Hero

WE ARE

HACKIFY

What is the hacking training

Icon of a hacking training

The hacking training is an intensive one-day workshop. IT professionals, system administrators and developers learn how an attacker goes about taking over an infrastructure. Unlike a theoretical course, during this training you carry out a real penetration test yourself, following the PTES methodology.

Data breaches often begin with a hacking attack, and a lack of security awareness within the IT team is an important cause of this. By finding and exploiting vulnerabilities yourself in a safe lab environment, you gain a better sense of the risks than any theory can offer.

We deliver the training entirely at your location, with two OSCP-certified ethical hackers from Hackify. We bring the hacking laptops and the entire lab infrastructure with vulnerable systems on which participants can hack. Participants apply every technique straight away in realistic scenarios, from OSINT and port scanning to privilege escalation in Active Directory.


Why and when is a hacking training important?

An IT team works with systems and networks every day, but often does not know how an attacker actually gets in. Knowing in theory which vulnerabilities exist is something quite different from exploiting one yourself or taking over a complete Active Directory domain.

A hacking training is sensible in the following situations:

  • your IT team wants to understand how an attacker gets into systems, in order to defend them better
  • you have had an incident and want to prevent a recurrence by understanding the attack vectors
  • you need to meet the awareness requirements of ISO 27001 or NIS2
  • you are moving to new technology and want to validate security during a cloud migration or with new infrastructure
  • you want to give your team annual refresher training, so it keeps up with new attack techniques

Those who hack themselves truly see where the risks lie and can better assess the organisation’s attack surface.


What does a hacking training cover?

A hacking training covers the components of the pentest process, based on the PTES methodology (Penetration Testing Execution Standard). The training is delivered by two OSCP-certified ethical hackers who carry out penetration tests every day.

Introduction to ethical hacking

The training begins with an introduction to ethical hacking and penetration testing. We discuss the different types and methodologies, with an emphasis on the PTES methodology, the difference between black-box, grey-box and white-box testing, and the legal and ethical side of a pentest.

Enumeration and OSINT

Gathering information is the basis of every penetration test. You learn to work with Kali Linux and OSINT techniques to gather information about an organisation. We show you how to uncover email addresses, employees and the technologies in use through public sources and metadata.

Identifying vulnerabilities

Port scanning and service detection are important for finding attack vectors. You learn port scanning with Nmap, banner grabbing and version detection. We link discovered services to known CVEs and discuss how to assess the risk of an attack vector. As a practical exercise, you scan the entire lab environment.

Exploitation and general attacks

With exploitation, theory becomes practice. You learn how to exploit a known vulnerability and how to turn a misconfiguration or a logic flaw into full access to a system. We cover privilege escalation from an ordinary user to admin or root, and reading passwords with Mimikatz. You break into multiple systems in the lab.

Active Directory exploitation

Active Directory is often an attacker’s most important target. You learn SMB exploitation, pass-the-hash, Kerberoasting and analysing attack paths with BloodHound. The highlight is domain privilege escalation: from an ordinary user to Domain Admin, taking the entire Windows network into your hands.


Why choose Hackify?

  • Proven expertise - Ethical hackers with at least 5 years of experience, 3 certificates and relevant expertise per test component (not the industry minimum of 1 year and 1 certificate)
    • Track record - Responsible disclosures at Philips, Zoom, Oracle, Politie and many others
    • Hacking competition winners - Prizes at Hack010, PVIB CTF, Hackerhotel and HackTheHague
  • Active pentesters as trainers - Delivered by ethical hackers who carry out pentests daily
  • Hands-on focus - 80% practice, 20% theory for maximum learning effect
  • Complete provision - Hacking laptops, lab environment and all tools fully arranged
  • On-site training - Delivered at your office for minimal travel time

More about our approach and expertise on our about us page.


Plan your hacking training

Would you like to give your IT team hands-on security training? Then get in touch with us without obligation via our contact page. We would be happy to tell you more about our company and our approach, and would love to hear more about your organisation and your team’s needs.

Every hacking training is different, so we draw up a tailored proposal for each assignment. The training can take place within 3 weeks and is delivered entirely at your location. The training lasts one day of 7 hours and covers the introduction, OSINT, identifying vulnerabilities, exploitation and taking over Active Directory.

Ready for on-site hacking training?

We give your team a day of hands-on training in OSINT, exploitation and Active Directory attacks, at your office. Request a tailored proposal.

Get in touch

Or email us directly at [email protected]

Frequently asked questions about the hacking training

How many participants can take part?

We work with small groups, so we can give everyone proper guidance. A session has a minimum of 4 and a maximum of 8 participants. With 6 participants there is the most room for interaction between attendees. If you register more than 8 people, we schedule multiple sessions. Because the group is small, there is personal attention and plenty of room for questions.

How long does the hacking training take?

The hacking training lasts one day, with 7 hours of hands-on work.

  • In the morning, from 09:00 to 12:45, we cover the introduction, OSINT and identifying vulnerabilities.
  • In the afternoon, from 13:30 to 17:00, the focus is on exploitation and Active Directory.
  • In between there are two 15-minute breaks and a 45-minute lunch.

We deliver the training entirely at your location, with two ethical hackers.

What does the hacking training cost?

The price of a hacking training depends on the scope, the number of participants and other aspects such as customisation and specific requirements. After an intake meeting, we draw up a suitable proposal for you that matches your situation.

What facilities do we need to provide from our organisation?

For the training day we need a room with at least 10 chairs, for 8 participants and 2 trainers. We also ask for a stable internet connection to download tools and a large screen with an HDMI connection for the presentation. A whiteboard is handy for explanations, but not required. We bring the laptops and the lab environment ourselves.