Learning objectives

The participants know the dangers of network attacks. They are able to check their company independently for weak spots and can introduce and apply the corresponding countermeasures.

Highlights

  • Information gathering (Google, Website, WHOIS)
  • Port Scanning, Vulnerability Scanning, Exploitation, Elevation of Privileges
  • OSSTMM process description for penetration tests
  • Sniffing, ARP spoofing
  • Tunneling Mechanisms (HTTP Tunnel, DNS Tunnel)
  • Voice over IP and remote access threats
  • Hands-on with Nessus, Metasploit, Nmap, etc

 

Demarcation: This course primarily treats attacks on the network and system levels. The attacks on web applications will be taught in the Web Application Security courses. Analysis and monitoring of logs will be treated in the courses on forensics and APT analysis.

Target group

  • Security Officers
  • Network Administrators/Engineers
  • Unix/Windows Administrators
  • Firewall Administrators/Engineer

 Prerequisite

  • Familiarity with the Windows command line
  • Basic knowledge of network protocols (TCP/IP)
  • VoIP, VLAN, ARP, DNS should be familiar concepts

CALENDAR

Beer-Talk in St. Gallen: Azure Security 101

Im Sommer 2018 kündigte Microsoft an, ihre Cloud-Lösungen aus Schweizer Rechenzentren anzubieten. Viele hiesige KMUs und Grossunternehmen haben sich... Read more

Swiss Cyber Hackathon 2019 / Zurich

Simulating Real World Cyber Scenarios – Educational Cyber Competition of Defending your Environment and Attacking your Opponents Read more

Internet Security Days 2019 - Game of IT-Security

Based on the theme "Online Security", a wide conference program and an exhibition awaits you on September 26/27, 2019. New in the programme are... Read more

ALL DATES

NEWS

So leicht wird dein Handy gehackt

Die Blick-Reporterin weiss dank Ivan Bütler, warum man auch bei einer SMS von Mami kritisch sein soll. Read more

Rückblick Digitaltag 2019

Ivan Bütler von Compass Security hat einen aufregenden Digitaltag hinter sich. Seine Live Hacks am Züricher Hauptbahnhof waren ein Publikumsmagnet. Read more

Wie steht es um die Sicherheit der Schweizer Stromversorgung?

Im Bericht der Eidgenössischen Elektrizitätskommision kommt die Schweizer Stromversorgung diesbezüglich nicht gut weg. Studerus AG hat dazu Cyrill... Read more

ARCHIVES

Compass Security Blog

enOcean Security

In this post, we are going to take a closer look at the enOcean technology, how security is implemented, and if the security measures and options available are sufficient. mehr

Privilege escalation in Windows Domains (3/3)

In this last article about privilege escalation in Windows domains, we demonstrate how to extract credentials from running systems to compromise high-privileged accounts. mehr

ZUM BLOG