Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
How to Test Network and Service Security
- Penetration testing – what is it?
- Penetration test vs. audit – similarities, differences, and which is appropriate?
- Practical challenges – what can go wrong?
- Test scope – i.e., what do we want to check?
- Sources of best practices and recommendations
Penetration Testing – Reconnaissance
- OSINT – acquiring information from public sources
- Passive and active network traffic analysis methods
- Identifying services and network topology
- Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on tests
Penetration Testing – Vulnerability Hunting
- System identification and version detection
- Searching for vulnerabilities in systems, infrastructure, and applications
- Vulnerability assessment – i.e., 'will it hurt'?
- Sources of exploits and possibilities for adapting them
Penetration Testing – Attack and Gaining Control
- Types of attacks – how they are conducted and their consequences?
- Attacking using remote and local exploits
- Attacks on network infrastructure
- Reverse shell – managing the compromised system
- Privilege escalation – i.e., how to become an administrator
- Ready-made 'hacking tools'
- Analyzing the compromised system – interesting files, saved passwords, private data
- Special cases: web applications, WiFi networks
- Social engineering – i.e., how to 'break' a person if systems cannot be hacked?
Penetration Testing – Covering Tracks and Maintaining Access
- Logging systems and activity monitoring
- Cleaning logs and covering tracks
- Backdoor – i.e., how to leave yourself an open entry point
Penetration Testing – Summary
- Report preparation and its structure
- Report delivery and consultation
- Verification of recommendation implementation
Requirements
- Knowledge of basic computer networking concepts (IP addressing, Ethernet, core services – DNS, DHCP) and operating systems
- Familiarity with Windows and Linux (basic administration, command-line terminal)
Target Group
- Individuals responsible for network and service security,
- Network and system administrators wishing to learn security testing methods
- Anyone interested in the subject.
28 Hours
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 6400 € + VAT*
Contact us for an exact quote and to hear our latest promotions