Learning Objectives
5 objectives- Understand the fundamental concepts and importance of ethical hacking in cybersecurity.
- Develop skills in reconnaissance, vulnerability assessment, exploitation, and post-exploitation techniques.
- Apply various penetration testing methodologies to evaluate system and network security.
- Recognize and defend against social engineering and wireless network attacks.
- Effectively document findings and produce professional reports adhering to compliance standards.
Content Outline
PreviewUnit 612: Ethical Hacking and Penetration Testing
1. Introduction to Ethical Hacking
- Definition and scope of ethical hacking
- Differences between ethical hacking and malicious hacking
- Importance of ethical hacking in modern cybersecurity
- Legal and ethical considerations
- Overview of ethical hacking methodologies and techniques
2. Reconnaissance and Footprinting
- Purpose and importance of reconnaissance
- Passive vs. active reconnaissance
- Footprinting techniques:
- DNS queries
- WHOIS lookup
- Network scanning
- Scanning:
- Port scanning (e.g., using Nmap)
- Vulnerability scanning overview
- Enumeration techniques:
- SNMP enumeration
- NetBIOS enumeration
- SMTP enumeration
- Tools commonly used for reconnaissance and footprinting
3. Vulnerability Assessment and Scanning
- Understanding vulnerabilities and their impact
- Types of vulnerability assessments
- Overview of vulnerability scanning tools:
- Nessus
- OpenVAS
- Conducting vulnerability scans:
- Configuration and scope
- Interpreting scan results
- Prioritizing vulnerabilities for remediation
4. Exploitation and Post-Exploitation
- Exploitation fundamentals
- Using exploits to gain unauthorized access:
- Buffer overflow attacks
- SQL injection exploitation
- Remote code execution
- Post-exploitation techniques:
- Maintaining access (backdoors, rootkits)
- Privilege escalation
- Data extraction and lateral movement
- Ethical considerations and containment
5. Penetration Testing Methodologies
- Overview of penetration testing
- Types of testing:
- White-box testing
- Black-box testing
- Grey-box testing
- Phases of penetration testing:
- Planning and reconnaissance
- Scanning and enumeration
- Exploitation
- Reporting
- Tools and frameworks supporting penetration testing
6. Social Engineering Attacks
- Understanding social engineering and its impact
- Common social engineering techniques:
- Phishing
- Pretexting
- Tailgating
- Baiting
- Psychological principles exploited
- Detection and prevention strategies
7. Wireless Network Hacking
- Wireless network fundamentals
- Wireless security protocols:
- WEP
- WPA/WPA2
- Common wireless attacks:
- WEP/WPA cracking
- Rogue access points
- Man-in-the-middle attacks
- Tools for wireless network assessment
- Securing wireless networks
8. Web Application Security
- Introduction to web application vulnerabilities
- Common vulnerabilities:
- SQL Injection
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Insecure authentication and session management
- Techniques to identify and exploit vulnerabilities
- Best practices for securing web applications
9. Reporting and Compliance
- Importance of documentation in ethical hacking
- Structure of a professional penetration testing report:
- Executive summary
- Technical findings
- Risk assessment
- Recommendations
- Adherence to legal and compliance standards (e.g., GDPR, PCI-DSS)
- Ethical guidelines and professional conduct
Unlock the full outline
Get the complete content outline, learning outcomes and assessment methods for Ethical Hacking And Penetration Testing.
KSh 20 one-off, or included with a plan
Learning Outcomes
Unlock the outline above to see learning outcomes.
Assessment Methods
Unlock the outline above to see assessment methods.