Security

Pentester Training – Practical Penetration Testing and IT Security

The Pentester – Practical Penetration Testing and IT Security training is a comprehensive workshop that prepares you to independently conduct security testing of applications, networks, and IT infrastructure.

Duration
6h
Who it's for

Ideal for teams that…

1 IT specialists who want to start working in penetration testing
2 System administrators and engineers who want to improve the security of their infrastructure
3 Developers and architects of web and mobile applications
4 People preparing for roles in cybersecurity or certifications such as CEH, OSCP
Outcomes after the program

Application and infrastructure security — a workshop for technical teams.

How to understand application architecture and identify its weak points

How to detect vulnerabilities in network services and web/mobile applications

How to apply risk assessment models (STRIDE, DREAD, CVSS) in a security context

How to use key pentesting tools (Nmap, Wireshark, Burp Suite, Metasploit)

How to conduct penetration tests following the stages: planning, execution, reporting

How to create recommendations and reports after tests in line with best practices

Program · 3 modules

What we actually do

M01
Day 1: Basics of Applications and Networks
  • · Application workflow
  • · Key application components
  • · Typical communication issues between components (weak points)
  • · TCP/IP protocol
  • · OSI model layers
  • · Key network services and their use
  • · Common vulnerabilities of network services
  • · Network security models
  • · Firewalls, IDS/IPS
  • · Network segmentation
  • · Common threats and detection methods
M02
Day 2: Risk Management and Application Security
  • · Definition of risk
  • · Risk identification and assessment methods
  • · STRIDE
  • · DREAD
  • · CVSS
  • · Overview of OWASP Top 10 threats
  • · Application testing in the OWASP context
  • · Examples of real-world vulnerabilities
  • · Goals and scope of infrastructure penetration tests
  • · Scanning techniques and weakness detection
  • · Examples of attacks and analysis
M03
Day 3: Penetration Testing and System Security
  • · Security settings and system policies
  • · Permissions and access control management
  • · Incident detection and response
  • · Nmap
  • · Wireshark
  • · Burp Suite
  • · Metasploit
  • · Using tools in security testing
  • · Practical usage scenarios
  • · Security threats specific to iOS and Android
  • · Mobile application testing methods
  • · Client-side and server-side security
  • · Web application architecture
  • · Common attack points
  • · Programming mistakes and common vulnerabilities
  • · Tools and techniques for web application testing
  • · Planning
  • · Execution
  • · Reporting
  • · Ethical aspects of penetration testing
  • · Documentation and post-test recommendations
Every module is adapted to your stack and context. The above is a starting point — not a fixed agenda.
How we work

From brief to retro in 30 days.

01

Brief & diagnosis

A call with the team lead + a short survey for participants. We define goals, gap and context.

02

Program customization

We adapt modules, case studies and code examples to your stack. Approval in 5 days.

03

Workshop

Trainer-led sessions, hands-on, code review. Mentor available between sessions too.

04

Retro + report

Outcome report for the team and lead. 30 days of consulting included.

Inquiry

Send a brief. We'll reply within 1 day.

After a short brief we'll prepare a program and a quote. No obligations — it's just a starting point.

Quote within 48h of the brief
First session within 30 days
Pilot before the full decision
VAT invoice, payment in instalments possible

Ochrona antyspamowa (Cloudflare Turnstile) zostanie aktywowana po wpięciu klucza.