The training content is divided into the following modules:
- Module 1: Penetration test and typology of tools (8h) Select the different strategies and operation of the tools available in the execution of an intrusion test.
- Module 2: Penetration testing methodologies (20h) Compare the techniques and practical recommendations of relevant international organizations for carrying out penetration tests.
- Module 3: Tools for executing penetration tests (18h) Select tools and procedures for exploiting vulnerabilities in applications and software platforms, both to prepare intrusion (penetration) tests and to detect the efficiency of existing protection mechanisms.
- Module 4: Results and reports (6h) Prepare reports based on the analyses carried out, clearly specifying the results and recommendations obtained.
- Module 5: Planning and executing a penetration test (8h) Apply techniques and tools in the planning and development of a real penetration test.
Module 1. Penetration testing and typology of tools
This 8-hour module aims to select the different strategies and operation of the tools available in the execution of an intrusion test. Specifically, in this module the following knowledge will be acquired:
Distinction between penetration testing and auditing:
- Goals
- Differentiating elements
Classification of the typology according to the information we have:
- White box
- Black box
- Gray box
Classification of the typology based on the services to be tested:
- Network Penetration Testing
- Wireless network penetration testing
- Systems penetration testing
- Web application penetration testing
- Social engineering penetration test
Module 2. Penetration testing methodologies
This 20-hour module aims to compare the techniques and practical recommendations of relevant international organizations for conducting penetration tests. Specifically, in this module the following knowledge will be acquired:
Description of the phases of a penetration test:
- Planning the test
- Test analysis
- Reports with test results
Definition of concepts:
- Scope of the test
- Attack vector
OSSTMM classification (Open Source Security Testing Methodology Manual):
- Physical security
- Process security
- Security in Internet technologies
- Security in communications
- Wireless security
- Information security
- RAV (Risk assessment value)
OWASP (Open Web Applications Security Project) classification:
- Configuration and deployment management testing
- Identity management tests
- Authentication test
- Authorization test
- Session management test
- Input validation test
- Error handling test
- Weak cryptography test
- Business logic tests
- Client-side testing
- API testing
Differentiation between OSSTMM and OWASP
Module 3: Tools for executing penetration tests
This 18-hour module aims to select the tools and procedures for exploiting vulnerabilities in applications and software platforms, both to prepare intrusion (penetration) tests and to detect the efficiency of existing protection mechanisms. Specifically, in this module the following knowledge will be acquired:
Classification of generic tools:
- Burp Suite
- OpenVAS
- Nessus
- Metasploit
- Kali Linux
Classification of network tools:
- Nmap
- Aircrack-ng
- Wireshark
- zmap
- Ettercap
Classification of password theft tools:
- Hydra
- John the Ripper
- Hashcat
Module 4: Results and reports
This 6-hour module aims to prepare reports based on the analyses carried out, clearly specifying the results and recommendations obtained. Specifically, in this module the following knowledge will be acquired:
Description of documentation support tools:
Report preparation:
- Evaluation and analysis of results
- Specification of tests performed
- Technical results
- Recommendations
Definition of record retention policies:
- Granularity and durability of recorded data depending on sources and relevance
- Regulatory and contractual requirements
Module 5: Planning and executing a penetration test
This 8-hour module aims to apply techniques and tools in the planning and development of a real penetration test. Specifically, in this module the following knowledge will be acquired:
Selection of the most appropriate methodology to carry out a penetration test:
- Define scope
- Determine attack vectors
- Planning to carry it out
Selection of the type of penetration test to determine the exploitability of vulnerabilities:
- Determine the test based on scope
- Running the selected test
- Obtaining results
Preparation of the penetration test report:
- Collection and organization of information
- Report writing