| Curriculum |
|---|
|
1. Penetration test and types of tools - 8 hours Distinction between penetration testing and auditing.
Classification according to available information:
Classification according to the services to be tested:
|
|
2. Intrusion testing methodologies - 20 hours Description of the phases of an intrusion test:
Definition of concepts:
OSSTMM (Open Source Security Testing Methodology Manual) classification:
OWASP (Open Web Application Security Project) classification:
Differences between OSSTMM and OWASP |
|
3. Tools for the execution of penetration tests - 18 hours Generic tool classification:
Classification of network tools:
Classification of password cracking/stealing tools:
|
|
4. Results and reports - 6 hours Documentation support tools:
Reporting:
Defining record retention policies:
|
|
5. Planning and execution of an intrusion test - 8 hours Selection of the most appropriate methodology to perform an intrusion test:
Selection of the type of test to determine the exploitability of vulnerabilities:
Preparation of the intrusion test report:
|