Get in Touch

Course Outline

How to Test Network and Service Security

  • Penetration testing – what is it?
  • Penetration test vs. audit – similarities, differences, and which is appropriate?
  • Practical challenges – what can go wrong?
  • Test scope – i.e., what do we want to check?
  • Sources of best practices and recommendations

Penetration Testing – Reconnaissance

  • OSINT – acquiring information from public sources
  • Passive and active network traffic analysis methods
  • Identifying services and network topology
  • Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on tests

Penetration Testing – Vulnerability Hunting

  • System identification and version detection
  • Searching for vulnerabilities in systems, infrastructure, and applications
  • Vulnerability assessment – i.e., 'will it hurt'?
  • Sources of exploits and possibilities for adapting them

Penetration Testing – Attack and Gaining Control

  • Types of attacks – how they are conducted and their consequences?
  • Attacking using remote and local exploits
  • Attacks on network infrastructure
  • Reverse shell – managing the compromised system
  • Privilege escalation – i.e., how to become an administrator
  • Ready-made 'hacking tools'
  • Analyzing the compromised system – interesting files, saved passwords, private data
  • Special cases: web applications, WiFi networks
  • Social engineering – i.e., how to 'break' a person if systems cannot be hacked?

Penetration Testing – Covering Tracks and Maintaining Access

  • Logging systems and activity monitoring
  • Cleaning logs and covering tracks
  • Backdoor – i.e., how to leave yourself an open entry point

Penetration Testing – Summary

  • Report preparation and its structure
  • Report delivery and consultation
  • Verification of recommendation implementation

Requirements

  • Knowledge of basic computer networking concepts (IP addressing, Ethernet, core services – DNS, DHCP) and operating systems
  • Familiarity with Windows and Linux (basic administration, command-line terminal)

Target Group

  • Individuals responsible for network and service security,
  • Network and system administrators wishing to learn security testing methods
  • Anyone interested in the subject.
 28 Hours

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 6400 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories