Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 35 hours
Course Outline
Introduction to Ethical Hacking
- Foundations of ethical hacking and information security
- Overview of cybersecurity threats, vulnerabilities, and attack surfaces
- Core concepts, phases, and methodologies in ethical hacking
- Information security controls and security frameworks
- Classifications of hackers, attacks, and attack vectors
- Legal, regulatory, and ethical considerations
- Introduction to AI applications in ethical hacking and cybersecurity
- Concepts of the Cyber Kill Chain and MITRE ATT&CK
Footprinting and Reconnaissance
- Basics of reconnaissance activities
- Techniques for passive and active information gathering
- Identifying target infrastructure and potential attack surfaces
- Utilizing search engines for reconnaissance
- WHOIS, DNS, and IP intelligence analysis
- Footprinting websites and organizations
- Reconnaissance via email and social media
- Discovering cloud and network infrastructure
- OSINT tools and techniques
- AI-assisted reconnaissance and information analysis
Scanning Networks
- Network scanning concepts and methodologies
- Host discovery and port scanning techniques
- Scanning via TCP, UDP, and ICMP protocols
- Identifying services and operating systems
- Banner grabbing techniques
- Mapping network topology
- Vulnerability scanning procedures
- Considerations for Firewalls and IDS
- Scanning tools and automation
- AI-assisted network analysis
Enumeration
- Enumeration concepts and techniques
- Enumeration on Windows and Linux systems
- NetBIOS and SMB enumeration
- SNMP enumeration
- LDAP and directory services enumeration
- DNS and SMTP enumeration
- Enumeration of users, groups, and shares
- Active Directory reconnaissance
- Countermeasures against enumeration
- Automated enumeration techniques
Vulnerability Analysis
- Vulnerability assessment methodologies
- Identifying and classifying vulnerabilities
- Understanding CVE, CVSS, and vulnerability databases
- Network and system vulnerability scanning
- Web and application vulnerability assessment
- Cloud and container vulnerability considerations
- Prioritizing vulnerabilities and risk analysis
- Managing false positives and validation
- The vulnerability management lifecycle
- AI-assisted vulnerability analysis and prioritization
System Hacking
- System hacking methodology
- Password and credential attacks
- Password cracking techniques
- Weaknesses in authentication and authorization
- Privilege escalation
- Fundamentals of exploitation
- Maintaining persistent access
- Techniques for hiding files and systems
- Covering tracks
- Post-exploitation on Windows and Linux
- AI-assisted exploitation and attack-path analysis
Malware Threats
- Malware concepts and classifications
- Viruses, worms, Trojans, ransomware, and spyware
- Fileless and polymorphic malware
- Rootkits and backdoors
- Malware delivery mechanisms
- Command-and-control concepts
- Malware analysis fundamentals
- Techniques for evading anti-malware
- Malware detection and prevention
- AI-enabled malware and defensive countermeasures
Sniffing
- Fundamentals of network sniffing
- Packet capture and traffic analysis
- Passive and active sniffing
- Protocol analysis
- ARP poisoning and MAC attacks
- DNS and DHCP-based attacks
- Credential interception
- Man-in-the-middle concepts
- Sniffing countermeasures
- Secure network communication
- AI-assisted packet and traffic analysis
Social Engineering
- Principles of social engineering
- Human-based and technical-based attacks
- Phishing, spear phishing, and whaling
- Vishing, smishing, and other communication-based attacks
- Impersonation and pretexting
- Baiting and physical social engineering
- The social engineering attack lifecycle
- Awareness training and security testing
- Detection and prevention strategies
- AI-generated phishing and social engineering threats
Denial-of-Service
- DoS and DDoS fundamentals
- Types of denial-of-service attacks
- Network and application-layer attacks
- Resource exhaustion
- Distributed attack infrastructure
- Botnets and amplification concepts
- DDoS detection and monitoring
- Mitigation and prevention techniques
- Incident response for DoS attacks
- AI-assisted attack detection and response
Session Hijacking
- Session management fundamentals
- Session identification and authentication
- Session hijacking techniques
- Cookie and token-based attacks
- TCP/IP session hijacking
- Browser and web session attacks
- Man-in-the-middle attacks
- Session fixation
- Session security controls
- Detection and mitigation techniques
Evading IDS, Firewalls, and Honeypots
- Intrusion detection and prevention systems
- Firewall architectures and technologies
- Honeypots and deception technologies
- Network security monitoring
- IDS/IPS evasion concepts
- Firewall evasion techniques
- Traffic fragmentation and obfuscation concepts
- Proxy and tunneling concepts
- Honeypot detection and countermeasures
- Defensive monitoring and hardening
- AI-assisted anomaly detection and adaptive defense
Hacking Web Servers
- Web server architecture and technologies
- Web server footprinting
- Web server enumeration
- Common web server vulnerabilities
- Misconfiguration and insecure defaults
- Authentication and access-control weaknesses
- Directory traversal and related attacks
- Web server attacks and exploitation concepts
- Web server hardening
- Patch and configuration management
- Web server monitoring and incident response
Hacking Web Applications
- Web application architecture
- Web application attack surfaces
- Client-side and server-side vulnerabilities
- Authentication and authorization attacks
- Session management vulnerabilities
- Input validation weaknesses
