamentals of administration, system terminal)

Target Audience

  • Individuals responsible for network and service security,
  • Network and system administrators who wish to learn about security testing methods
  • All those interested in the subject.
 28 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories