Profile
In the Penetration Testing module, participants will be introduced to the comprehensive process of penetration testing. The course covers information gathering techniques, such as WHOIS, domain name system (DNS) reconnaissance, and Shodan, as well as scanning and enumeration tools like Nmap and Nessus. Students will learn to exploit vulnerabilities using various methods and tools, including Metasploit and Burp Suite. Post-exploitation tactics, such as privilege escalation and persistence, will also be covered. Additionally, the module delves into web application security, teaching participants about common web attacks and defense mechanisms. By the end of this module, students will be equipped with the skills to conduct thorough penetration tests and enhance the security of systems and applications.
What You'll Learn
By the end of this module, learners will be able to:
- Master the techniques of information gathering
- Performing scanning using Nmap and Nessus to accurately assess and document system vulnerabilities
- Learn the practical aspects of exploiting vulnerabilities in systems, focusing on methodologies for gaining access to systems, crafting and deploying payloads, and using tools like Metasploit
- Gain knowledge of advanced post-exploitation tactics, including privilege escalation, persistence, and disabling security features
- Delve into the security of web applications, understanding the various threats and vulnerabilities specific to web environments. They will learn about HyperText Markup Language (HTML) basics, Open Worldwide Application Security Project (OWASP) guidelines, Structured query language (SQL) Injection, Cross-Site Scripting (XSS), Local File Inclusion (LFI)/ Remote File Inclusion (RFI), and other common web attack vectors
Minimum Entry Requirement
Basic Information technology (IT) literacy
It is recommended the participant to have at least 1 year of working experience in IT industry