Penetration Testing Essential Training

Penetration Testing Essential Training

2h 56mIntermediate2024-07-18

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

Penetration testing is one of the best ways to see if your security will hold. It puts testers in the role of attackers, looking for vulnerabilities in your networks, computers, applications, email, and users. This course provides an introduction to the key knowledge and skills to start a program of professional penetration testing at your organization.

Cybersecurity expert Malcolm Shore reviews and demonstrates the popular pen testing tools, as well as the Bash and Python scripting skills required to be able to acquire, modify, and reuse exploit code. He also provides a refresher on the Kali Linux penetration testing toolbox, approaches to web testing, and several important facets of exploit code. At the end of this course, you'll be prepared to take more advanced training and to pursue the popular Offensive Security Certified Professional (OSCP) certification.

Learning objectives
Summarize the key concepts and stages of the cyber kill chain and the MITRE ATT&CK repository.
Demonstrate proficiency in using various pen testing tools such as nmap, tcpdump, Powershell, and Bloodhound.
Write effective Bash and Python scripts to automate pen testing tasks and interact with systems and networks.
Evaluate web applications for vulnerabilities using tools like BurpSuite, Nikto, and SQLmap.
Analyze and exploit vulnerabilities in systems using Metasploit, understand exploit code, and find relevant exploits.

Skills covered

Penetration TestingLinuxEssential TrainingCybersecurityOpen Source

Concepts

Introduction

  • Establishing a solid foundation to progress into a career of penetration testing
  • What you should know
  • Disclaimer

What Is Pen Testing

  • Pen testing overview
  • The cyber kill chain
  • The MITRE ATT&CK repository

Pen Testing Tools

  • Scanning networks with Nmap
  • A netcat refresher
  • Capturing packets with tcpdump
  • Work with netstat, nbtstat, and arp
  • Scripting with PowerShell
  • Extending PowerShell with Nishang
  • What is Active Directory
  • Analyze Active Directory with BloodHound

Bash Scripting

  • Refreshing your Bash skills
  • Controlling the flow in a script
  • Using functions in bash

Python Scripting

  • Refresh your Python skills
  • Use the system functions
  • Use networking functions
  • Work with websites
  • Access SQLite databases
  • Using Scapy to work with packets
  • Leveraging OpenAI for testing

Kali and Metasploit

  • A Kali refresher
  • Fuzzing with Spike
  • Information gathering with Legion
  • Using Metasploit
  • Scan targets with GVM

Web Testing

  • Approach web testing
  • Test websites with Burp Suite
  • Check web servers with Nikto
  • Fingerprint web servers
  • Web server penetration using sqlmap

Understand Exploit Code

  • Exploit a target
  • Finding caves for code injection
  • Understand code injection
  • Understand command injection
  • Understand buffer overflows
  • Password spraying Active Directory
  • Find exploit code

Conclusion

  • What's next
80,000 Toman