
Just a brief "hello" and explanation for you.
In this module, you will learn about building a cyber range, a simulated network environment used for training and testing cybersecurity skills and strategies.
This module covers the use of multiple layers and switches in networking, including their functions and benefits.
In this module, you will learn how to customize and configure IP addresses on different devices, including the importance and benefits of doing so.
Discover how to acquire and build test machines from ISO-based installs or prebuilt VMs, using networks and sources like Archaeopteryx and Vorlon hub.
In this module, you will learn about building an advanced cyber range, including the use of more advanced features and technologies for training and testing cybersecurity skills and strategies.
This 60-minute activity will help you build and configure your own cyber range using the concepts from Section 1.
This module covers the process of penetration testing, including the steps and tools involved in identifying and assessing vulnerabilities in a network or system.
This 60-minute activity helps you apply the full lifecycle of penetration testing, including planning, scoping, risk evaluation, and legal considerations.
In this module, you will learn about the abstract methodology, a systematic approach to problem-solving that involves defining and analyzing a problem, generating potential solutions, and selecting and implementing the best solution.
Plan a penetration test by defining scope and boundaries, simulate a medium-skill threat with manual and tool-based testing, and perform nonintrusive target searches using public records, Google hacking, and Shodan.
This module covers the intrusive target search and scanning methodology, including the steps and tools used to identify and assess vulnerabilities in a network or system.
In this module, you will learn about network mapping and the use of the Nmap tool to discover and map networks, including its features and commands.
This module covers the concept of open ports, including how to identify and interpret them and their potential vulnerabilities.
In this module, you will learn about the services that run on ports and how to identify and interpret them for security purposes.
This module covers the concept of enumeration, including the techniques and tools used to gather information about a network or system for security purposes.
This 60-minute activity helps you practice planning and executing early phases of a penetration test — from abstract methodology to enumeration.
In this module, you will learn about identifying vulnerabilities in a network or system, including the tools and techniques used to do so.
In this module, you will learn about identifying vulnerabilities in a network or system, including the tools and techniques used to do so.
This module covers the use of OpenVAS, an open source vulnerability assessment tool, including its features and use in identifying vulnerabilities in a network or system.
This 60-minute activity will help you apply manual and automated techniques to identify vulnerabilities using OpenVAS and logical auditing.
In this module, you will learn about the process of validating vulnerabilities, including the tools and techniques used to confirm the existence and impact of a potential vulnerability.
This module covers the use of exploit tools and distributions, including the types and functions of these tools and how they can be used to test and exploit vulnerabilities.
This 60-minute activity will help you validate vulnerabilities and understand how to safely work with common exploit tools.
Learn to craft a concise, professional penetration testing report that clearly communicates scope, methodology, findings, risk, and actionable mitigations to clients.
This 60-minute activity will help you practice analyzing scan data, calculating risk, and writing effective technical and executive-level reports.
Open virtual box, add and edit a network, and set subnet to enable two machines on the same switch to talk to each other using host-only adapters rather than NAT.
Set up multiple layers by adding a second network adapter to the VM, assign VMnet8 and VMnet5, and configure IP tables for a firewall in a cyber range.
Configure virtual box networks to mirror VMware switches. Create host-only networks, attach adapters, and set up a multi-homed virtual machine to route traffic through the internal switch.
Learn two VMware Player methods to add a network adapter and connect to a virtual switch, then compare VMware Player with VMware Workstation Pro and explore multilayer networks.
Customize IP addresses in VMware workstation pro and virtual box to emulate production networks, except in VMware workstation player, editing subnet blocks and enabling promiscuous mode for traffic sniffing.
Learn to find or build your own virtual machines and set them up in VMware or VirtualBox, then configure a flat network for practical penetration testing in a cyber range.
Set up the advanced range by adding five switches across VMware Workstation Pro and Oracle VirtualBox, configuring networks and promiscuous mode for VM access.
This 60-minute activity will help you apply virtualization and network design techniques from Labs Module One. You’ll build and document a working multi-layered cyber range.
Identify open ports on the target with nmap in verbose mode and compare results using unicornscan and hping, then review host services and port states.
