Seminare
Seminare

Junior Penetration Tester (IHK) - Online (English)

Webinar - Weiterbildungsgesellschaft der IHK Bonn/Rhein-Sieg gGmbH

The certificate course Junior Penetration Tester imparts the craft of detecting and controlled exploitation of security vulnerabilities within a network. Such a penetration test forms the basis for fortifying an IT infrastructure against hacking attacks.

In addition to financially motivated black hat hackers, politically motivated individuals or groups are playing an increasingly significant role. The damages from a single attack can be immense.

The key is to be prepared for this scenario and prevent greater damages. A penetration test subjects the entire IT infrastructure of a client to a comprehensive examination of its security. This includes technical aspects as well as organisational, physical, and the human factor. The goal is to identify vulnerabilities, uncover sources of errors, and ultimately enhance security comprehensively.
Termin Ort Preis*
07.10.2024- 15.10.2024 online 3.495,00 €
*Alle Preise verstehen sich inkl. MwSt.

Detaillierte Informationen zum Seminar

Inhalte:
Graduates of the Junior Penetration Tester certificate course receive specialised training in the field of IT security: the practical ability to investigate IT infrastructural vulnerabilities within a company. A Junior Penetration Tester can take on supporting activities within a penetration test. This is achieved through practical instruction and the independent application of the learning content.
The participant masters the standard procedures of a penetration test. They learn about legal foundations, standards, and a selection of different career paths, and can name and categorise them as needed. They are capable of independently conducting superficial reconnaissance and identifying obvious vulnerabilities. Additionally, the participant is taught the basics of exploiting vulnerabilities to gain a foothold. The participant is familiar with the differences between exploit frameworks and manual approaches, their advantages and disadvantages, as well as troubleshooting non-functional exploits. They learn various types of privilege escalation and lateral movement and can apply them under guidance. The participant can appropriately prepare and document discovered vulnerabilities in a target audience-oriented manner.



Course content




1. Foundations and Frameworks

- Security goals, pillars of IT security
- Types of hackers
- Laws and regulations, critical infrastructure (KRITIS)
- Standards and methods
- Career paths & IT security professions
- Relevant certifications, further education opportunities, training labs
- Project management (Waterfall vs. Agile)
- Red Teaming vs. Pentesting vs. Vulnerability Analysis
- CTF vs. Pentesting
- Phases of an attack/Kill Chain, Lockheed Martin, PTES, MITRE, etc.

2. Structure and Process of a Penetration Test

- Phases/Process of a penetration test
- Objective and results of a penetration test
- Documentation of vulnerabilities
- Planning/Initiation of a penetration test
- Risks and common mistakes (from practice to practice)
- Scoping
- Result presentations for IT & Management

3. Conducting a Penetration Test

- KickOff
- Information Gathering/ Active /Passive Reconnaissance
- Fundamentals of countermeasures (FW, IDS, IPS, WAF, EPP, Logging, SIEM) & Security Operations (SOC, CERT, Blue Team, etc.)
- Vulnerability Analysis and Vulnerability Classification (CVE, CVSS, Exploitability, and Criticality)
- Dealing with 0-Days Disclosure Types (Responsible, Full)
- Exploitation/Low Hanging Fruits (Common Attack Paths like SQL/Command Injection, Basic Buffer-Overflow, Misconfigurations, etc.)
- Post Exploitation Basic Privilege Escalation Looting, Persistence, and Lateral Movement/ Low Hanging Fruits
- Differences On-Premise vs. Cloud
- Mobile & Web Application Pentesting Basics


Participants have access to a specially developed virtual E-LAB during the event and the exam, through which the course contents are taught and tested. The practical implementation of various attack techniques takes centre stage.



Video Introduction to the Course: https://youtu.be/VoEt4msIjC0

The course is carried out in cooperation with the IT-Security Company ProSec GmbH . The company offers premium IT security services, penetration testing, as well as security consulting and actively conducts zero-day research.
Lehrgangsverlauf/Methoden:
Zertifikatslehrgang
Zielgruppe:
The course is aimed at trained IT personnel who want to establish themselves in the field of penetration testing as well as system administrators or people who deal with IT security in a company (e.g. CISO, ITSB) in order to apply the knowledge they have learned to their own IT infrastructure to apply.
Seminarkennung:
ihkbonnrheinsieg_weiterbildungsgesellschaft_6331
Nach unten
Nach oben
Wir setzen Analyse-Cookies ein, um Ihre Zufriedenheit bei der Nutzung unserer Webseite zu verbessern. Diese Cookies werden nicht automatisiert gesetzt. Wenn Sie mit dem Einsatz dieser Cookies einverstanden sind, klicken Sie bitte auf Akzeptieren. Weitere Informationen finden Sie hier.
Akzeptieren Nicht akzeptieren









Um Spam abzuwehren, geben Sie bitte die Buchstaben auf dem Bild in das Textfeld ein:

captcha



Bei der Verarbeitung Ihrer personenbezogenen Daten im Zusammenhang mit der Kontaktfunktion beachten wir die gesetzlichen Bestimmungen. Unsere ausführlichen Datenschutzinformationen finden Sie hier. Bei der Kontakt-Funktion erhobene Daten werden nur an den jeweiligen Anbieter weitergeleitet und sind nötig, damit der Anbieter auf Ihr Anliegen reagieren kann.







Um Spam abzuwehren, geben Sie bitte die Buchstaben auf dem Bild in das Textfeld ein:

captcha