Get in Touch
 Duration 35 hours

Course Outline

Introduction to Ethical Hacking

  • Foundations of ethical hacking and information security
  • Overview of cybersecurity threats, vulnerabilities, and attack surfaces
  • Core concepts, phases, and methodologies in ethical hacking
  • Information security controls and security frameworks
  • Classifications of hackers, attacks, and attack vectors
  • Legal, regulatory, and ethical considerations
  • Introduction to AI applications in ethical hacking and cybersecurity
  • Concepts of the Cyber Kill Chain and MITRE ATT&CK

Footprinting and Reconnaissance

  • Basics of reconnaissance activities
  • Techniques for passive and active information gathering
  • Identifying target infrastructure and potential attack surfaces
  • Utilizing search engines for reconnaissance
  • WHOIS, DNS, and IP intelligence analysis
  • Footprinting websites and organizations
  • Reconnaissance via email and social media
  • Discovering cloud and network infrastructure
  • OSINT tools and techniques
  • AI-assisted reconnaissance and information analysis

Scanning Networks

  • Network scanning concepts and methodologies
  • Host discovery and port scanning techniques
  • Scanning via TCP, UDP, and ICMP protocols
  • Identifying services and operating systems
  • Banner grabbing techniques
  • Mapping network topology
  • Vulnerability scanning procedures
  • Considerations for Firewalls and IDS
  • Scanning tools and automation
  • AI-assisted network analysis

Enumeration

  • Enumeration concepts and techniques
  • Enumeration on Windows and Linux systems
  • NetBIOS and SMB enumeration
  • SNMP enumeration
  • LDAP and directory services enumeration
  • DNS and SMTP enumeration
  • Enumeration of users, groups, and shares
  • Active Directory reconnaissance
  • Countermeasures against enumeration
  • Automated enumeration techniques

Vulnerability Analysis

  • Vulnerability assessment methodologies
  • Identifying and classifying vulnerabilities
  • Understanding CVE, CVSS, and vulnerability databases
  • Network and system vulnerability scanning
  • Web and application vulnerability assessment
  • Cloud and container vulnerability considerations
  • Prioritizing vulnerabilities and risk analysis
  • Managing false positives and validation
  • The vulnerability management lifecycle
  • AI-assisted vulnerability analysis and prioritization

System Hacking

  • System hacking methodology
  • Password and credential attacks
  • Password cracking techniques
  • Weaknesses in authentication and authorization
  • Privilege escalation
  • Fundamentals of exploitation
  • Maintaining persistent access
  • Techniques for hiding files and systems
  • Covering tracks
  • Post-exploitation on Windows and Linux
  • AI-assisted exploitation and attack-path analysis

Malware Threats

  • Malware concepts and classifications
  • Viruses, worms, Trojans, ransomware, and spyware
  • Fileless and polymorphic malware
  • Rootkits and backdoors
  • Malware delivery mechanisms
  • Command-and-control concepts
  • Malware analysis fundamentals
  • Techniques for evading anti-malware
  • Malware detection and prevention
  • AI-enabled malware and defensive countermeasures

Sniffing

  • Fundamentals of network sniffing
  • Packet capture and traffic analysis
  • Passive and active sniffing
  • Protocol analysis
  • ARP poisoning and MAC attacks
  • DNS and DHCP-based attacks
  • Credential interception
  • Man-in-the-middle concepts
  • Sniffing countermeasures
  • Secure network communication
  • AI-assisted packet and traffic analysis

Social Engineering

  • Principles of social engineering
  • Human-based and technical-based attacks
  • Phishing, spear phishing, and whaling
  • Vishing, smishing, and other communication-based attacks
  • Impersonation and pretexting
  • Baiting and physical social engineering
  • The social engineering attack lifecycle
  • Awareness training and security testing
  • Detection and prevention strategies
  • AI-generated phishing and social engineering threats

Denial-of-Service

  • DoS and DDoS fundamentals
  • Types of denial-of-service attacks
  • Network and application-layer attacks
  • Resource exhaustion
  • Distributed attack infrastructure
  • Botnets and amplification concepts
  • DDoS detection and monitoring
  • Mitigation and prevention techniques
  • Incident response for DoS attacks
  • AI-assisted attack detection and response

Session Hijacking

  • Session management fundamentals
  • Session identification and authentication
  • Session hijacking techniques
  • Cookie and token-based attacks
  • TCP/IP session hijacking
  • Browser and web session attacks
  • Man-in-the-middle attacks
  • Session fixation
  • Session security controls
  • Detection and mitigation techniques

Evading IDS, Firewalls, and Honeypots

  • Intrusion detection and prevention systems
  • Firewall architectures and technologies
  • Honeypots and deception technologies
  • Network security monitoring
  • IDS/IPS evasion concepts
  • Firewall evasion techniques
  • Traffic fragmentation and obfuscation concepts
  • Proxy and tunneling concepts
  • Honeypot detection and countermeasures
  • Defensive monitoring and hardening
  • AI-assisted anomaly detection and adaptive defense

Hacking Web Servers

  • Web server architecture and technologies
  • Web server footprinting
  • Web server enumeration
  • Common web server vulnerabilities
  • Misconfiguration and insecure defaults
  • Authentication and access-control weaknesses
  • Directory traversal and related attacks
  • Web server attacks and exploitation concepts
  • Web server hardening
  • Patch and configuration management
  • Web server monitoring and incident response

Hacking Web Applications

  • Web application architecture
  • Web application attack surfaces
  • Client-side and server-side vulnerabilities
  • Authentication and authorization attacks
  • Session management vulnerabilities
  • Input validation weaknesses
  • Cross-site scripting
  • Cross-site request forgery
  • File inclusion and upload vulnerabilities
  • API security fundamentals
  • Web application security testing methodologies
  • Secure coding and mitigation techniques
  • AI-assisted web application security testing

SQL Injection

  • Database and SQL fundamentals
  • SQL injection concepts and attack vectors
  • Authentication bypass concepts
  • Error-based, union-based, and blind SQL injection
  • Database fingerprinting
  • Data extraction concepts
  • SQL injection testing methodologies
  • Automated SQL injection assessment
  • SQL injection prevention
  • Parameterized queries and input validation
  • Database security monitoring
  • AI-assisted SQL injection detection and analysis

Hacking Wireless Networks

  • Wireless networking fundamentals
  • Wi-Fi standards and security protocols
  • Wireless reconnaissance
  • Wireless network discovery
  • Authentication and encryption weaknesses
  • Wireless traffic analysis
  • Rogue access points and evil-twin concepts
  • Wireless denial-of-service concepts
  • Bluetooth security fundamentals
  • Wireless security testing methodologies
  • Wireless hardening and monitoring
  • Secure wireless configuration

Hacking Mobile Platforms

  • Mobile security architecture
  • Android and iOS security concepts
  • Mobile application attack surfaces
  • Mobile application reconnaissance
  • Insecure data storage
  • Authentication and authorization weaknesses
  • Mobile communication security
  • API and backend security
  • Mobile malware
  • Mobile application security testing
  • Mobile device security controls
  • Mobile application hardening

IoT and OT Hacking

  • IoT and OT security fundamentals
  • IoT architecture and communication protocols
  • IoT device discovery and reconnaissance
  • IoT vulnerabilities and misconfigurations
  • Firmware and hardware security concepts
  • IoT authentication and access control
  • Industrial Control Systems and OT environments
  • SCADA security fundamentals
  • OT attack surfaces and risks
  • IoT/OT vulnerability assessment
  • Defensive monitoring and segmentation
  • Secure IoT and OT architecture
  • AI-enabled IoT and OT security considerations

Cloud Computing

  • Cloud computing fundamentals
  • Cloud service models and deployment models
  • Cloud architecture and shared responsibility
  • Cloud reconnaissance and attack surfaces
  • Identity and access management
  • Cloud storage and database security
  • Virtualization and container security
  • Cloud misconfigurations
  • Cloud network security
  • Cloud privilege escalation concepts
  • Cloud vulnerability assessment
  • Cloud logging and monitoring
  • Cloud incident response
  • AI-assisted cloud security analysis

Cryptography

  • Cryptography fundamentals and terminology
  • Symmetric and asymmetric encryption
  • Hashing and message integrity
  • Digital signatures and certificates
  • Public Key Infrastructure
  • Key management and cryptographic protocols
  • Common cryptographic vulnerabilities
  • Password hashing and secure authentication
  • SSL/TLS security concepts
  • Cryptographic attacks and weaknesses
  • Encryption implementation best practices
  • Cryptography in cloud, mobile, and IoT environments
  • Emerging cryptographic and AI-related security considerations

Requirements

What is new in CEH version 13?

  • AI-powered - Recognized as the world’s first ethical hacking certification to fully leverage artificial intelligence capabilities.
  • Hands-on experience - Refine your practical abilities in realistic scenarios via interactive labs, allowing you to simulate attack vectors and master advanced hacking tools.
  • More efficiency – Discover AI-driven methods that can increase cyber defense efficiency by 40% while optimizing your workflow.
  • Power-packed, updated curriculum – Gain proficiency in the latest advanced attack techniques, emerging trends, and defensive countermeasures.
  • 2x productivity gains – Features include Advanced Threat Detection, Enhanced Decision Making, Adaptive Learning, Enhanced Reporting, and Automation of Repetitive Tasks.
  • Real-world skills, proven mastery – Engage in monthly global hacking competitions to compete with peers and climb the leaderboards.

Prerequisites

  • Familiarity with Windows and Linux operating systems
  • Basic knowledge of cybersecurity and IT fundamentals

Audience

  • Mid-Level Information Security Auditor
  • Cybersecurity Auditor
  • Security Administrator
  • IT Security Administrator
  • Information Security Analyst 1
  • Infosec Security Administrator
  • Cybersecurity Analyst level 1, level 2, & level 3
  • Network Security Engineer
  • SOC Security Analyst
  • Network Engineer
  • Senior Security Consultant
  • Information Security Manager
  • Senior SOC Analyst
  • Solution Architect
  • Cybersecurity Consultant
  • Cyber Defense Analyst
  • Vulnerability Assessment Analyst
  • Warning Analyst
  • All-Source Analyst
  • Cyber Defense Incident Responder
  • Research & Development Specialist
  • Senior Cloud Security Analyst
  • Third Party Risk Management
  • Threat Hunting Analyst
  • Penetration tester
  • Cyber Delivery Manager
  • Application Security Risk
  • Threat Modelling Specialist
  • Web Application Penetration Testing
  • SAP Vulnerability Management - Solution Delivery Advisor
  • Ethical Hacker
  • SIEM Threat Responder
  • Product Security Engineer / Manager
  • Endpoint Security Engineer
  • Cybersecurity Instructor
  • Red Team Specialist
  • Data Protection & Privacy Officer
  • SOAR Engineer
  • AI Security Engineer
  • Sr. IAM Engineer
  • PCI Security Advisor
  • Exploitation Analyst (EA)
  • Zero Trust Solutions Engineer / Analyst
  • Cryptographic Engineer
  • AI/ML Security Engineer
  • Machine Learning Security Specialist
  • AI Penetration Tester
  • AI/ML Security Consultant
  • Crypto Security Consultant

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories