Penetration Testing and Ethical Hacking in WANs (HCK2)

Cybersecurity, ICT Security

This practical course presents a structured method for penetration testing of WAN infrastructures, stressing realistic attack scenarios and intensive hands-on labs. Participants learn to map remote networks, identify and validate vulnerabilities, and plan safe tests on Windows and Linux.

The course trains use of security distributions like Kali Linux and professional Metasploit workflows for exploitation and privilege escalation. You will practice IDS/firewall evasion, VPN and DoS testing, shellcode handling and post forensic analysis.

THIS TRAINING COURSE WILL HELP YOU:

  • Learn WAN reconnaissance and target identification techniques.
  • Use Kali Linux for practical testing and security tools.
  • Identify vulnerabilities with scanners and public CVE data.
  • Apply Metasploit for exploitation and privilege escalation.
  • Perform IDS/firewall evasion, VPN and DoS testing, and forensics.

WHO SHOULD ATTEND?

  • Network and system administrators (Windows and Linux)
  • Penetration testers and security consultants
  • DevOps engineers and WAN administrators
  • Security analysts and SOC team members
  • Developers responsible for securing network applications

COURSE LOCATION AND AVAILABLE DATES



Choose whether to attend in person in our classroom or join online. You can select your preferred format during registration. Learn more about hybrid training.

Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.

For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.

Request training in English

Course content:

Hide details
  • Reconnaissance of targets on the Internet
    1. Discovering the target's online presence
    2. Determining the target's IP ranges
  • Offensive tools for Linux and Windows
    1. Basics of inventory and using network-layer scanners
    2. Overview of different scanner types
    3. Using scanners for higher-layer reconnaissance – amap, dsniff
  • Tracing the route to a target and scouting firewalls using firewallking
    1. Detection techniques
  • Standard and specialized scanners
    1. Using them to scan services
    2. Inventory options via higher-layer protocols (LDAP, SNMP, etc.)
  • Discovering vulnerabilities of WAN targets
    1. Using independent vulnerability and weakness databases
  • Using discovered vulnerabilities to gain and escalate privileges on remote systems
    1. Using Metasploit in a WAN context
    2. Modifying shellcode to bypass intrusion detection
    3. Privilege escalation options and demonstrating remote system control
  • Automating penetration tests with Metasploit
  • Basics of writing shellcode, types and establishing connections to targets
    1. Demonstration of shellcode usage
    2. Kernel and memory manipulation by malicious code and rootkits
    3. Practical removal of shellcode from an OS
  • Description of attacks at the network layer
    1. Attack forms against protocols and services such as DNS, HTTP and others
    2. Direct attack possibilities on network devices, primarily Cisco IOS
  • Use of stack-overflow techniques
    1. Demonstrations of DoS attacks on various protocols and services
    2. Ensuring response to unusual network activity
    3. Examples of monitoring and detection tools
  • Bypassing firewalls, IDS and honeypots
    1. Logging options for standard and non-standard activity
  • Demonstrations of attacks on web and proxy servers
    1. Security review of MS IIS web server
    2. Exploiting servers via dynamic code – ActiveX
    3. Implementation flaws in the Java Virtual Machine
    4. Browser weaknesses
  • Reconnaissance of VPN services on remote systems and potential VPN attacks
    1. Defenses using encryption – SSL, IPSec and other techniques
  • Actions after confirming a system compromise
    1. Tracing attacker activity
    2. Hiding traces of illegal activity
    3. Capabilities of standard security audit tools
Prerequisites:
Experience with Windows and Linux; basic understanding of TCP/IP network security.
Recommended previous course:
Penetration Testing and Ethical Hacking (HCK1)
Schedule:
3 days (9:00-17:00)
Price per person:
756.00 € ( 914.76 € incl. 21% VAT)

Training and learning environment