Introduction
Certified Ethical Hacker (CEH): Introduction
()
1. Introduction to Ethical Hacking
Module 1: Information security, cybersecurity, and ethical hacking overview introduction
()
Learning objectives
()
Introducing information security and cybersecurity
()
Understanding the cyber kill chain and hacking concepts
()
Surveying ethical hacking methodologies
()
Understanding information security controls
()
Understanding security laws and standards
()
Planning and scoping a penetration testing assessment
()
Building your own hacking lab with WebSploit Labs
()
2. Footprinting and Reconnaissance
Module 2: Reconnaissance techniques introduction
()
Learning objectives
()
Understanding information gathering and vulnerability identification
()
Introducing open source intelligence (OSINT) techniques
()
Exploring footprinting methodologies
()
Utilizing search engines for footprinting
()
Footprinting web services
()
Exploiting social networking sites for footprinting
()
Surveying password dumps, file metadata, and public source-code repositories
()
Using whois for footprinting
()
Implementing DNS footprinting
()
Executing network footprinting
()
Applying social engineering for footprinting
()
Introducing Shodan, Maltego, Amass, Recon-ng, and other recon tools
()
Identifying cloud vs. self-hosted assets
()
3. Scanning Networks
Surveying network scanning concepts
()
Exploiting scanning tools
()
Understanding host discovery
()
Performing website and web application reconnaissance
()
Performing OS discovery: Banner grabbing and OS fingerprinting
()
Scanning beyond IDS and firewall
()
Creating network diagrams
()
Discovering cloud assets
()
Crafting packets with Scapy to perform reconnaissance
()
4. Enumeration
Learning objectives
()
Introducing enumeration techniques
()
Performing NetBIOS enumeration
()
Performing SNMP enumeration
()
Performing LDAP enumeration
()
Performing NTP and NFS enumeration
()
Performing SMTP and DNS enumeration
()
Conducting additional enumeration techniques
()
Surveying enumeration countermeasures
()
5. Vulnerability Analysis
Module 3: System hacking phases and attack techniques introduction
()
Understanding vulnerability assessment concepts
()
Classifying and assessing vulnerability types
()
Utilizing vulnerability assessment tools
()
Generating vulnerability assessment reports
()
6. System Hacking
Learning objectives
()
Understanding system hacking concepts
()
Gaining system access
()
Cracking passwords
()
Exploiting known and zero-day vulnerabilities
()
Escalating privileges
()
Maintaining access, command and control, and exfiltration
()
Executing applications
()
Hiding files
()
Clearing logs
()
Performing on-path attacks
()
Introduction to lateral movement and exfiltration
()
Understanding post-engagement cleanup
()
7. Malware Threats
Understanding malware concepts
()
Comprehending APT concepts
()
Grasping trojan concepts
()
Exploring virus and worm concepts
()
Examining fileless malware and living off the land techniques
()
Analyzing malware
()
Implementing malware countermeasures
()
8. Sniffing
Module 4: Network and perimeter hacking introduction
()
Learning objectives
()
Introducing sniffing concepts
()
Performing MAC attacks
()
Conducting DHCP attacks
()
Performing ARP poisoning
()
Performing spoofing attacks
()
Performing DNS poisoning
()
Surveying sniffing tools
()
Exploring sniffing countermeasures and detection techniques
()
9. Social Engineering
Learning objectives
()
Introducing social engineering concepts and techniques
()
Understanding the insider threat
()
Impersonation on social networking sites
()
Understanding identity theft
()
Understanding social engineering countermeasures
()
10. Denial-of-Service
Introducing DoS/DDoS concepts and attack techniques
()
Defining what botnets are
()
Exploring DDoS case studies
()
Surveying DoS/DDoS attack tools
()
Understanding DoS/DDoS countermeasures and protection tools
()
11. Session Hijacking
Learning objectives
()
Introducing session hijacking concepts
()
Performing application level session hijacking
()
Understanding network level session hijacking
()
Surveying session hijacking tools
()
Understanding session hijacking countermeasures
()
12. Evading IDS, Firewalls, and Honeypots
Learning objectives
()
Introducing IDS, IPS, firewall, and honeypot concepts
()
Exploring IDS, IPS, firewall, and honeypot solutions
()
Evading IDS and firewalls
()
Surveying IDS and firewall evading tools
()
Detecting honeypots and sandboxes
()
Understanding IDS and firewall evasion countermeasures
()
13. Hacking Web Servers
Module 5: Web application hacking introduction
()
Learning objectives
()
Introducing web server concepts
()
Exploring web server attacks
()
Surveying web server attack methodologies
()
Understanding web server countermeasures
()
Understanding patch management
()
14. Hacking Web Applications
Learning objectives
()
Understanding web app concepts and identifying web app threats
()
Exploring the OWASP Top 10 for web applications
()
