Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
How to test network and service security
- Penetration testing – what is it?
- Penetration testing vs audit – similarities, differences, what is correct?
- Practical problems – what can go wrong?
- Scope of tests – what do we want to check?
- Sources of good practices and recommendations.
Penetration testing – reconnaissance
- OSINT – collecting information from open sources.
- Passive and active methods of network traffic analysis.
- Identifying services and network topology.
- Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on testing.
Penetration testing – vulnerability discovery
- Discovery of systems and their versions.
- Searching for vulnerabilities in systems, infrastructure, and applications.
- Vulnerability assessment – meaning “will it hurt?”
- Sources of exploits and possibilities for their adaptation.
Penetration testing – attack and gaining control
- Types of attacks – how they are conducted and their consequences.
- Attack using remote and local exploits.
- Attacks on network infrastructure.
- Reverse shell – how to manage a compromised system.
- Privilege escalation – how to become an administrator.
- Ready-made “hacking tools.”
- Analyzing a compromised system – interesting files, saved passwords, private data.
- Special cases: web applications, WiFi networks.
- Social engineering – how to “break” a person if systems cannot be compromised.
Penetration testing – covering tracks and maintaining access
- Logging and activity monitoring systems.
- Clearing logs and covering tracks.
- Backdoor – how to leave yourself an open entry point.
Penetration testing – summary
- Report preparation and its structure.
- Delivering and consulting the report.
- Verifying the implementation of recommendations.
Requirements
- Knowledge of basic computer networking topics (IP addressing, Ethernet, basic services – DNS, DHCP) and operating systems.
- Knowledge of Windows and Linux (basic administration, system terminal).
Target Group
- people responsible for network and service security,
- network and system administrators who want to learn about security testing methods.
- everyone interested in the topic.
28 Hours