To wersja testowa nowego serwisu infoShare Academy — wyświetlane treści i oferta nie są wiążące ani kompletne

Security

Pentester

The Pentester – Practical Penetration Testing and IT Security training is a comprehensive workshop that prepares you to independently conduct security testing of applications, networks, and IT infrastructure.

Duration
24h · 3 days
Who it's for

Ideal for teams that…

1 IT specialists who want to start working in penetration testing
2 System administrators and engineers who want to improve the security of their infrastructure
3 Developers and architects of web and mobile applications
4 People preparing for roles in cybersecurity or certifications such as CEH, OSCP
Outcomes after the program

Application and infrastructure security — a workshop for technical teams.

How to understand application architecture and identify its weak points

How to detect vulnerabilities in network services and web/mobile applications

How to apply risk assessment models (STRIDE, DREAD, CVSS) in a security context

How to use key pentesting tools (Nmap, Wireshark, Burp Suite, Metasploit)

How to conduct penetration tests following the stages: planning, execution, reporting

How to create recommendations and reports after tests in line with best practices

Program

What we actually do

Day 1: Basics of Applications and Networks

  • · Application workflow
  • · Key application components
  • · Typical communication issues between components (weak points)
  • · TCP/IP protocol
  • · OSI model layers
  • · Key network services and their use
  • · Common vulnerabilities of network services
  • · Network security models
  • · Firewalls, IDS/IPS
  • · Network segmentation
  • · Common threats and detection methods

Day 2: Risk Management and Application Security

  • · Definition of risk
  • · Risk identification and assessment methods
  • · STRIDE
  • · DREAD
  • · CVSS
  • · Overview of OWASP Top 10 threats
  • · Application testing in the OWASP context
  • · Examples of real-world vulnerabilities
  • · Goals and scope of infrastructure penetration tests
  • · Scanning techniques and weakness detection
  • · Examples of attacks and analysis

Day 3: Penetration Testing and System Security

  • · Security settings and system policies
  • · Permissions and access control management
  • · Incident detection and response
  • · Nmap
  • · Wireshark
  • · Burp Suite
  • · Metasploit
  • · Using tools in security testing
  • · Practical usage scenarios
  • · Security threats specific to iOS and Android
  • · Mobile application testing methods
  • · Client-side and server-side security
  • · Web application architecture
  • · Common attack points
  • · Programming mistakes and common vulnerabilities
  • · Tools and techniques for web application testing
  • · Planning
  • · Execution
  • · Reporting
  • · Ethical aspects of penetration testing
  • · Documentation and post-test recommendations
Every module is adapted to your stack and context. The above is a starting point — not a fixed agenda.
How we work

From brief to retro in 30 days.

01

Brief & diagnosis

A call with the team lead + a short survey for participants. We define goals, gap and context.

02

Program customization

We adapt modules, case studies and code examples to your stack. Approval in 5 days.

03

Workshop

Trainer-led sessions, hands-on, code review. Mentor available between sessions too.

04

Retro + report

Outcome report for the team and lead. 30 days of consulting included.

Inquiry

Send a brief. We'll reply within 1 day.

After a short brief we'll prepare a program and a quote. No obligations — it's just a starting point.

Quote within 48h of the brief
First session within 30 days
Pilot before the full decision
VAT invoice, payment in instalments possible

How we handle your data

We process your business data (name, work e-mail, phone number, company, job title) in order to handle your corporate training inquiry and prepare an offer. The data controller is infoShare Academy Sp. z o.o., Al. Grunwaldzka 472B, 80-309 Gdańsk. Providing the data is voluntary but necessary to receive a response. You have the right to access, rectify, erase or restrict the processing of your data and to object to it. Full information is available in our data processing notice.

Optional marketing consents

The controller of your personal data is infoShare Academy sp. z o.o. The rules for processing personal data are set out in the Privacy Policy and the Data Processing Notice.