Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
How to Test Network and Service Security
- Penetration testing – what is it?
- Penetration testing vs. audit – similarities, differences, and what is appropriate?
- Practical challenges – what can go wrong?
- Scope of tests – what do we want to check?
- Sources of best practices and recommendations.
Penetration Testing – Reconnaissance
- OSINT – gathering information from open sources.
- Passive and active network traffic analysis methods.
- Identifying services and network topology.
- Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on testing.
Penetration Testing – Vulnerability Discovery
- System identification and version detection.
- Finding vulnerabilities in systems, infrastructure, and applications.
- Vulnerability assessment – "what can be exploited?"
- Exploit sources and customization capabilities.
Penetration Testing – Attack and Control Gain
- Types of attacks – how they are conducted and their consequences.
- Attacks using remote and local exploits.
- Attacks on network infrastructure.
- Reverse shell – managing a compromised system.
- Privilege escalation – becoming an administrator.
- Ready-made "hacking tools".
- Analyzing a compromised system – interesting files, stored passwords, private data.
- Special cases: web applications, WiFi networks.
- Social engineering – how to "break" a human if systems cannot be targeted?
Penetration Testing – Covering Tracks and Maintaining Access
- Logging systems and activity monitoring.
- Cleaning logs and covering tracks.
- Backdoors – how to leave an open entry point.
Penetration Testing – Summary
- Report preparation and structure.
- Report presentation and consultation.
- Verification of recommendation implementation.
Requirements
- Familiarity with basic computer networking concepts (IP addressing, Ethernet, core services such as DNS, DHCP) and operating systems.
- Knowledge of Windows and Linux (basic administration, system terminal usage).
Target Group
- Individuals responsible for network and service security.
- Network and system administrators seeking to learn security testing techniques.
- Anyone interested in the topic.
28 Hours