Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Modern Ethical Hacking - Complete Course
Rating: 4.5 out of 5(144 ratings)
1,844 students

Modern Ethical Hacking - Complete Course

Become a Competent Red Teamer or Penetration Tester with Step-By-Step Guidance over Bite-Sized Lectures
Created byVonnie Hudson
Last updated 11/2022
English

What you'll learn

  • Modern Offensive Operational Hacking Techniques
  • How to build a World Class Cyber Range to Practice Attacks and Defense
  • Attacker Tradecraft against modern Active Directory environments
  • End to end hacking hacking from Initial Access to Action on Objectives (mapped to MITRE ATT&CK)
  • New Bug Bounty reconnaissance techniques being used on HackerOne and BugCrowd
  • Blue Team strategies for detecting and blocking Red Team aggressors.
  • How to EASILY write an awesome Penetration Testing report (and WOW your Managers)
  • Practical steps for getting a job in Cyber Security!

Course content

11 sections110 lectures15h 9m total length
  • The Big Picture4:33

    Welcome to Modern Ethical Hacking! In this quick introduction video I'm going to give you the big picture of the course and set the stage for some of the awesome things you'll be doing as we go through this cyber journey together!

  • First! Two Frequently Asked Questions!5:04

    Before we jump in - I've got to read your mind and shine some light on two questions you probably have lurking in the back of your mind.  Let's quickly address these concerns before we move on shall we!?

  • Helpful Resources5:27

    I created a helpful Github resource which complements the material in your course.  In this lecture I'm going to walk through that resource with you so you can get the maximum value possible! 

  • My Story4:37

    What's it REALLY like being a Penetration Tester\Red Teamer?  Let me share my story.  I want to tell you how I got into this field so you'll know how you can break in as well.  In addition, it's always good to have the backstory on how the author got to where he was - I'm not some super smart guy - I'm just an ordinary dude with loads of curiosity and a passion to be the best Cybersecurity Professional I can be!  Let's jump in.

  • Methodology: MITRE ATT&CK9:48

    So do you really want to be a professional Ethical Hacker?  Do you really want to get paid to Pen Test or Red Team an organization to help fortify their defensive posture?  Okay, then you need to know how to speak MITRE ATT&CK! In this lecture I'm going to break down the MITRE mystery and arm you with the skills you need to wow and win!

  • Methodology: MITRE Shield3:22

    MITRE Shield is the lesser known, newer, but equally important half of MITRE ATT&CK.  Shield is all about Active Defense.  If you don't know what that is - come on in and get a quick 4 minute rundown.  You're about to get the edge up on the competition - especially if you're interviewing for a cyber job!  Think of this lecture like the sprinkles on your ice cream cone.  Let's go!

  • Methodology: OWASP Top 105:25

    Ahh the OWASP Top 10.  Injection, XXE, XSS all the good stuff I've come to love about Web Application Penetration Testing!  This is where the fun lives guys.  When you master these methodologies: MITRE + OWASP = You_Are_Incredibly_Valuable_To_An_Employer;  So that's what's up.  In this lecture you're going to get a nice taste of OWASP and then in the coming lectures you'll have the freedom to practice the theory in the safety of your lab!  It's going to be a wild ride guys and we are just getting started!  Let's do this!!

  • Taking Notes + Staying Organized7:05

    It's important to stay organized when conducting a pentest engagement or red team exercise.  I know documentation is boring but  - to be honest with you guys - this is where the real value shows up.  Your report is really all the client cares about so if it sucks... well it doesn't matter that you used Unicorn to evade their CrowdStrike Falcon EDR or that you used Cobalt Strike's Beacon Object Files to fool the target organization's SOC.  The bottom line is all that technical leetspeak is nothing without a well documented, meaningful report - and that's why I wanted to take a few moments to show you my favorite way for taking notes while I work!  Don't worry this lecture is going to be quick.  Let's jump in!

Requirements

  • A HacktheBox VIP subscription is recommended (but not required because you can still follow along)
  • 16GB of RAM is recommended for our Active Directory lab environment; although, 32GB is ideal.

Description

New Summer/Fall 2021 Launch!

Did you know some estimates are showing there is a 3 million shortfall in Cyber Security talent in 2020?

Isn't that crazy?

This means this fields is thirsty for competent cybersecurity professionals who can help organizations fortify their critical infrastructure, eradicate adversaries from their networks and emulate the most advanced threat actors in the world to help protect companies from compromise.

It feels like hacking is always in the news, glamorized on TV but often misunderstood.  So in this course you will learn hacking from A-Z - from the ground up.

Nothing is missing.

All attacks are mapped to the latest industry standard frameworks such as the OWASP Top 10 and the MITRE ATT&CK Enterprise Matrix.   And all techniques are currently being used by real world black hat attackers.  By the end of this course you will know how to protect any organization with an internet presence from a thinking and adaptive adversary using the latest tools, techniques and procedures.

This is a full scope course - meaning it covers everything from recon to action on objectives... breach to impact... it's all here.

Scroll down and take a look at the lectures and tell me if it's not getting you excited!! 

For example, in the Cyber Range section you can see you will build a world-class range featuring fully intrumented Windows 10 Endpoints with Windows Defender for Endpoint EDR, Sysmon, and the Splunk Universal Forwarder!  You'll  also notice we are using a dockerized OWASP Juice Shop container with logs being shipped from the Docker container into Splunk Enterprise.  And we're using OPNSense as our Firewall with Suricata signatures and the ET PRO ProofPoint ruleset!  We've even got enterprise email setup so you can spearphish victims in your Active Directory lab!  You'll learn how to setup an internal DNS resolver, configure Windows Server 2019 DHCP services and even push out policies via Active Directory GPO!  And it gets even better than that - I'm just sharing the tip of the iceberg as new lectures are currently being released weekly.

Let's get started!

Oh and one more thing: the best part is you will be being a hands-on lab that is completely isolated from the internet and will afford you the best opportunity to learn real world attacks through experimentation.  This is truly the best way to learn and since it's your lab you'll have access to it forever.... it isn't limited by cloud costs or monthly limitations! 

Let's do this!

Who this course is for:

  • ANYONE with a passion for Cyber Security
  • Help Desk Analysts
  • Network Engineers
  • System Administrators
  • SOC Analysts
  • Penetration Testers
  • Red Teamers
  • Bug Bounty Hunters
  • Cyber Threat Hunters
  • Cyber Security Managers (who want to keep their tech skills sharp!)