- Cross-site scripting
- Cross-site request forgery
- File inclusion and upload vulnerabilities
- API security fundamentals
- Web application security testing methodologies
- Secure coding and mitigation techniques
- AI-assisted web application security testing
SQL Injection
- Database and SQL fundamentals
- SQL injection concepts and attack vectors
- Authentication bypass concepts
- Error-based, union-based, and blind SQL injection
- Database fingerprinting
- Data extraction concepts
- SQL injection testing methodologies
- Automated SQL injection assessment
- SQL injection prevention
- Parameterized queries and input validation
- Database security monitoring
- AI-assisted SQL injection detection and analysis
Hacking Wireless Networks
- Wireless networking fundamentals
- Wi-Fi standards and security protocols
- Wireless reconnaissance
- Wireless network discovery
- Authentication and encryption weaknesses
- Wireless traffic analysis
- Rogue access points and evil-twin concepts
- Wireless denial-of-service concepts
- Bluetooth security fundamentals
- Wireless security testing methodologies
- Wireless hardening and monitoring
- Secure wireless configuration
Hacking Mobile Platforms
- Mobile security architecture
- Android and iOS security concepts
- Mobile application attack surfaces
- Mobile application reconnaissance
- Insecure data storage
- Authentication and authorization weaknesses
- Mobile communication security
- API and backend security
- Mobile malware
- Mobile application security testing
- Mobile device security controls
- Mobile application hardening
IoT and OT Hacking
- IoT and OT security fundamentals
- IoT architecture and communication protocols
- IoT device discovery and reconnaissance
- IoT vulnerabilities and misconfigurations
- Firmware and hardware security concepts
- IoT authentication and access control
- Industrial Control Systems and OT environments
- SCADA security fundamentals
- OT attack surfaces and risks
- IoT/OT vulnerability assessment
- Defensive monitoring and segmentation
- Secure IoT and OT architecture
- AI-enabled IoT and OT security considerations
Cloud Computing
- Cloud computing fundamentals
- Cloud service models and deployment models
- Cloud architecture and shared responsibility
- Cloud reconnaissance and attack surfaces
- Identity and access management
- Cloud storage and database security
- Virtualization and container security
- Cloud misconfigurations
- Cloud network security
- Cloud privilege escalation concepts
- Cloud vulnerability assessment
- Cloud logging and monitoring
- Cloud incident response
- AI-assisted cloud security analysis
Cryptography
- Cryptography fundamentals and terminology
- Symmetric and asymmetric encryption
- Hashing and message integrity
- Digital signatures and certificates
- Public Key Infrastructure
- Key management and cryptographic protocols
- Common cryptographic vulnerabilities
- Password hashing and secure authentication
- SSL/TLS security concepts
- Cryptographic attacks and weaknesses
- Encryption implementation best practices
- Cryptography in cloud, mobile, and IoT environments
- Emerging cryptographic and AI-related security considerations
Requirements
What is new in CEH version 13?
- AI-powered - Recognized as the world’s first ethical hacking certification to fully leverage artificial intelligence capabilities.
- Hands-on experience - Refine your practical abilities in realistic scenarios via interactive labs, allowing you to simulate attack vectors and master advanced hacking tools.
- More efficiency – Discover AI-driven methods that can increase cyber defense efficiency by 40% while optimizing your workflow.
- Power-packed, updated curriculum – Gain proficiency in the latest advanced attack techniques, emerging trends, and defensive countermeasures.
- 2x productivity gains – Features include Advanced Threat Detection, Enhanced Decision Making, Adaptive Learning, Enhanced Reporting, and Automation of Repetitive Tasks.
- Real-world skills, proven mastery – Engage in monthly global hacking competitions to compete with peers and climb the leaderboards.
Prerequisites
- Familiarity with Windows and Linux operating systems
- Basic knowledge of cybersecurity and IT fundamentals
Audience
- Mid-Level Information Security Auditor
- Cybersecurity Auditor
- Security Administrator
- IT Security Administrator
- Information Security Analyst 1
- Infosec Security Administrator
- Cybersecurity Analyst level 1, level 2, & level 3
- Network Security Engineer
- SOC Security Analyst
- Network Engineer
- Senior Security Consultant
- Information Security Manager
- Senior SOC Analyst
- Solution Architect
- Cybersecurity Consultant
- Cyber Defense Analyst
- Vulnerability Assessment Analyst
- Warning Analyst
- All-Source Analyst
- Cyber Defense Incident Responder
- Research & Development Specialist
- Senior Cloud Security Analyst
- Third Party Risk Management
- Threat Hunting Analyst
- Penetration tester
- Cyber Delivery Manager
- Application Security Risk
- Threat Modelling Specialist
- Web Application Penetration Testing
- SAP Vulnerability Management - Solution Delivery Advisor
- Ethical Hacker
- SIEM Threat Responder
- Product Security Engineer / Manager
- Endpoint Security Engineer
- Cybersecurity Instructor
- Red Team Specialist
- Data Protection & Privacy Officer
- SOAR Engineer
- AI Security Engineer
- Sr. IAM Engineer
- PCI Security Advisor
- Exploitation Analyst (EA)
- Zero Trust Solutions Engineer / Analyst
- Cryptographic Engineer
- AI/ML Security Engineer
- Machine Learning Security Specialist
- AI Penetration Tester
- AI/ML Security Consultant
- Crypto Security Consultant
Testimonials (1)
The really lot of extra tools that was mentioned and the real life examples form Mane's experience.