Learning Tree International

Security Training

1-888-THE-TREE (1-888-843-8733)
 

Request Info

Salutation

First Name

Last Name

Job Title

Department

Mailstop

Company

Address

P.O. Box

City

Province

Postal Code

Country
List

Work Telephone

Ext.

E-mail Address

A representative will contact you to follow up your request.

Privacy Statement

 
Save up to $900 per course with Training Vouchers

 

Ethical Hacking and Countermeasures:
Hands-On

Preventing Network and System Breaches


Course 5374 Days

  E-mail   Print   Q&A   PDF   Facebook   Twitter

Quick Enrol

You Will Learn How To

  • Deploy ethical hacking to expose weaknesses in your organization and select countermeasures
  • Gather intelligence by employing reconnaissance, published data and scanning tools
  • Probe and compromise your network using hacking tools to test and improve your security
  • Discover how malicious hackers exploit weaknesses to "own" the network
  • Protect against privilege escalation to prevent intrusions
  • Evade antivirus software, firewalls and IDS

Course Benefits

As network breaches become increasingly sophisticated, proactive defenses are essential to counter malicious attacks. In this course, you learn to discover weaknesses in your network using the same mindset and methods as hackers. You acquire the knowledge to systematically test and exploit internal and external defenses. You learn countermeasures and how to reduce risk to your enterprise.

Who Should Attend

Security consultants, Information Assurance auditors, firewall/IDS personnel, programmers, PCI security testers and others responsible for securing enterprise systems. Security knowledge at the level of Course 468, "System and Network Security Introduction," and strong TCP/IP experience, is assumed.

Hands-On Training

Hands-on exercises model hacking methods and countermeasures, including:
  • Preparing the hacker toolkit
  • Executing advanced port scanning
  • Linking vulnerabilities and exploits
  • Determining the vulnerabilities of a network
  • Performing injection attacks
  • Predicting and hijacking Web sessions
  • Poisoning DNS to lure clients
  • Configuring and using the Metasploit Framework
  • Defeating stateless firewalls, IDS and antivirus software
  • Deploying rootkits

Course 537 Content

Introduction to Ethical Hacking

  • Defining a penetration testing methodology
  • Creating a security testing plan
  • Adhering to PCI standards
  • Assembling the hacking tools

Footprinting and Intelligence Gathering

Acquiring target information

  • Locating useful and relevant information
  • Scavenging published data
  • Mining archive sites

Scanning and enumerating resources

  • Identifying authentication methods
  • Analyzing firewalls
  • Harvesting e-mail information
  • Interrogating network services
  • Scanning from the inside out with HTML

Identifying Vulnerabilities

Correlating weaknesses and exploits

  • Researching databases
  • Determining target configuration
  • Evaluating Vulnerability Assessment tools

Leveraging opportunities for attack

  • Discovering exploit resources
  • Attacking with Metasploit

Attacking Servers and Devices to Build Better Defenses

Bypassing router access control lists (ACLs)

  • Discovering filtered ports
  • Manipulating ports to gain access
  • Connecting to blocked services

Compromising operating systems

  • Examining Windows protection modes
  • Analyzing Linux/UNIX processes

Subverting Web applications

  • Injecting SQL and HTML code
  • Hijacking Web sessions by prediction and fixation
  • Bypassing authentication mechanisms

Manipulating Clients to Uncover Internal Threats

Baiting and snaring inside users

  • Poisoning DNS
  • Executing Cross-Site Scripting (XSS)
  • Gaining control of browsers

Creating custom malware

  • Harvesting client information
  • Enumerating internal data

Exploiting Targets to Increase Security

Initiating remote shells

  • Selecting reverse or bind shells
  • Leveraging the Metasploit Meterpreter

Pivoting and island hopping

  • Deploying portable media attacks
  • Routing through compromised clients
  • Forwarding and redirecting ports

Pilfering target information

  • Stealing password hashes
  • Extracting infrastructure routing, DNS and NetBIOS data

Uploading and executing payloads

  • Controlling memory processes
  • Utilizing the remote file system

Testing Antivirus and IDS Security

Masquerading network traffic

  • Obfuscating vectors and payloads
  • Sidestepping perimeter defenses

Evading antivirus systems

  • Falsifying file headers to inject malware
  • Discovering the gaps in antivirus protection

Installing rootkits to hide activity

  • Hooking APIs and virtualizing malware
  • Controlling memory and execution with Direct Kernel Object Manipulation (DKOM)

Mitigating Risk and Next Steps

  • Reporting results and creating an action plan
  • Managing patches and configuration
  • Recommending defensive countermeasures
  • Staying current with tools, trends and technology

<< Back to Security Course List
 

Related Courses

 
Ethical Hacking and Countermeasures: Hands-On
Hands-On Training

Course Dates

Nov 30 - Dec 3Toronto enrol
Jan 11 - 14Ottawa enrol
May 3 - 6Ottawa enrol
May 31 - Jun 3Toronto enrol

US Dates

Sep 21 - 24Reston, VA enrol
Oct 26 - 29Rockville, MD enrol
Nov 16 - 19New York enrol
Nov 30 - Dec 3Reston, VA enrol
Mar 29 - Apr 1Reston, VA enrol
Apr 26 - 29Rockville, MD enrol
Live online classroom training.

Attend highlighted events
in person or online with Learning Tree AnyWareTM.

More Dates and Locations.

On-Site &
Custom Training

Bring this or any Learning Tree course to your location or have it customized for your organization.

Tuition

$ 3,095 Standard Tuition
Tuition with a Savings Plan
$ 1,800Flex-Training Pass
$ 1,800Multi-Course Passport
$ 2,650Voucher 5-Pack
$ 2,785Alumni Gold Discount
$ 2,660Government Discount
 
Ethical Hacking and Countermeasures: Hands-On

Course participants analyzing browser security.


The most recent 100 evaluations scored this course:

  (3.80/4.00)

 
"The Learning Tree instructor I had was willing to come in early to work with you if you had questions or didn't grasp the material. That's a real plus."

– K. Upperman
NJVC

 
Ten Questions to Ask Your Training Provider - Position Paper