Course : Cybersecurity, testing environments

attack, detect, collect and analyze

Practical course - 3d - 21h00 - Ref. CTE
Price : 2470 CHF E.T.

Cybersecurity, testing environments

attack, detect, collect and analyze



This advanced training course will teach you the techniques you need to measure the security level of your Information System. Following these attacks, you will learn how to trigger the appropriate response and raise the security level of your network.


INTER
IN-HOUSE
CUSTOM

Practical course in person or remote class
Disponible en anglais, à la demande

Ref. CTE
  3d - 21h00
2470 CHF E.T.




This advanced training course will teach you the techniques you need to measure the security level of your Information System. Following these attacks, you will learn how to trigger the appropriate response and raise the security level of your network.


Teaching objectives
At the end of the training, the participant will be able to:
Understand hacker techniques and counter their attacks
Measure the security level of your Information System
Perform a penetration test

Intended audience
Security managers and architects. System and network technicians and administrators.

Prerequisites
Good knowledge of IS security, networks and systems (especially Linux).

Course schedule

1
Web attacks

  • OWASP: organization, chapters, Top10, manuals, tools.
  • Discover the infrastructure and associated technologies, strengths and weaknesses.
  • Client side: clickjacking, CSRF, cookie theft, XSS, components (Flash, Java). New vectors.
  • Server side: authentication, session theft, injections (SQL, LDAP, files, commands).
  • Inclusion of local and remote files, cryptographic attacks and vectors.
  • Evasion and bypassing protection: WAF bypass techniques, for example.
  • Burp Suite tools, ZAP, Sqlmap, BeEF.
Role-playing
Presentation and familiarization with environments and tools. Implementation of various Web attacks in real-life conditions on the server and client sides.

2
Detecting intrusions

  • Operating principles and detection methods.
  • Market players, overview of systems and applications.
  • Network (Nmap) and application (Web applications) scanners.
  • IDS (Intrusion Detection System).
  • The advantages of these technologies, and their limitations.
  • How do you place them in your enterprise architecture?
  • Market overview, detailed SNORT study.
Role-playing
Presentation and familiarization with environments and tools. Installation, configuration and implementation of SNORT, writing attack signatures.

3
Information gathering

  • Heterogeneous sources. What is a safety event?
  • Security Event Information Management (SIEM). Events collected from the IS.
  • Equipment system logs (firewalls, routers, servers, databases, etc.).
  • Passive collection in listening mode and active collection.
Role-playing
Log analysis procedure. Geolocating an address. Correlating logs from different sources, visualizing, sorting and searching for rules.


Customer reviews
4,5 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
LAURENT C.
24/06/26
5 / 5

The course could be worthwhile over five days so that we can explore each topic in greater depth
WASSIMA H.
24/06/26
5 / 5

A brilliant trainer, with a very good balance between theory and practice. The training content was very comprehensive
JEAN YVES G.
24/06/26
5 / 5

An excellent, dynamic and highly professional trainer



Publication date : 07/30/2024



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.

Dates and locations

Dernières places
Date garantie en présentiel ou à distance
Session garantie
From 7 to 9 October 2026
FR
Remote class
Registration
From 9 to 11 December 2026 *
FR
Remote class
Registration
From 24 to 26 March 2027
FR
Remote class
Registration
From 24 to 26 March 2027
EN
Remote class
Registration
From 23 to 25 June 2027
FR
Remote class
Registration
From 23 to 25 June 2027
EN
Remote class
Registration
From 22 to 24 September 2027
FR
Remote class
Registration
From 22 to 24 September 2027
EN
Remote class
Registration
From 15 to 17 December 2027
FR
Remote class
Registration
From 15 to 17 December 2027
EN
Remote class
Registration

REMOTE CLASS
2026 : 7 Oct., 9 Dec.

2027 : 24 Mar., 24 Mar., 23 June, 23 June, 22 Sep., 22 Sep., 15 Dec., 15 Dec.



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.