The hacking training is an intensive one-day workshop. IT professionals, system administrators and developers learn how an attacker goes about taking over an infrastructure. Unlike a theoretical course, during this training you carry out a real penetration test yourself, following the PTES methodology.
Data breaches often begin with a hacking attack, and a lack of security awareness within the IT team is an important cause of this. By finding and exploiting vulnerabilities yourself in a safe lab environment, you gain a better sense of the risks than any theory can offer.
We deliver the training entirely at your location, with two OSCP-certified ethical hackers from Hackify. We bring the hacking laptops and the entire lab infrastructure with vulnerable systems on which participants can hack. Participants apply every technique straight away in realistic scenarios, from OSINT and port scanning to privilege escalation in Active Directory.
An IT team works with systems and networks every day, but often does not know how an attacker actually gets in. Knowing in theory which vulnerabilities exist is something quite different from exploiting one yourself or taking over a complete Active Directory domain.
A hacking training is sensible in the following situations:
Those who hack themselves truly see where the risks lie and can better assess the organisation’s attack surface.
A hacking training covers the components of the pentest process, based on the PTES methodology (Penetration Testing Execution Standard). The training is delivered by two OSCP-certified ethical hackers who carry out penetration tests every day.
The training begins with an introduction to ethical hacking and penetration testing. We discuss the different types and methodologies, with an emphasis on the PTES methodology, the difference between black-box, grey-box and white-box testing, and the legal and ethical side of a pentest.
Gathering information is the basis of every penetration test. You learn to work with Kali Linux and OSINT techniques to gather information about an organisation. We show you how to uncover email addresses, employees and the technologies in use through public sources and metadata.
Port scanning and service detection are important for finding attack vectors. You learn port scanning with Nmap, banner grabbing and version detection. We link discovered services to known CVEs and discuss how to assess the risk of an attack vector. As a practical exercise, you scan the entire lab environment.
With exploitation, theory becomes practice. You learn how to exploit a known vulnerability and how to turn a misconfiguration or a logic flaw into full access to a system. We cover privilege escalation from an ordinary user to admin or root, and reading passwords with Mimikatz. You break into multiple systems in the lab.
Active Directory is often an attacker’s most important target. You learn SMB exploitation, pass-the-hash, Kerberoasting and analysing attack paths with BloodHound. The highlight is domain privilege escalation: from an ordinary user to Domain Admin, taking the entire Windows network into your hands.
More about our approach and expertise on our about us page.
Would you like to give your IT team hands-on security training? Then get in touch with us without obligation via our contact page. We would be happy to tell you more about our company and our approach, and would love to hear more about your organisation and your team’s needs.
Every hacking training is different, so we draw up a tailored proposal for each assignment. The training can take place within 3 weeks and is delivered entirely at your location. The training lasts one day of 7 hours and covers the introduction, OSINT, identifying vulnerabilities, exploitation and taking over Active Directory.
We give your team a day of hands-on training in OSINT, exploitation and Active Directory attacks, at your office. Request a tailored proposal.
Get in touchOr email us directly at [email protected]
The hacking training lasts one day, with 7 hours of hands-on work.
We deliver the training entirely at your location, with two ethical hackers.