Get in Touch

Course Outline

Testing Network and Service Security

  • Penetration testing – what is it?
  • Penetration test vs. audit – similarities, differences, which is appropriate?
  • Practical issues – what can go wrong?
  • Scope of testing – i.e., what do we want to check?
  • Sources of best practices and recommendations

Penetration Test – Reconnaissance

  • OSINT – i.e., information gathering from open sources
  • Passive and active methods of network traffic analysis
  • Identification of services and network topology
  • Security systems (firewalls, IPS/IDS systems, WAF, etc.) and their impact on testing

Penetration Test – Vulnerability Discovery

  • System and version identification
  • Vulnerability scanning in systems, infrastructure, and applications
  • Vulnerability assessment – i.e., "will it hurt?"
  • Sources of exploits and possibilities for their adaptation

Penetration Test – Attack and Gaining Control

  • Types of attacks – how are they conducted and what are the consequences?
  • Attacking using remote and local exploits
  • Attacks on network infrastructure
  • Reverse shell – how to manage a compromised system
  • Privilege escalation – i.e., how to become an administrator
  • Ready-made "hacking tools"
  • Analysis of the compromised system – interesting files, saved passwords, private data
  • Special cases: web applications, WiFi networks
  • Social engineering – i.e., how to "break" a person if the systems cannot be broken

Penetration Test – Covering Tracks and Maintaining Access

  • Logging and activity monitoring systems
  • Log cleaning and covering tracks
  • Backdoor – i.e., how to leave an open entry point

Penetration Test – Summary

  • Report preparation and its structure
  • Report delivery and consultation
  • Verification of recommendation implementation

Requirements

  • Familiarity with fundamental concepts of computer networks (IP addressing, Ethernet, basic services – DNS, DHCP) and operating systems
  • Knowledge of Windows and Linux (basic administration, system terminal)

Target Audience

  • Individuals responsible for network and service security,
  • Network and systems administrators who wish to learn security testing methodologies,
  • All interested parties.
 28 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories