Introduction to Ethical Hacking
- Elements of information security, attack classes and hacker types
- Ethical hacking and AI-driven ethical hacking, AI tools for ethical hackers
- CEH Ethical Hacking Framework, Cyber Kill Chain and MITRE ATT&CK
- Information assurance, risk management, threat intelligence lifecycle and incident management
- Laws and standards: PCI DSS, HIPAA, SOX, GDPR and Data Protection Act
Footprinting and Reconnaissance
- Footprinting with advanced Google hacking techniques, people search services and on the dark web
- Competitive intelligence and footprinting via social networks
- Whois queries, DNS footprinting, traceroute analysis and email footprinting
- Footprinting through social engineering and with AI-driven OSINT tools
Scanning Networks
- Scanning tools, host discovery and port scanning techniques, including with AI
- Detecting service versions and operating systems (banner grabbing)
- Scanning beyond IDS and firewall
- Detecting and preventing scans
Enumeration
- NetBIOS, SNMP, LDAP, NTP, NFS and SMTP enumeration
- DNS cache snooping and DNSSEC zone walking
- IPsec, VoIP, RPC, SMB and Unix/Linux user enumeration
- Enumeration with AI and countermeasures
Vulnerability Analysis
- Vulnerability classification, scoring systems and vulnerability databases
- Vulnerability management lifecycle and vulnerability research
- Vulnerability scans, assessment tools, including AI-driven ones, and assessment reports
System Hacking
- Password attacks and password cracking tools
- Exploiting vulnerabilities with the Metasploit Framework and AI-driven tools, buffer overflow
- Active Directory enumeration and privilege escalation
- Executing applications: keyloggers, spyware, rootkits; steganography and steganalysis
- Persistence, post-exploitation on Windows and Linux, covering tracks and clearing logs
Malware Threats
- Lifecycle of advanced persistent threats
- Trojans, viruses, ransomware, worms, fileless and AI-based malware
- Static and dynamic malware analysis
- Detection methods, countermeasures and AI-driven tools for malware analysis
Sniffing
- MAC flooding, DHCP starvation, ARP spoofing and MAC spoofing
- VLAN hopping, STP attacks and DNS poisoning
- Sniffing tools, as well as techniques and tools for detecting sniffers
Social Engineering
- Human, computer-based and mobile social engineering techniques
- Impersonation, including with AI, as well as phishing and phishing tools
- Identity theft and countermeasures, detecting phishing attacks
Denial of Service
- DoS and DDoS attacks, botnets
- Attack techniques and toolkits
- Detection techniques, protection tools and protection services
Session Hijacking
- Application-level session hijacking: compromising session IDs
- Network-level session hijacking: TCP/IP, RST and blind hijacking
- Tools, detection methods and prevention measures
Evading IDS, Firewalls and Honeypots
- Intrusion detection and intrusion prevention, firewall types and tools
- Evasion techniques for IDS, firewalls, NAC and endpoint security
- Honeypots: types and tools
- Countermeasures against IDS and firewall evasion
Hacking Web Servers
- Web server architecture and vulnerabilities
- Attacks such as DNS server hijacking and web cache poisoning
- Footprinting and banner grabbing, directory brute forcing, vulnerability scans and password attacks
- Countermeasures, detecting attack attempts and security tools for web servers
Hacking Web Applications
- OWASP Top 10 and attacks on web applications
- Mapping web infrastructure and analysing web applications, bypassing client-side controls, attacking access controls and web services
- Web APIs and webhooks, hacking methodology for web APIs, API security risks and solutions
- Security testing and fuzzing of web applications, encoding schemas, countermeasures
SQL Injection
- Types of SQL injection: error-based, union and blind/inferential
- Methodology: gathering information, identifying vulnerabilities, carrying out attacks, advanced SQL injection
- SQL injection tools, SQL injection with AI and evasion techniques
- Countermeasures and detection tools
Hacking Wireless Networks
- WLAN standards, encryption and threats
- Hacking methodology: WLAN discovery, traffic analysis, attacks and cracking WLAN encryption
- Countermeasures and tools for WLAN security audits
Hacking Mobile Platforms
- OWASP Top 10 Mobile Risks, anatomy of mobile attacks and sandboxing issues
- SMiShing, call spoofing, OTP and two-factor hijacking, attacks on camera and microphone
- Android rooting and hacking Android devices, iOS jailbreaking and hacking iOS devices
- Mobile device management, security policies and security tools for mobile devices
IoT and OT Hacking
- IoT architecture, technologies and protocols, OWASP Top 10 IoT Threats
- IoT vulnerabilities, attacks, hacking methodology, and hacking and security tools
- IT/OT convergence (IIoT), OT technologies and protocols
- OT vulnerabilities, threats, attacks, hacking methodology and tools
Cloud Computing
- Cloud, fog and edge computing, containers, Docker, Kubernetes and serverless computing
- OWASP Top 10 Cloud Security Risks, container and Kubernetes vulnerabilities, cloud attacks
- Cloud hacking methodology: AWS, Microsoft Azure, Google Cloud and containers
- Cloud network security, security controls and security tools
Cryptography
- Ciphers, symmetric and asymmetric encryption algorithms, hash functions, quantum cryptography
- Public key infrastructure (PKI), signed certificates and digital signatures
- Email and disk encryption, blockchain
- Cryptanalysis, attacks on cryptography and blockchain, quantum computing attacks