Applying web app hacking methodologies and footprinting web infrastructure
()
Analyzing web applications and bypassing client-side controls
()
Attacking authentication mechanisms
()
Attacking session management mechanisms
()
Exploiting authorization schemes and access controls flaws
()
Exploiting cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities
()
Understanding server-side request forgery (SSRF) vulnerabilities
()
Exploiting buffer overflows and creating payloads
()
Attacking application logic flaws and shared environments
()
Attacking database connectivity and web app clients
()
Attacking web services, exploiting web APIs, webhooks, and web shells
()
Ensuring web app security
()
15. SQL Injection
Introducing SQL injection concepts
()
Understanding the types of SQL injection
()
Exploring the SQL injection methodologies
()
Exploring SQL injection tools
()
Exploring SQL injection evasion techniques
()
Understanding SQL injection countermeasures
()
16. Hacking Wireless Networks
Module 6: Wireless, mobile, IoT, and OT hacking introduction
()
Learning objectives
()
Introducing wireless concepts
()
Understanding wireless encryption
()
Exploring wireless threats
()
Understanding wireless hacking methodologies
()
Surveying wireless hacking tools
()
Hacking Bluetooth
()
Introducing wireless countermeasure
()
Exploring wireless security tools
()
17. Hacking Mobile Platforms
Learning objectives
()
Understanding mobile platform attack vectors
()
Hacking Android OS
()
Hacking iOS
()
Understanding mobile device management
()
Surveying mobile security guidelines and tools
()
18. IoT and OT Hacking
Learning objectives
()
Understanding IoT concepts
()
Surveying IoT hacking methodologies and IoT hacking tools
()
Implementing IoT attack countermeasures
()
Introducing OT, ICS, and SCADA concepts and attacks
()
Implementing OT attack countermeasures
()
19. Cloud Computing
Module 7: Cloud computing and cryptography introduction
()
Learning objectives
()
Understanding cloud computing concepts
()
Exploring container technology and Kubernetes
()
Leveraging serverless computing
()
Identifying cloud computing threats
()
Conducting cloud hacking
()
Ensuring cloud security
()
Surveying patch management in the cloud
()
Introducing DevSecOps
()
Securing code, applications, and building DevSecOps pipelines
()
20. Cryptography
Learning objectives
()
Introducing cryptography and cryptanalysis
()
Understanding the different encryption algorithms and post-quantum cryptography
()
Describing hashing algorithms
()
Understanding public key infrastructure (PKI)
()
Understanding email encryption
()
Understanding disk encryption
()
Introducing certificate authorities (CAs) and certificate enrollment
()
Surveying SSL and TLS implementations
()
Surveying IPsec implementations and modern VPN implementations
()
21. Introduction to AI Threats and LLM Security
Module 8: Securing generative AI introduction
()
Learning objectives
()
Understanding the significance of LLMs in the AI landscape
()
Exploring the resources for this course: GitHub repositories and others
()
Introducing retrieval augmented generation (RAG)
()
Understanding the OWASP Top 10 risks for LLMs
()
Exploring the MITRE ATLAS™ (Adversarial Threat Landscape for Artificial-Intelligence Systems) framework
()
Understanding the NIST taxonomy and terminology of attacks and mitigations
()
22. Understanding Prompt Injection Insecure Output Handling
Learning objectives
()
Defining prompt injection attacks
()
Exploring real-life prompt injection attacks
()
Using ChatML for OpenAI API calls to indicate to the LLM the source of prompt input
()
Enforcing privilege control on LLM access to back-end systems
()
Best practices around API tokens for plugins, data access, and function-level permissions
()
Understanding insecure output handling attacks
()
Using the OWASP ASVS to protect against insecure output handling
()
23. Training Data Poisoning, Model Denial of Service Supply Chain Vulnerabilities
Learning objectives
()
Understanding training data poisoning attacks
()
Exploring model denial of service attacks
()
Understanding the risks of the AI and ML supply chain
()
Best practices when using open-source models from Hugging Face and other sources
()
Securing Amazon Bedrock, SageMaker, Microsoft Azure AI services, and other environments
()
24. Sensitive Information Disclosure, Insecure Plugin Design, and Excessive Agency
Learning objectives
()
Understanding sensitive information disclosure
()
Exploiting insecure plugin design
()
Avoiding excessive agency
()
25. Overreliance, Model Theft, and Red Teaming AI Models
Learning objectives
()
Understanding overreliance
()
Exploring model theft attacks
()
Understanding red teaming of AI models
()
26. Protecting Retrieval Augmented Generation (RAG) Implementations
Learning objectives
()
Understanding the RAG, LangChain, LlamaIndex, and AI orchestration
()
Securing embedding models
()
Securing vector databases
()
Monitoring and incident response
()
Conclusion
Certified Ethical Hacker (CEH): Summary
()