Mastering advanced hacking and IT security techniques
Defending a system effectively requires understanding how to test its weaknesses within an authorised setting. Structure penetration tests, analyse vulnerabilities and make findings actionable. Strengthen your ability to connect technical results with remediation priorities.
- Duration
- 5 days 35 hours
- Code
- HACK-001-FR Code
Presentation
Hacking and IT security techniques are constantly evolving, with attackers and defenders engaged in an ongoing race. Hackers continually explore new vulnerabilities and develop sophisticated tools and increasingly ingenious tactics to compromise information systems. Meanwhile, cybersecurity professionals work to strengthen defences, detect threats proactively and respond effectively to incidents.
This intensive course provides a solid understanding of cybersecurity, covering both offensive and defensive techniques. You will deepen your analysis of cyberattack mechanisms, attackers' tools and best practices for securing information systems. Alongside theory, numerous labs allow you to apply this knowledge and develop operational skills.
Designed for IT and cybersecurity professionals with sound experience in these areas, the course will help you strengthen information systems security, detect and respond effectively to attacks, and address growing cybersecurity challenges.
Objectives
By the end of this cybersecurity course, you will be able to:
- understand cyberattack mechanisms in depth to prevent and respond to them more effectively;
- develop the skills to protect information systems against current and future threats;
- build expertise in advanced offensive and defensive tools;
- optimise security incident detection and response to minimise organisational impacts.
Program
Day 1: introduction to cybersecurity and the Red Team approach
- Cybersecurity overview:
- Defining hacking and cybersecurity and their challenges.
- Overview of current and emerging threats.
- Security references: ANSSI, ENISA, CLUSIF, Cybermalveillance.gouv and others.
- Types of hackers: hacktivists, cybercriminals, insiders and others.
- Types of attacks: phishing, malware, ransomware, denial of service and others.
- Tools and techniques used by hackers: reconnaissance, port scanning, vulnerability exploitation and more.
- The cyberattack life cycle: reconnaissance, exploitation, maintaining access, privilege escalation, data exfiltration and more.
- Establishing a Red Team:
- The offensive approach: simulating real attacks to identify vulnerabilities.
- Reconnaissance and discovery: network scanning, exploring open services and identifying weaknesses.
- Vulnerability exploitation and privilege escalation techniques.
- Establishing a backdoor: information exfiltration, dictionary creation and brute-force attacks.
Day 2: understanding defensive security
- Establishing a Blue Team:
- Proactive cyberattack defence: detection, prevention and response.
- Security pillars: confidentiality, integrity, availability and traceability.
- Implementing defence-in-depth strategies.
- Network and system security: internal networks, VLANs, DMZs, firewalls and more.
- System and application hardening
- Linux and Windows hardening: the process of securing an information system.
- Securing network services: SSH, DHCP, VLANs and more.
- Implementing security measures for critical services: IDS/IPS and log management.
- Monitoring and managing security incidents through SOC and SIEM capabilities.
- Incident response:
- Establishing structured incident response: log analysis and identifying attack traces.
- Using tools such as Wireshark and ELK for intrusion detection.
- Incident management approaches: identification, isolation and remediation.
Day 3: advanced concepts and in-depth hardening
- Advanced security principles:
- How IAAA works: Identification, Authentication, Authorisation and Audit.
- Security principles: need to know, least privilege, non-repudiation and more.
- Securing access to critical systems: privilege management, network segmentation and access control.
- Network infrastructure security:
- OSI Layer 2: VLANs, port security and ARP MITM attack prevention.
- OSI Layer 3: IPsec and router filtering.
- OSI Layer 4: gateways, firewalls and IDS/IPS configuration.
- OSI Layer 5: proxies and outbound communication filtering.
- Security monitoring and management
- Introduction to SOC and SIEM capabilities for threat detection and management.
- Implementing a log management system with ELK.
Day 4: practical labs — AD, Linux and web applications
- Active Directory exploitation:
- How AD architecture works: identity and permission management.
- Active Directory attack techniques: LDAP injection, Kerberos attacks and privilege escalation through pass-the-hash attacks.
- Privilege escalation and manipulation of groups and security policies.
- Linux system exploitation:
- Privilege escalation and exploitation of vulnerable services.
- Backdoor techniques and data exfiltration.
- Hardening and implementing protections.
- Web application exploitation:
- Common attacks: SQL injection, XSS, CSRF and more.
- Using tools such as Burp Suite to exploit vulnerabilities.
- Web application hardening: securing entry points and databases.
Day 5: practical labs — attacks and defences
- Simulating real attacks:
- A complete attack from reconnaissance to data exfiltration.
- Using Red Team tools: Metasploit, Nmap, Burp Suite and others.
- Pivoting and escalation techniques in multicomponent environments: AD, Linux and web applications.
- Incident response and log analysis:
- Collecting and analysing logs across systems and environments.
- Investigation with Wireshark, ELK and Splunk.
- Incident response: identifying actions to contain and eliminate attacks.
- Review and best practices
- Reviewing the main vulnerabilities discovered during labs.
- Security best practices to strengthen system defences.
- Discussion of establishing a sustainable, effective security policy.
Audience
This course is intended for:
- IT security analysts;
- IT security engineers;
- IT security architects;
- IT security consultants;
- developers;
- system and network administrators.
Prerequisites
This course requires the following prerequisites:
- basic network and system knowledge and an understanding of IT security fundamentals;
- initial cybersecurity experience is an advantage but is not mandatory.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
• Theoretical and practical lessons enabling you to apply attack and defence techniques and develop an in-depth understanding of security mechanisms.
• A final assessment based on an attack and response simulation, with personalised support throughout.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en