Security

Network Security and Penetration Testing Training

The Network Security and Penetration Testing training is a comprehensive course that introduces participants to the world of cybersecurity, penetration testing, and network infrastructure protection in a practical way.

Duration
6h
Who it's for

Ideal for teams that…

1 Pentesters and IT security specialists who want to expand their skills
2 Network and system administrators responsible for infrastructure security
3 Developers and DevOps teams interested in vulnerability analysis of applications and services
4 People beginning their career in cybersecurity
Outcomes after the program

Application and infrastructure security — a workshop for technical teams.

How to create test environments for penetration testing (Kali Linux, DVWA, Metasploitable2)

How to detect and exploit web application vulnerabilities (SQLi, XSS, CSRF, LFI, RFI, Command Injection)

How to conduct attacks on WLAN networks (WEP, WPA/WPA2, WPS, Evil Twin, Rogue AP)

How to analyze and attack remote access services (VNC, SSH, Samba, RDP)

How to understand SSL/TLS weaknesses and perform Man-in-the-Middle attacks

How to exploit vulnerabilities in Windows systems and identify security gaps

How to implement basic defense mechanisms and incident response strategies

Program · 6 modules

What we actually do

M01
Module 1: Creating Test Environments for Penetration Testing
  • · Introduction to vulnerable-by-design environments
  • · Configuring Kali Linux as the main pentesting tool
  • · DVWA (Damn Vulnerable Web Application) – testing web applications
  • · Metasploitable / Metasploitable2 – environment for testing network services and exploits
M02
Module 2: Web Application Security
  • · OWASP – Open Web Application Security Project: mission, goals, Top 10
  • · Path Traversal
  • · Local File Inclusion (LFI)
  • · Remote File Inclusion (RFI)
  • · SQL Injection
  • · Command Injection
  • · Cross-Site Scripting (XSS)
  • · Cookie manipulation & Session Hijacking
  • · Brute-force attacks
  • · Cross-Site Request Forgery (CSRF)
  • · Vulnerabilities in file upload mechanisms
M03
Module 3: Attacks on WLAN Infrastructure
  • · Introduction to wireless network security
  • · Monitor mode – packet capturing
  • · Attacks on protocols: WPS, WEP, WPA/WPA2
  • · Offensive techniques: Wardriving, Evil Twin attack, Rogue Access Points
M04
Module 4: Attacks on Remote Access Services
  • · Samba – unauthorized access to resources
  • · VNC remote access – session hijacking
  • · SSH remote access – exploiting weak passwords or known exploits
M05
Module 5: Attacks on SSL/TLS Connections
  • · Basics of SSL/TLS – purpose and functionality
  • · Known SSL/TLS attacks: POODLE, SSL Stripping, FREAK, Lucky Thirteen, Raccoon, BEAST
  • · Introduction to MITM
  • · Tools: Bettercap, SSLStrip
  • · Decrypting SSL/TLS – intercepting encrypted traffic
M06
Module 6: Attacks on Windows System Security
  • · File History service vulnerability
  • · Critical flaw in Microsoft Outlook
  • · ZeroLogon – domain controller privilege escalation
  • · Windows CryptoAPI Spoofing Vulnerability
  • · Remote Desktop Gateway – RDP attacks over the internet
  • · SAMBA vulnerability in Windows 7
  • · Exploiting RDP services – remote desktop session takeover
Every module is adapted to your stack and context. The above is a starting point — not a fixed agenda.
How we work

From brief to retro in 30 days.

01

Brief & diagnosis

A call with the team lead + a short survey for participants. We define goals, gap and context.

02

Program customization

We adapt modules, case studies and code examples to your stack. Approval in 5 days.

03

Workshop

Trainer-led sessions, hands-on, code review. Mentor available between sessions too.

04

Retro + report

Outcome report for the team and lead. 30 days of consulting included.

Inquiry

Send a brief. We'll reply within 1 day.

After a short brief we'll prepare a program and a quote. No obligations — it's just a starting point.

Quote within 48h of the brief
First session within 30 days
Pilot before the full decision
VAT invoice, payment in instalments possible

Ochrona antyspamowa (Cloudflare Turnstile) zostanie aktywowana po wpięciu klucza.