Penetration Testing and Ethical Hacking (HCK1)

Cybersecurity, ICT Security

This course is aimed at Windows and Linux administrators and teaches core hacking tools and techniques for security testing. Through hands-on labs you will learn to operate common tools and workflows and use Kali Linux for system checks.

The training shows practical LAN attacks and compromises of local Windows clients, combined with network analysis and defensive checks. It teaches methods to audit systems ethically, reproduce attacks safely, and validate fixes on your own infrastructure.

THIS TRAINING COURSE WILL HELP YOU:

  • Identify and assess common security threats
  • Gain hands-on experience with hacking tools
  • Understand core concepts of cybersecurity

WHO SHOULD ATTEND?

  • IT technicians and support staff
  • Server and system administrators
  • Software developers and security engineers

COURSE LOCATION AND AVAILABLE DATES



Choose whether to attend in person in our classroom or join online. You can select your preferred format during registration. Learn more about hybrid training.

Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.

For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.

Request training in English

Course content:

Hide details
  • Basic Windows commands for users, processes, network, services and registry
    1. Traffic analysis using netstat and its parameters
    2. Description of configuration files and registries for network services
  • Basics of Wireshark and Network Monitor on Windows
    1. Analysis of TCP, UDP and IP protocols
    2. Capturing passwords on the network
    3. Link-layer protocol analysis, e.g. CDP
    4. Client-server model in networks
    5. Capture and analysis of ARP, HTTP, FTP, DNS, DHCP, RDP, IPSec, Skype and more
    6. Using filters in Wireshark
    7. Basic Unix commands for network tasks
    8. Example of sniffing on Linux
    9. Changing MAC address in Windows
  • Introduction to ethical hacking
    1. Types of attackers and their motivation
    2. Methods for gathering information about targets
    3. Hacker tools for Linux and Windows
    4. Basics of inventory and use of network-layer scanners
    5. Demonstration of various scanners and inspecting higher layers
    6. NetBIOS scanning
  • Specialized scanners and web server checks
    1. Detecting sniffers with specialized tools
    2. Using independent vulnerability databases
    3. Inventorying via higher-layer protocols like LDAP, SNMP and others
  • Basics of viruses, classification and removal with practical demo
    1. Use of Sysinternals tools
    2. Detecting and removing infections with antivirus tools
    3. Kernel and memory manipulation by malware and rootkits
    4. Introduction to rootkits and removal methods
    5. Use of trojans to control a system
    6. Practical trojan removal from an OS
  • Attacks on the network layer
    1. Password capture and a "Man in the Middle" demonstration
    2. Using ettercap to capture passwords
    3. Attacks on protocols and services such as DNS, ARP, HTTP and more
    4. Direct attacks on network devices
    5. Demonstrations of DoS and MAC table exhaustion attacks
  • Bypassing firewalls, IDS and honeypots
    1. Logging of normal and unusual activity
    2. Ensuring response to unusual network behavior
    3. Demonstration of monitoring and detection tools
    4. Attacks on web and proxy servers
    5. Attacks targeting IPv6
    6. Security checks for Microsoft IIS web server
  • Protecting remote access with VPNs and potential attacks
    1. Privilege escalation on remote systems and remote takeover demo
    2. Defenses using encryption such as SSL, IPSec and related techniques
  • Actions after discovering a compromised computer
    1. Tracing attacker activity
    2. Hiding traces of illegal activity
    3. Using standard security audit tools and procedures
Prerequisites:
Basic experience with Windows and Linux and a basic understanding of TCP/IP security.
Recommended previous course:
Basics of the TCP/IP Protocol (TCP1)
Recommended follow-up course:
Penetration Testing and Ethical Hacking in WANs (HCK2)
Schedule:
3 days (9:00-17:00)
Price per person:
752.00 € ( 909.92 € incl. 21% VAT)

Training and learning environment