Get in Touch

Course Outline

Introduction to Ethical Hacking

  • Fundamentals of ethical hacking and information security
  • Cybersecurity threats, vulnerabilities, and attack surfaces
  • Ethical hacking concepts, phases, and methodologies
  • Information security controls and security frameworks
  • Types of hackers, attacks, and attack vectors
  • Legal, regulatory, and ethical considerations
  • Introduction to AI in ethical hacking and cybersecurity
  • Cyber Kill Chain and MITRE ATT&CK concepts

Footprinting and Reconnaissance

  • Fundamentals of reconnaissance
  • Passive and active information gathering
  • Identifying target infrastructure and attack surfaces
  • Search engine reconnaissance
  • WHOIS, DNS, and IP intelligence
  • Website and organizational footprinting
  • Email and social media reconnaissance
  • Cloud and network infrastructure discovery
  • OSINT tools and techniques
  • AI-assisted reconnaissance and information analysis

Scanning Networks

  • Network scanning concepts and methodologies
  • Host discovery and port scanning
  • TCP, UDP, and ICMP scanning
  • Service and operating system identification
  • Banner grabbing
  • Network mapping and topology discovery
  • Vulnerability scanning
  • Firewall and IDS considerations
  • Scanning tools and automation
  • AI-assisted network analysis

Enumeration

  • Enumeration concepts and techniques
  • Windows and Linux enumeration
  • NetBIOS and SMB enumeration
  • SNMP enumeration
  • LDAP and directory services enumeration
  • DNS and SMTP enumeration
  • User, group, and share enumeration
  • Active Directory reconnaissance
  • Enumeration countermeasures
  • Automated enumeration techniques

Vulnerability Analysis

  • Vulnerability assessment methodologies
  • Vulnerability identification and classification
  • CVE, CVSS, and vulnerability databases
  • Network and system vulnerability scanning
  • Web and application vulnerability assessment
  • Cloud and container vulnerability considerations
  • Vulnerability prioritization and risk analysis
  • False positives and validation
  • Vulnerability management lifecycle
  • AI-assisted vulnerability analysis and prioritization

System Hacking

  • System hacking methodology
  • Password attacks and credential attacks
  • Password cracking techniques
  • Authentication and authorization weaknesses
  • Privilege escalation
  • Exploitation fundamentals
  • Maintaining access
  • File and system hiding techniques
  • Covering tracks
  • Windows and Linux post-exploitation
  • AI-assisted exploitation and attack-path analysis

Malware Threats

  • Malware concepts and classifications
  • Viruses, worms, Trojans, ransomware, and spyware
  • Fileless and polymorphic malware
  • Rootkits and backdoors
  • Malware delivery mechanisms
  • Command-and-control concepts
  • Malware analysis fundamentals
  • Anti-malware evasion techniques
  • Malware detection and prevention
  • AI-enabled malware and defensive countermeasures

Sniffing

  • Network sniffing fundamentals
  • Packet capture and traffic analysis
  • Passive and active sniffing
  • Protocol analysis
  • ARP poisoning and MAC attacks
  • DNS and DHCP-based attacks
  • Credential interception
  • Man-in-the-middle concepts
  • Sniffing countermeasures
  • Secure network communication
  • AI-assisted packet and traffic analysis

Social Engineering

  • Social engineering principles
  • Human-based and technical-based attacks
  • Phishing, spear phishing, and whaling
  • Vishing, smishing, and other communication-based attacks
  • Impersonation and pretexting
  • Baiting and physical social engineering
  • Social engineering attack lifecycle
  • Awareness and security testing
  • Detection and prevention strategies
  • AI-generated phishing and social engineering threats

Denial-of-Service

  • DoS and DDoS fundamentals
  • Types of denial-of-service attacks
  • Network and application-layer attacks
  • Resource exhaustion
  • Distributed attack infrastructure
  • Botnets and amplification concepts
  • DDoS detection and monitoring
  • Mitigation and prevention techniques
  • Incident response for DoS attacks
  • AI-assisted attack detection and response

Session Hijacking

  • Session management fundamentals
  • Session identification and authentication
  • Session hijacking techniques
  • Cookie and token-based attacks
  • TCP/IP session hijacking
  • Browser and web session attacks
  • Man-in-the-middle attacks
  • Session fixation
  • Session security controls
  • Detection and mitigation techniques

Evading IDS, Firewalls, and Honeypots

  • Intrusion detection and prevention systems
  • Firewall architectures and technologies
  • Honeypots and deception technologies
  • Network security monitoring
  • IDS/IPS evasion concepts
  • Firewall evasion techniques
  • Traffic fragmentation and obfuscation concepts
  • Proxy and tunneling concepts
  • Honeypot detection and countermeasures
  • Defensive monitoring and hardening
  • AI-assisted anomaly detection and adaptive defense

Hacking Web Servers

  • Web server architecture and technologies
  • Web server footprinting
  • Web server enumeration
  • Common web server vulnerabilities
  • Misconfiguration and insecure defaults
  • Authentication and access-control weaknesses
  • Directory traversal and related attacks
  • Web server attacks and exploitation concepts
  • Web server hardening
  • Patch and configuration management
  • Web server monitoring and incident response

Hacking Web Applications

  • Web application architecture
  • Web application attack surfaces
  • Client-side and server-side vulnerabilities
  • Authentication and authorization attacks
  • Session management vulnerabilities
  • Input validation weaknesses
  • Cross-site scripting
  • Cross-site request forgery
  • File inclusion and upload vulnerabilities
  • API security fundamentals
  • Web application security testing methodologies
  • Secure coding and mitigation techniques
  • AI-assisted web application security testing

SQL Injection

  • Database and SQL fundamentals
  • SQL injection concepts and attack vectors
  • Authentication bypass concepts
  • Error-based, union-based, and blind SQL injection
  • Database fingerprinting
  • Data extraction concepts
  • SQL injection testing methodologies
  • Automated SQL injection assessment
  • SQL injection prevention
  • Parameterized queries and input validation
  • Database security monitoring
  • AI-assisted SQL injection detection and analysis

Hacking Wireless Networks

  • Wireless networking fundamentals
  • Wi-Fi standards and security protocols
  • Wireless reconnaissance
  • Wireless network discovery
  • Authentication and encryption weaknesses
  • Wireless traffic analysis
  • Rogue access points and evil-twin concepts
  • Wireless denial-of-service concepts
  • Bluetooth security fundamentals
  • Wireless security testing methodologies
  • Wireless hardening and monitoring
  • Secure wireless configuration

Hacking Mobile Platforms

  • Mobile security architecture
  • Android and iOS security concepts
  • Mobile application attack surfaces
  • Mobile application reconnaissance
  • Insecure data storage
  • Authentication and authorization weaknesses
  • Mobile communication security
  • API and backend security
  • Mobile malware
  • Mobile application security testing
  • Mobile device security controls
  • Mobile application hardening

IoT and OT Hacking

  • IoT and OT security fundamentals
  • IoT architecture and communication protocols
  • IoT device discovery and reconnaissance
  • IoT vulnerabilities and misconfigurations
  • Firmware and hardware security concepts
  • IoT authentication and access control
  • Industrial Control Systems and OT environments
  • SCADA security fundamentals
  • OT attack surfaces and risks
  • IoT/OT vulnerability assessment
  • Defensive monitoring and segmentation
  • Secure IoT and OT architecture
  • AI-enabled IoT and OT security considerations

Cloud Computing

  • Cloud computing fundamentals
  • Cloud service models and deployment models
  • Cloud architecture and shared responsibility
  • Cloud reconnaissance and attack surfaces
  • Identity and access management
  • Cloud storage and database security
  • Virtualization and container security
  • Cloud misconfigurations
  • Cloud network security
  • Cloud privilege escalation concepts
  • Cloud vulnerability assessment
  • Cloud logging and monitoring
  • Cloud incident response
  • AI-assisted cloud security analysis

Cryptography

  • Cryptography fundamentals and terminology
  • Symmetric and asymmetric encryption
  • Hashing and message integrity
  • Digital signatures and certificates
  • Public Key Infrastructure
  • Key management and cryptographic protocols
  • Common cryptographic vulnerabilities
  • Password hashing and secure authentication
  • SSL/TLS security concepts
  • Cryptographic attacks and weaknesses
  • Encryption implementation best practices
  • Cryptography in cloud, mobile, and IoT environments
  • Emerging cryptographic and AI-related security considerations

Requirements

What is new in CEH version 13?

  • AI-powered - The world’s first ethical hacking certification to harness the power of AI.
  • Hands-on experience - Hone your skills in real-world scenarios through hands-on labs, where you practice attack vectors and master advanced hacking tools.
  • More efficiency - Learn AI-driven techniques to boost efficiency by 40% in cyber defense and streamline your workflow.
  • Power-packed, updated curriculum - Master the latest advanced attack techniques, trends, and countermeasures.
  • 2x productivity gains - Advanced Threat Detection, Enhanced Decision Making, Adaptive Learning, Enhanced Reporting, and Automation of Repetitive Tasks.
  • Real-world skills, proven mastery - Participate in monthly global hacking competitions, compete with your peers, and make it to the leaderboard.

Prerequisites

  • An understanding of Windows and Linux operating systems
  • Basic experience with cybersecurity and IT

Audience

  • Mid-Level Information Security Auditor
  • Cybersecurity Auditor
  • Security Administrator
  • IT Security Administrator
  • Information Security Analyst 1
  • Infosec Security Administrator
  • Cybersecurity Analyst level 1, level 2, & level 3
  • Network Security Engineer
  • SOC Security Analyst
  • Network Engineer
  • Senior Security Consultant
  • Information Security Manager
  • Senior SOC Analyst
  • Solution Architect
  • Cybersecurity Consultant
  • Cyber Defense Analyst
  • Vulnerability Assessment Analyst
  • Warning Analyst
  • All-Source Analyst
  • Cyber Defense Incident Responder
  • Research & Development Specialist
  • Senior Cloud Security Analyst
  • Third Party Risk Management
  • Threat Hunting Analyst
  • Penetration tester
  • Cyber Delivery Manager
  • Application Security Risk
  • Threat Modelling Specialist
  • Web Application Penetration Testing
  • SAP Vulnerability Management - Solution Delivery Advisor
  • Ethical Hacker
  • SIEM Threat Responder
  • Product Security Engineer / Manager
  • Endpoint Security Engineer
  • Cybersecurity Instructor
  • Red Team Specialist
  • Data Protection & Privacy Officer
  • SOAR Engineer
  • AI Security Engineer
  • Sr. IAM Engineer
  • PCI Security Advisor
  • Exploitation Analyst (EA)
  • Zero Trust Solutions Engineer / Analyst
  • Cryptographic Engineer
  • AI/ML Security Engineer
  • Machine Learning Security Specialist
  • AI Penetration Tester
  • AI/ML Security Consultant
  • Crypto Security Consultant
 35 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories