Call : (+91) 968636 4243
Mail : info@EncartaLabs.com
EncartaLabs

Penetration Testing

( Duration: 4 Days )

In Penetration Testing training course, you will learn to discover weaknesses in the network using the same mindset and methods as hackers. They acquire the knowledge to test and exploit internal and external defenses. You will learn countermeasures to reduce risk to your enterprise.

By attending Penetration Testing workshop, delegates will learn to:

  • Deploy ethical hacking to expose weaknesses in the organization
  • Gather intelligence by employing reconnaissance, published data and scanning tools
  • Probe and compromise the network using hacking tools to test and improve security
  • Protect against privilege escalation to prevent intrusions

This Penetration Testing class is ideal for Security consultants, Information Assurance auditors, firewall/IDS personnel, programmers, PCI security testers and those involved in cyber security measures and implementation.

COURSE AGENDA

1

Introduction to Ethical Hacking

  • Defining a penetration testing methodology
  • Creating a security testing plan
2

Footprinting and Intelligence Gathering

  • Acquiring target information
    • Locating useful and relevant information
    • Scavenging published data
    • Mining archive sites
  • Scanning and enumerating resources
    • Identifying authentication methods
    • Harvesting email information
    • Interrogating network services
    • Scanning from the inside out with HTML and XHR
3

Identifying Vulnerabilities

  • Correlating weaknesses and exploits
    • Researching databases
    • Determining target configuration
    • Evaluating Vulnerability Assessment tools
  • Leveraging opportunities for attack
    • Discovering exploit resources
    • Attacking with Metasploit
4

Attacking Servers and Devices to Build Better Defenses

  • Bypassing router access control lists (ACLs)
    • Discovering filtered ports
    • Manipulating ports to gain access
    • Connecting to blocked services
  • Compromising operating systems
    • Examining Windows protection modes
    • Analyzing Linux/UNIX processes
  • Subverting web applications
    • Injecting SQL and HTML code
    • Hijacking web sessions by prediction and cross-site scripting (XSS)
    • Bypassing authentication mechanisms
5

Manipulating Clients to Uncover Internal Threats

  • Baiting and snaring inside users
    • Executing client-side attacks
    • Gaining control of browsers
  • Manipulating internal clients
    • Harvesting client information
    • Enumerating internal data
  • Deploying the Social Engineering Toolkit
    • Cloning a legitimate site
    • Diverting clients by poisoning DNS
6

Exploiting Targets to Increase Security

  • Initiating remote shells
    • Selecting reverse or bind shells
    • Leveraging the Metasploit Meterpreter
  • Pivoting and island-hopping
    • Deploying portable media attacks
    • Routing through compromised clients
  • Pilfering target information
    • Stealing password hashes
    • Extracting infrastructure routing, DNS and NetBIOS data
  • Uploading and executing payloads
    • Controlling memory processes
    • Utilizing the remote file system
7

Testing Antivirus and IDS Security

  • Masquerading network traffic
    • Obfuscating vectors and payloads
    • Side-stepping perimeter defenses
  • Evading antivirus systems
    • Falsifying file headers to inject malware
    • Discovering the gaps in antivirus protection
8

Mitigating Risks and Next Steps

  • Reporting results and creating an action plan
  • Managing patches and configuration
  • Recommending cyber security countermeasures

Encarta Labs Advantage

  • One Stop Corporate Training Solution Providers for over 6,000 various courses on a variety of subjects
  • All courses are delivered by Industry Veterans
  • Get jumpstarted from newbie to production ready in a matter of few days
  • Trained more than 50,000 Corporate executives across the Globe
  • All our trainings are conducted in workshop mode with more focus on hands-on sessions

View our other course offerings by visiting https://www.encartalabs.com/course-catalogue-all.php

Contact us for delivering this course as a public/open-house workshop/online training for a group of 10+ candidates.

Top
Notice
X