Advanced Infrastructure Hacking Training

  • Learn via: Classroom
  • Duration: 5 Days
  • Price: From $5,453+VAT
  • We can host this training at your preferred location. Contact us!
Upcoming Training
$5,453+VAT
08 June 2023
5 Days

Our Advanced Infrastructure Hacking course is designed for those who wish to push their knowledge. Whether you are Pen Testing, Red Teaming or trying to get a better understanding of managing vulnerabilities in your environment, understanding advanced hacking techniques is critical.

This course teaches the audience a wealth of advanced Pen Testing techniques, from the neat, to the new, to the ridiculous, to compromise modern Operating Systems, networking devices and Cloud environments. From hacking Domain Controllers to local root, to VLAN Hopping, to VoIP Hacking, to compromising Cloud account keys, we have got everything covered.

Who should attend

System Administrators, SOC Analysts, Penetration Testers, Network Engineers, security enthusiasts and anyone who wants to take their skills to next level.

While prior pen testing experience is not a strict requirement, familiarity with both Linux and Windows command line syntax will be greatly beneficial and a reasonable technical understanding of computers and networking in general is assumed. Some hands-on experience with tools commonly used by hackers, such as Nmap, NetCat, or Metasploit, will also be beneficial.

The course is ideal for those preparing for CREST CCT (ICE), CHECK (CTL), TIGER SST and other similar industry certifications, as well as those who perform Penetration Testing on infrastructure as a day job and wish to add to their existing skill set.

Harden your organisation’s infrastructure and make it a less attractive target for attackers by building a team that can identify, test, and recommend remediations for vulnerabilities and misconfigurations throughout your environments.

Trained delegates can:

  • Perform security testing that uses complex attack chaining across Windows (local), Active Directory, Linux, and common cloud environments
  • Design this testing around real-world attacker behaviour and tooling to ensure its relevance to the threats facing your organisation
  • Identify misconfigurations from network level to system level
  • Understand the business impact of misconfigurations and vulnerabilities and articulate this to key stakeholders
  • Implement logging and monitoring processes to detect live attacks
  • Take on greater responsibility in the team and become an advocate of security in the wider business

IPV4/IPV6 SCANNING, OSINT

  • Advanced topics in network scanning
  • Understanding & exploiting IPv6 Targets
  • Advanced OSINT Data gathering

WEB TECHNOLOGIES

  • Exploiting DVCS (git)
  • Owning Continuous Integration (CI) servers
  • Deserialization Attacks (Java, Python, Node, PHP)

HACKING DATABASE SERVERS

  • Mysql
  • Postgres
  • Oracle
  • MongoDB

WINDOWS EXPLOITATION

  • Windows Enumeration and Configuration Issues
  • Windows Desktop ‘Breakout’ and AppLocker Bypass Techniques (Win 10)
  • Local Privilege Escalation
  • A/V & AMSI Bypass techniques
  • Offensive PowerShell Tools and Techniques
  • Post Exploitation Tips, Tools and Methodology

AD EXPLOITATION

  • Active Directory Delegation Reviews and Pwnage (Win 2016 server)
  • Pass the Hash/Ticket Pivoting and WinRM Certificates
  • Cross Domain and Forest attacks
  • Pivoting, Port Forwarding and Lateral Movement Techniques
  • Persistence and backdooring techniques (Golden Ticket, DCSync, LOLBAS)
  • Command and Control (C2) Frameworks

LINUX EXPLOITATION

  • Linux Vulnerabilities and Configuration Issues
  • Treasure hunting via enumeration
  • File Share/SSH Hacks
  • X11 Vulnerabilities
  • Restricted Shells Breakouts
  • Breaking Hardened Web Servers
  • Local Privilege Escalation
  • MongoDB exploitation
  • TTY hacks, Pivoting
  • Gaining root via misconfigurations
  • Kernel Exploitation
  • Post Exploitation and credentials harvesting

CONTAINER BREAKOUT

  • Breaking and Abusing Docker
  • Exploiting Kubernetes environments
  • Breaking out of kubernetes containers

CLOUD HACKING

  • AWS/Azure/GCP specific attacks
  • Storage Misconfigurations
  • Credentials, API’s and token Abuse
  • IaaS, PaaS, SaaS, CaaS and Serverless exploitation
  • Azure AD attacks

VPN EXPLOITATION

  • Exploiting Insecure VPN Configuration

VLAN ATTACKS

  • VLAN Concepts
  • VLAN Hopping Attacks



Contact us for more detail about our trainings and for all other enquiries!

Upcoming Trainings

Join our public courses in our Istanbul, London and Ankara facilities. Private class trainings will be organized at the location of your preference, according to your schedule.

08 June 2023

Classroom / Virtual Classroom

Istanbul, Ankara, London
12 June 2023
$5,453+VAT
Book Now
Classroom / Virtual Classroom

Istanbul, Ankara, London
08 July 2023

Classroom / Virtual Classroom

Istanbul, Ankara, London
16 July 2023

Classroom / Virtual Classroom

Istanbul, Ankara, London
20 July 2023

Classroom / Virtual Classroom

Istanbul, Ankara, London
07 August 2023

Classroom / Virtual Classroom

Istanbul, Ankara, London
11 August 2023

Classroom / Virtual Classroom

Istanbul, Ankara, London
05 October 2023

Classroom / Virtual Classroom

Istanbul, Ankara, London

Related Trainings

By using this website you agree to let us use cookies. For further information about our use of cookies, check out our Cookie Policy.