Ethical Hacking Course Content
Ethical Hacking Course Content
Cover the fundamentals of key issues in the information security world, including the basics of
ethical hacking, information security controls, relevant laws, and standard procedures.
Key topics covered:
Elements of Information Security
Cyber Kill Chain Methodology
MITRE ATT&CK Framework
Hacker Classes
Ethical Hacking
Information Assurance (IA)
Risk Management
Incident Management
PCI DSS
HIPPA
SOX
GDPR
Module 2: Foot Printing and Reconnaissance
Learn how to use the latest techniques and tools to perform foot printing and reconnaissance, a
critical pre-attack phase of the ethical hacking process.
Hands-On Lab Exercises:
Over 30 hands-on exercises with real-life simulated targets to build skills on how to:
Perform foot printing on the target network using search engines, web services, and social
networking sites
Perform website, email, whois, DNS, and network foot printing on the target network
Module 3: Scanning Networks
Cover the fundamentals of key issues in the information security world, including the basics of
ethical hacking, information security controls, relevant laws, and standard procedures.
Hands-On Lab Exercises:
Over 10 hands-on exercises with real-life simulated targets to build skills on how to:
Perform host, port, service, and OS discovery on the target network
Perform scanning on the target network beyond IDS and firewall
Module 4: Enumeration
Learn various enumeration techniques, such as Border Gateway Protocol (BGP) and Network File
Sharing (NFS) exploits, plus associated countermeasures.
Hands-On Lab Exercises:
Over 20 hands-on exercises with real-life simulated targets to build skills on how to:
Perform NetBIOS, SNMP, LDAP, NFS, DNS, SMTP, RPC, SMB, and FTP Enumeration
Module 5: Vulnerability Analysis
Learn how to identify security loopholes in a target organization’s network, communication
infrastructure, and end systems.
Hands-On Lab Exercises:
Over 5 hands-on exercises with real-life simulated targets to build skills on how to:
Perform vulnerability research using vulnerability scoring systems and databases
Perform vulnerability assessment using various vulnerability assessment tools
Module 6: System Hacking
Learn about the various system hacking methodologies—including steganography, steganalysis
attacks, and covering tracks.
Hands-On Lab Exercises:
Over 25 hands-on exercises with real-life simulated targets to build skills on how to:
Perform an active online attack to crack the system’s password
Escalate privileges using privilege escalation tools
Escalate privileges in Linux machine
Hide data using steganography
Clear Windows and Linux machine logs using various utilities
Hiding artifacts in Windows and Linux machines
Module 7: Malware Threats
Get an introduction to the different types of malware, such as Trojans, viruses, and worms, as well
as system auditing for malware attacks, malware analysis, and countermeasures.
Hands-On Lab Exercises:
Over 20 hands-on exercises with real-life simulated targets to build skills on how to:
Gain control over a victim machine using malware
Infect the target system using a virus
Perform static and dynamic malware analysis
Key topics covered:
Malware, Components of Malware
APT
Trojan
Types of Trojans
Exploit Kits
Virus
Virus Lifecycle
Types of Viruses
Ransomware
Computer Worms
Fileless Malware
Malware Analysis
Static Malware Analysis
Dynamic Malware Analysis
Virus Detection Methods
Trojan Analysis
Virus Analysis
Fileless Malware Analysis
Anti-Trojan Software
Antivirus Software
Fileless Malware Detection Tools
Module 8: Sniffing
Learn about packet-sniffing techniques and how to use them to discover network vulnerabilities, as
well as countermeasures to defend against sniffing attacks.
Hands-On Lab Exercises:
Over 10 hands-on exercises with real-life simulated targets to build skills on how to:
Perform MAC flooding, ARP poisoning, MITM and DHCP starvation attack
Spoof a MAC address of Linux machine
Perform network sniffing using various sniffing tools
Detect ARP poisoning in a switch-based network
Key topics covered:
Network Sniffing
Wiretapping
MAC Flooding
DHCP Starvation Attack
ARP Spoofing Attack
ARP Poisoning
ARP Poisoning Tools
MAC Spoofing
STP Attack
DNS Poisoning
DNS Poisoning Tools
Sniffing Tools
Sniffer Detection Techniques
Promiscuous Detection Tools
Module 9: Social Engineering
Learn social engineering concepts and techniques, including how to identify theft attempts, audit
human-level vulnerabilities, and suggest social engineering countermeasures.
Hands-On Lab Exercises:
Over 4 hands-on exercises with real-life simulated targets to build skills on how to:
Perform social engineering using Various Techniques
Spoof a MAC address of a Linux machine
Detect a phishing attack
Audit an organization’s security for phishing attacks
Key topics covered:
Social Engineering
Types of Social Engineering
Phishing
Phishing Tools
Insider Threats/Insider Attacks
Identity Theft
Module 10: Denial-of-Service
Learn about different Denial-of-Service (DoS) and Distributed DoS (DDoS) attack techniques, as
well as the tools used to audit a target and devise DoS and DDoS countermeasures and protections.
Hands-On Lab Exercises:
Over 5 hands-on exercises with real-life simulated targets to build skills on how to:
Perform a DoS and DDoS attack on a target host
Detect and protect against DoS and DDoS attacks
Key topics covered:
DoS Attack, DDoS Attack
Botnets
DoS/DDoS Attack Techniques
DoS/DDoS Attack Tools
DoS/DDoS Attack Detection Techniques
DoS/DDoS Protection Tools
Module 11: Session Hijacking
Understand the various session hijacking techniques used to discover network-level session
management, authentication, authorization, and cryptographic weaknesses and associated
countermeasures.
Hands-On Lab Exercises:
Over 4 hands-on exercises with real-life simulated targets to build skills on how to:
Perform session hijacking using various tools
Detect session hijacking
Key topics covered:
Session Hijacking
Types of Session Hijacking
Spoofing
Application-Level Session Hijacking
Man-in-the-Browser Attack
Client-side Attacks
Session Replay Attacks
Session Fixation Attack
CRIME Attack
Network Level Session Hijacking
TCP/IP Hijacking
Session Hijacking Tools
Session Hijacking Detection Methods
Session Hijacking Prevention Tools