Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Complete Guide to Penetration Testing

Complete Guide to Penetration Testing

7h 18mIntermediate2024-09-25

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

In this comprehensive course, cybersecurity expert Malcolm Shore provides training in the three key areas of scripting—bash, Python, Powershell—and highlights the use of Kali Linux. Explore the use of basic tools for enumeration, vulnerability detection, and file transfer. Go over testing the different environments that a pen tester will encounter, such as web, cloud, active directory, and wireless. Learn about password brute force and cracking techniques, code injection through SQL, and the use of web and command shells. Discover how the key tools that come with Kali can be used to run exploits and how exploits work. Plus, go over the basics of malware reverse engineering and analysis.

Skills covered

Penetration TestingSecurity TestingCybersecurityOne-Off

Concepts

0. Introduction

  • 01 - Introduction to complete pen testing
  • 02 - What you should know
  • 03 - Disclaimer

1. What is Pen Testing

  • 04 - What is pen testing
  • 05 - Pen testing frameworks
  • 06 - The cyber kill chain
  • 07 - The MITRE ATT&CK repository
  • 08 - Scope of pen testing
  • 09 - Note taking
  • 10 - Living off the land

2. Setting Up a Pen Test Lab

  • 11 - Using a cyber lab
  • 12 - Crafting attacks with Kali Autopilot
  • 13 - Using VulnHub servers in a cyber range
  • 14 - Generating implants with sliver

3. The Basic Toolset

  • 15 - A Kali refresher
  • 16 - Scanning networks with Nmap
  • 17 - Using Nmap scripts
  • 18 - Open source information from Shodan
  • 19 - A netcat refresher
  • 20 - Relaying between network zones
  • 21 - Capturing packets with tcpdump
  • 22 - Working with netstat, nbtstat, and arp
  • 23 - Generating shells with msfvenom
  • 24 - Using Metasploit
  • 25 - Using PowerHub

4. Scripting in Windows with PowerShell

  • 26 - Basics of PowerShell
  • 27 - PowerShell variables and control flow
  • 28 - PowerShell for pen testers
  • 29 - Extending PowerShell with Nishang
  • 30 - Bypassing the antimalware service
  • 31 - Post-exploitation with PowerShell Empire

5. Scripting in Linux with Bash

  • 32 - Refreshing your Bash skills
  • 33 - Controlling the flow in a script
  • 34 - Using functions in Bash

6. Python Scripting

  • 35 - Refreshing your Python skills
  • 36 - Using the system functions
  • 37 - Using networking functions
  • 38 - Working with websites
  • 39 - Accessing SQLite databases
  • 40 - Using Scapy to work with packets
  • 41 - Leveraging OpenAI for testing

7. Commonly Used Kali Tools

  • 42 - Introducing password recovery
  • 43 - Using command line tools for dictionaries
  • 44 - Having a ripping good time
  • 45 - Running an exploit from Kali
  • 46 - Fuzzing with Spike
  • 47 - Information gathering with Legion
  • 48 - Using Metasploit
  • 49 - Scan targets with GVM

8. Web Testing

  • 50 - A refresher on web technology
  • 51 - Approaches to web testing
  • 52 - Refreshing your basic web testing skills
  • 53 - Fingerprinting web servers
  • 54 - A refresher on web shell implants
  • 55 - Web server penetration using SQLMap
  • 56 - Busting open websites
  • 57 - Testing websites with Burp Suite
  • 58 - Exploiting message headers with Burp Suite
  • 59 - Exploiting your way into the gym
  • 60 - Understanding CMS targets
  • 61 - Getting into WordPress
  • 62 - Shelling through WordPress
  • 63 - Exploiting Joomla via SQL

9. Testing Active Directory

  • 64 - Understand Active Directory's role in security
  • 65 - What are Active Directory Domain Services
  • 66 - Interact with Active Directory at the command line
  • 67 - Active Directory security audit
  • 68 - Password spraying Active Directory
  • 69 - Use CrackMapExec to access and enumerate AD
  • 70 - Set the BloodHound loose
  • 71 - What is Kerberos
  • 72 - Kerberos brute forcing attacks
  • 73 - Carry out a Kerberos roasting

10. Understanding Exploits

  • 74 - Exploiting a target
  • 75 - Spraying passwords with Hydra
  • 76 - Understand code injection
  • 77 - Understand buffer overflows
  • 78 - Finding exploit code

11. Wireless Testing

  • 79 - Understanding wireless networks
  • 80 - Selecting an antenna
  • 81 - Heat mapping with Ekahau
  • 82 - Scanning with Vistumbler
  • 83 - Using wifite and Aircrack-ng to test WPA passwords
  • 84 - Scanning and attacking with Fluxion

12. Introduction to Malware Analysis

  • 85 - The evolution of malware
  • 86 - How malware works
  • 87 - Analyzing BlackEnergy and GreyEnergy
  • 88 - Using reverse engineering to understand code

13. Testing in the Clouds

  • 89 - Cloud security guidance
  • 90 - Essential characteristics
  • 91 - Cloud services
  • 92 - Infrastructure as a service
  • 93 - Platform as a service
  • 94 - Software as a service
  • 95 - Microsoft Azure
  • 96 - Amazon Web Services
  • 97 - Unauthorized public access to buckets
  • 98 - Unauthorized user access to buckets
  • 99 - Searching for account keys

Conclusion

  • 100 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal