
Explore real world ethical hacking through four modules, more than 40 hands-on labs, and thousands of techniques in OSINT, network and client penetration testing with Maltego.
Learn essential terms of ethical hacking, including penetration testing, red team, blue team, purple team, adversary immolation, threat, and risk, and how these concepts guide security testing and remediation.
Explore the MITRE ATT&CK framework and attack navigator. Map tactics, techniques, and procedures to defense strategies, detections, and threat intelligence.
Explore the Detect methodology to inventory data sources, score data quality and visibility, and map detections to minor attack techniques, producing a navigator layer to visualize blue team defense gaps.
Explore the atomic purple team framework combining red and blue tactics to strengthen security in a six-step lifecycle: risk assessment, planning, attack execution, detection, optimization, and report.
Leverage the Tahiti threat hunting methodology to combine threat intelligence with proactive hunting, using unstructured and structured approaches to reveal attacker tactics, techniques, and procedures across a three-phase, six-step process.
Explore OSINT for ethical hacking and apply the four-stage OSINT cycle—requirements gathering, data retrieval, analysis, and reporting—to evaluate public data across media, text, and geolocation for offensive security.
Explore search engines for osint, comparing Google, DuckDuckGo, Yandex, and Bing; master dorking with operators title, in title, URL, file type, and cache, and use carrot to cluster results.
Practice searching the dark web using Tor, VPN, and a secured virtual machine, with DuckDuckGo and onion domains to identify safe, encrypted websites.
Explore how an open source search and results clustering engine automatically groups documents by topic, using algorithms like lingo, tse, and k-means, with a configurable workbench and data sources.
Explore the whois protocol for osint researchers, learn to retrieve domain registration details, registrant contacts, and historical data using online tools and reverse whois techniques.
Master practical reverse lookup methods, including reverse IP, reverse whois, and DNS report, then assess server security by examining HTTP headers and DNS security tests.
Learn to set up and run SpiderFoot for automated web information gathering, configure scans with multiple modules, monitor DNS and whois data, and export scan results as JSON.
Learn about ssid, mac address, and beacons that identify and connect to wifi networks. Practice wigle osint to locate networks by location, mac, or network name and export data.
Explore email osint techniques with recon-ng to identify target emails, build permutations, and validate addresses for social engineering and phishing campaigns, using osint frameworks and hunter io module.
Practice Twitter search techniques using advanced operators, hashtags, and account filters to explore topic trends, engagement, and location-based insights with real-world tools.
Maltego enables data mining for osint and forensics, revealing relationships among people, websites, and documents. It covers transforms, transform servers, TDS, and installing the community edition for practical lab use.
Learn to use maltego for website analysis by creating a new project, applying transforms to domain and website entities, attaching files, and adjusting layouts to reveal related sites.
Explore how to document ethical hacking findings by exporting analysis data into formats such as HTML or CSV, and craft customizable reports with target information, social accounts, and customer-focused solutions.
Explore layer two attacks on Cisco switches, including CDP reconnaissance, ARP spoofing, VLAN hopping, STP attacks, and password vulnerabilities; simulate IP reconnaissance and flooding attacks with Yersinia in hands-on lab.
Practice the cam table overflow attack in a lab using the Markov tool, running the pseudo markov command, and observe the mac address table on the switch.
Practice an arp spoofing attack using the arp spoof tool and sniff to position between the ftp server and client, enabling ip forwarding to capture usernames and passwords.
Execute a switch spoofing attack using Yersinia -G, launch from the Fitbit app, send HTTP packets, and observe mode changes to trunking and dynamic auto.
Explore a lab on STP attack techniques using Yersinia to claim root role, become the root bridge, and observe spanning tree status, cost, and forwarding behavior.
Engage in hands-on Cisco password decryption attacks, decrypting password types with keychain and running-config methods, and using Cisco power decrypt to reveal type five passwords with proper escaping.
Examine layer 3 attacks, including DHCP starvation and IP spoofing, and explore routing protocol exploits (RIP, OSPF, HRP) to understand potential man-in-the-middle and DDoS risks.
Learn how log spoofing creates fake syslog entries to mislead forensic investigations, and practice sending spoofed logs from routers using python-based tools in a hands-on lab.
Learn to replicate a log ddos attack using a python script to send many spoofed syslog messages, employing multithreading and loops to simulate packet bursts and test defense capabilities.
Explore dns attacks, including dns spoofing, dns cache poisoning, and dns reflection and amplification, revealing how attackers redirect traffic to fake sites and exploit udp weaknesses in a lab.
Learn firewall penetration testing across five firewall types, from packet filtering to next generation firewalls, and apply traffic analysis, tunneling, and ssl decryption to identify risks.
Explore the Metasploit framework, covering server-side, client-side, and local privilege escalation exploits, its core modules—exploits, payloads, auxiliary, and post—plus tools like MSF console and Armitage.
Explore client-side exploitation and privilege escalation through a hands-on lab using MSF venom in metasploit to create a trojan, upload it, and establish a reverse connection for system access.
Practice post-exploitation sniffing using a sniffer extension to load, start, and dump captures, view stats, and analyze with Wireshark to reveal sensitive information like usernames and passwords.
Practice host-based DNS poisoning by editing the hosts file to map a website to a chosen IP within a lab, and run the lab exploit.
After you completed this course, python for Red-Blue Teams course is the next step to become an expert in Ethical Hacking.
Welcome to this comprehensive Ethical Hacking course...!
This course assumes you have prior Networking knowledge. This course is practical but it won't neglect the theory. You'll learn everything Practically by exploiting everything such as Network Infrastructure Devices (Switch & Router) and Client (Windows 10) and you will never waste your time theoretical lectures
This course is divided into 4 main sections
1- MITRE Frameworks
In this Section, you will Learn MITRE Frameworks Such as :
MITRE ATT&CK Framework and how it really works and how to use MITRE ATT&CK Navigator.
You will learn DETT&CT Framework for Blue Teams and Investigators and how to use it
you will learn Threat Hunting Methodology (TaHiTI) for Threat Hunting, and how it works and introduction to MaGMa Use Case (UCS) Framework.
and I will introduce MITRE Cyber Analytics Repository (CAR) Framework, MITRE D3FEND Framework, MITRE ENGENUITY Framework, MITRE Engage Framework, and MITRE RE&CT Framework.
2- Open-source intelligence (OSINT)
This Section is ideal for Ethical Hackers, Investigators and Researchers
You will learn Search Engines, Dark Web For OSINT
You will learn Search Engine Clustering
You will Learn Whois and Reverse Whois
You will learn Spiderfoot for Website Analysis.
You will learn DNS Records and DNS Analysis Tools
You will learn Wireless OSINT
You will learn Email OSINT with Tools such as Recon-ng and Websites
You will learn People OSINT
You will learn Image OSINT Techniques such as Reverse Image Search
You will learn OCR Technology for Image OSINT
You will learn Sock Puppet for Social Networks
You will learn Social Networks OSINT such as Twitter and Facebook
You will learn Maltego and how it works.
You will learn Maltego Basics
You will learn Website analysis with Maltego
You will learn Footprint Machine Levels with maltego
You will learn documentation and see document template
3- Network Penetration Testing
in This section, You will learn Layer 2 Attacks such as :
CDP/LLDP Recon and CDP Flooding
CAM Table Overflow Attack
ARP Spoofing Attack
Vlan Hopping Attack (Switch Spoofing)
Vlan Hopping Attack (Double Tagging)
Spanning-Tree Protocol (STP) Attack
You will learn Layer 3 Attacks such as :
Cisco Password Decryption Attacks (Type 5 & Type 7)
DHCP Starvation Attack
FHRP Protocol Attacks (HSRP Attack)
You will learn Monitoring Attacks such as :
Log Spoofing Attack
Log DDoS Attack
you will learn DNS Attacks such as :
DNS Spoofing Attack
DNS Amplification Attack
Firewall Pentesting Steps
4- Client Penetration Testing
You will learn Metasploit Framework Components
You will learn Server-Side Exploitation using Metasploit
You will learn Client-Side Exploitation using Metasploit
You will learn Privilege Escalation using Bypass User Access Control (UAC)
You will learn Post-Exploitation Attacks such as Remote Sniffing
You will learn Post-Exploitation Attacks such as Host-Based DNS Poisoning
All the techniques in this comprehensive course are highly practical and at the end of this course, expected you to become an expert in Ethical Hacking
Notes :
This course is created for educational purposes only. all the attacks are launched in my own lab. This course is a product of Hamed Mehdi and no other organization is associated with it or a certification exam but you will receive a Course Completion Certification from Udemy