Execute a multithreaded services scan with zenmap to identify services and versions, then grab banners via telnet or netcat to extract data from open targets.
Enumerate targets using the scripting engine in Zenmap, run service scans, and collect host data including operating system details to support the next step: identify vulnerabilities.
This 60-minute activity lets you practice intrusive scans, interpret results, and manually enumerate open services using techniques from Labs Module Two.
Explore vulnerability sites and advisories to identify command injection, arbitrary code execution, and zero-day risks, while evaluating CVSS scores and defense implications.
Explore using nmap to find vulnerabilities with vulnerability scripts, run full or targeted scans (including MS17-010), and interpret results with risk factors for reporting in a lab environment.
Explore Nikto, a web scanner that tests for known vulnerabilities and evasion on a web server, revealing versions and a remote code execution vulnerability for ethical exploitation.
Practice penetration testing by validating vulnerabilities and exploiting targets using metasploit framework and exploit db, including remote code execution on Windows seven and server twenty eight.
Analyze network data using tcpdump and wireshark to identify open ports, suspicious activity, and packet-level evidence of intrusions through protocol analysis and data flows.
This 60-minute activity helps you investigate real-world exploits and interpret packet captures using ExploitDB and TCPDump.
To effectively secure modern networks, you must first understand the mindset of an attacker. That is, you have to attack your own network to learn how to defend it. This is where ethical hacking and penetration testing come in. A penetration test, also known as a pen test or pentest or cyber security penetration test, is an authorized simulated attack on a system designed to evaluate and strengthen its security posture.
In this cybersecurity course, you will learn how to conduct a pentest and what cybersecurity is all about. You will learn how to build and hone the skills to develop the mindset of someone who has the sole purpose of attacking a system and/or network
As you progress, you will follow a structured penetration testing methodology and learn how to conduct network penetration testing in detail. You will build the skills and apply techniques to penetrate devices, servers, and client systems, and perform security penetration testing engagements. You will work within a defined scope, targeting systems that simulate real-world cyber pen testing environments.
Each day, you will be presented with a scope of work and have a number of targets to engage and attempt to “own.” The targets will be progressive in nature, with the size of the attack surface being reduced as your skill sets increase. Henceforth, you will gain hands-on experience in cybersecurity pen testing, identifying weaknesses, exploiting vulnerabilities, and understanding how attackers operate in IT scenarios.
By the end of this program, you will have conducted multiple simulated penetration test cyber security engagements and drafted a preliminary report of findings just like a professional penetration tester. The techniques taught are aligned with industry practices used by global cybersecurity penetration testing teams. The system is proven and effective, and can be put into place at once.
Your instructor, Kevin Cardwell, is a former senior U.S. Navy cybersecurity expert and the author of multiple books on cybersecurity.
More about this course and Starweaver
This course is led by a seasoned technology industry practitioner and executive, with many years of hands-on, in-the-trenches cybersecurity work. It has been designed, produced and delivered by Starweaver. Starweaver is one of the most highly regarded, well-established training providers in the world, providing training courses to many of the leading financial institutions and technology companies, including:
Ahli United Bank; Mashreqbank; American Express; ANZ Bank; ATT; Banco Votorantim; Bank of America; Bank of America Global Markets; Bank of America Private Bank; Barclay Bank; BMO Financial Group; BMO Financial Services; BNP Paribas; Boeing; Cigna; Citibank; Cognizant; Commerzbank; Credit Lyonnais/Calyon; Electrosonic; Farm Credit Administration; Fifth Third Bank; GENPACT; GEP Software; GLG Group; Hartford; HCL; HCL; Helaba; HSBC; HSBC Corporate Bank; HSBC India; HSBC Private Bank; Legal & General; National Australia Bank; Nomura Securities; PNC Financial Services Group; Quintiles; RAK Bank; Regions Bank; Royal Bank of Canada; Royal Bank of Scotland; Santander Corporate Bank; Tata Consultancy Services; Union Bank; ValueMomentum; Wells Fargo; Wells Fargo India Solutions; Westpac Corporate Bank; Wipro; and, many others.
Happy learning.