Module 1: ISECOM and Methodologies
- Overview of ISECOM
- Rules of Engagement
- Rule of Thumb
- The Process
- The Security Map
- Risk Assessment
- Sections, Modules and Tasks
|
Module 2: Building a Testing Environment
|
Module 3: Vulnerabilities
- Keeping up to date
- Monitoring & Intrusion Detection (Lack of)
- Network Architecture
- Network File System
- NT Ports 135-139 (NetBIOS & File Sharing)
- NT Null Connection
- Poor Passwords & User Ids
- Remote Administration Services
- Services started by default
- Simple Mail Transport Protocol
- Application Holes
- Clear Text Services
- Default Accounts
- Domain Name Service (DNS)
- File Permissions
- FTP and Telnet
- Modems
- Web server
- Viruses and hidden code
- Buffer overflows
|
Module 4: Competitive Intelligence Scouting
- Discovery Profiling Tools
|
Module 5: Network Surveying
- Name Server Responses
- Outer wall of Network
- Tracks from Target Network
- Information Leaks
|
Module 6: System Services Identification
- Enumerate systems and ports
- Identify services and systems
|
Module 7: Sniffers
- Tools to capture network traffic
|
| | |
|
| |
|
Module 13: Intrusion Detection Systems
- What is Intrusion Detection
- What is Intrusion Detection?
- IDS Methodologies
- IDS Deployment
- Manager to Agent Communication
- Optimal Agent Placement
- IDS Applications and Rules
- IDS Actions, Logging & Concerns
- IDS Evasion
- Pitfalls
|
| |
|
Module 14: Firewalls
- Types of Firewall
- Advantages and Disadvantages of each type
- Bastion Hosts
- DMZ (Demilitarised Zone)
Network Address Translation
Evading Firewalls
|
|
| Module 8: Social Engineering |
Module 9: War-Dialling
- Attacks
- Methods
- Precautions
- Tools & Software
|
Module 10: Internal Penetration Testing
- Mapping the network
- NT & Unix Enumeration
|
Module 11: Automated Vulnerability Scanners
- Use in Pen Testing
- Limitations
|