Course Outline for Cyber Security & Ethical Hacking
This 3 day intensive training program offers profound knowledge on the core topics of cybersecurity such as Kali Linux, Application security, and Network security.
In this course, you will start as a beginner with no previous knowledge about penetration testing or hacking and by the end of it you'll be at an intermediate level being able to hack into networks and connected devices like black-hat hackers and secure them like security experts.
This course is focused on the practical side of penetration testing as well as the theory behind it. Before jumping into security and penetration, you will first learn how to set up a lab and install needed software (works on Windows, Mac OS X and Linux), then the course is structured in a way that will take you through the basics of linux, remoting into linux, computer systems, networks and how devices communicate with each other, then you will learn how to exploit this method of communication to carry out a number of powerful attacks.
The whole point of learning the attacks is so that you understand how hacking works and how to identify security loopholes. Armed with proper knowledge, security can be designed more efficiently and effectively.
All the attacks in this course are practical attacks that work against any wireless enabled device, ie: it does not matter if the device is a phone , tablet, laptop ...etc. These attacks also work against all operating systems (Windows, OSX, Linux IOS, Android ...ect.). in each technique you will understand the theory behind it and how it works, then you'll learn how to use that technique in a real life scenario, so by the end of the course you'll be able to modify these techniques or combine them to come up with more powerful attacks and design prevention techniques to secure the networks.
Demand for experts in cybersecurity has skyrocketed. By completing this course, participants can develop the skills required to understand and manage cyber risk and implement the right security controls.
Disclaimer
This course is designed for educational purposes without any intent or demonstration or content that violates any national or ethical laws.
Training Outcome
Every learner has different learning patterns and absorption rates. As such, it is virtually impossible to gauge an exact learning outcome of each participant. However, it may be safely assumed that by the end of this course, each learner shall be able to:
- Use Kali Linux
- Perform Penetration Testing
- Perform Reverse Engineering for Forensics
- Take necessary measures to prevent cyber attacks
- Secure networks
- Control connections of clients around you without knowing the password.
- Crack WEP/WPA/WPA2 using a number of methods.
- Hack any computer on the same network.
- Intercept data and spy on all on the network
- Gather detailed information about clients and networks like their OS, opened ports ...etc.
- A number of practical attacks that can be used without knowing the key to the target network
- ARP Spoofing/ARP Poisoning
- Launch Various Man In The Middle attacks.
- Sniff packets from clients and analyse them to extract important info such as: passwords, cookies, urls, videos, images ..etc.
- Detect ARP poisoning and protect your self and your network against it.
- You will be able to use more than 20 penetration testing tools such as ettercap, wireshark, aircrack-ng suit ...etc.
- Combine individual attacks to launch even more powerful attacks.
Prerequisites
It is expected that the pupil shall have the following at hand when participating in the course:
- Ability to comprehend the English Language (basic)
- Personal computer with full admin access
- Access to High Speed Internet
- Access to Linux based operating system (at least 2 units)
- Basic understanding of OS
- Basic understanding and experience using the internet
- Basic understanding of filing systems
- High School Mathematics
Course Outline
- Introduction to Cyber Security
- Types of networks
- Types of Attacks
- Dissection
- Terminologies
- Network Protocol
- IP Address
- Subnet
- NAT
- DHCP server
- Ports
- DNS
- OSI Model
- Services
- Hidden Wiki
- Proxy Server
- Proxy Bouncing
- Common Steps
- Gmail login untold Secret
- Windows Login Bypass
- Customize Windows options
- Web Architecture
- Server setup
- Web Component and Server
- Kali Linux
- Lab Overview & Needed Software
- Initial Preparation
- Installing Kali Linux as a VM on Windows
- Using Servers
- Kali Linux Overview
- SSH
- The Linux Terminal & Basic Commands
- Information Gathering
- Finding Vulnerable Ports
- Advanced Search Engine
- Finding hidden web pages and files
- Active and Passive Scan
- Discovering Connected Clients using netdiscover
- Gathering More Information Using Zenmap
- Gathering Even More Information Using Zenmap
- ARP Poisoning Theory
- ARP Poisoning Using arpspoof
- Bettercap Basics
- ARP Poisoning Using Bettercap
- Spying on Network Devices (Capturing Passwords, Visited Websites...etc)
- Creating Custom Spoofing Script
- Understanding HTTPS & How to Bypass it
- Bypassing HTTPS
- DNS Spoofing - Redirecting Requests From One Website To Another
- Injecting Javascript Code
- Running all the Above Using a Graphical Interface
- Wireshark - Basic Overview & How To Use It With MITM Attacks
- Wireshark - Sniffing & Analysing Data
- Wireshark - Using Filters, Tracing & Dissecting Packets
- Wireshark - Capturing Passwords & Anything Sent By Any Device In The Network
- Creating a Fake Access Point - Theory
- Creating a Fake AP Using Mana-Toolkit
- Social Engineering
- Fake mail
- Phishing page
- Cellphone tracking
- Creating Malware
- SET
- Penetration Testing
- SQL injections
- Burp Suite
- XSS
- File upload Vulnerability
- Command Line Execution
- Havij
- Reverse Engineering
- Software Hacking
- Virus illustration
- Firewall Bypassing
- Network Hacking
- MITM attack
- Wireshark
- WiFi hacking
- Metasploit Framework
- Packet Sniffing Basics Using Airodump-ng
- WiFi Bands - 2.4Ghz & 5Ghz Frequencies
- Targeted Packet Sniffing Using Airodump-ng
- Deauthentication Attack (Disconnecting Any Device From The Network)
- Accessing and Attacking
- Theory Behind Cracking WEP Encryption
- Associating With Target Network Using Fake Authentication Attack
- ARP Request Reply Attack
- Korek Chopchop Attack
- Fragmentation Attack
- Accessing more secured Networks
- Introduction to WPA / WPA2 Cracking
- Exploiting the WPS Feature
- How to Capture a Handshake
- Creating a Wordlist / Dictionary
- Cracking the Key Using a Wordlist Attack
- Cracking the Key Quicker using a Rainbow Table
- Cracking WPA/WPA2 Much Faster Using GPU
- Prevention & Security
- Securing Your Network From The Above Attacks
- How to Configure Wireless Security Settings To Secure Your Network
- Detecting ARP Poisoning Attacks
- Detecting Suspicious Activities using Wireshark
Practical, connected learning
My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.