Course : Hacking and security with CyberRange

Practical course - 5d - 35h00 - Ref. HCR
Price : 3660 CHF E.T.

Hacking and security with CyberRange




This advanced training course will teach you the techniques you need to measure the security level of your information system. Following these attacks, you'll learn how to trigger the appropriate response and raise the security level of your network.


INTER
IN-HOUSE
CUSTOM

Practical course in person or remote class
Disponible en anglais, à la demande

Ref. HCR
  5d - 35h00
3660 CHF E.T.




This advanced training course will teach you the techniques you need to measure the security level of your information system. Following these attacks, you'll learn how to trigger the appropriate response and raise the security level of your network.


Teaching objectives
At the end of the training, the participant will be able to:
Understand hacker techniques and counter their attacks
Measure the security level of your information system
Perform a penetration test
Defining the impact and scope of a vulnerability

Intended audience
Security managers and architects. System and network technicians and administrators.

Prerequisites
Good knowledge of IS security, networks, systems (especially Linux) and programming. Or knowledge equivalent to that acquired in the course "System and network security" (ref. SCR).

Practical details
Hands-on work
Airbus CyberSecurity's CyberRange is used to create and play out realistic scenarios involving real cyber-attacks.

Course schedule

1
Hacking and security

  • Forms of attack.
  • Operating procedures.
  • Players and issues.

2
Sniffing, interception, analysis, network injection

  • Packet anatomy, tcpdump, Wireshark, tshark.
  • Hijacking and interception of communications (man-in-the-middle, VLAN attacks, honeypots).
  • Packages: sniffing, reading/analysis from a pcap, extraction of useful data, graphical representations.
  • Scapy: architecture, capabilities, use.
  • Scenarios and tools available on CyberRange.
Hands-on work
Listen to the network with sniffers. Use scapy (command line, python script): injections, interception, pcap reading, scanning, DoS, man-in-the-middle (MITM).

3
Recognition, scanning and enumeration

  • Intelligence gathering, hot reading, darknet exploitation, social engineering.
  • Service, system, topology and architecture recognition.
  • Types of scans, filtering detection, firewalking, fuzzing.
  • Camouflage by spoofing and bouncing, path identification with traceroute, source routing.
  • IDS and IPS evasion: fragmentations, covert channels.
  • Nmap: scan and export results, options.
  • Other scanners: Nessus, OpenVAS.
  • Scenarios and tools available on CyberRange.
Hands-on work
Using the nmap tool and detecting filtering on the CyberRange platform.

4
Web attacks

  • OWASP: organization, chapters, Top10, manuals, tools.
  • Discover the infrastructure and associated technologies, strengths and weaknesses.
  • Client-side: clickjacking, CSRF, cookie theft, XSS, components (Flash, Java). New vectors.
  • Server side: authentication, session theft, injections (SQL, LDAP, files, commands).
  • Inclusion of local and remote files, cryptographic attacks and vectors.
  • Protection evasion and circumvention: WAF bypass techniques.
  • Burp Suite, ZAP, SQLmap, BeEF tools.
  • Scenarios available on CyberRange.
Hands-on work
Implementation of different web attacks under real conditions on both server and client sides using CyberRange.

5
Application attacks

  • Metasploit: architecture, features, interfaces, workspaces.
  • Exploit writing, shell code generation.


Publication date : 04/05/2024



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.

Dates and locations

Dernières places
Date garantie en présentiel ou à distance
Session garantie
From 2 to 6 November 2026
FR
Remote class
Registration
From 19 to 23 April 2027
FR
Remote class
Registration
From 19 to 23 April 2027
EN
Remote class
Registration
From 16 to 20 August 2027
FR
Remote class
Registration
From 16 to 20 August 2027
EN
Remote class
Registration
From 18 to 22 October 2027
FR
Remote class
Registration
From 18 to 22 October 2027
EN
Remote class
Registration

REMOTE CLASS
2026 : 2 Nov.

2027 : 19 Apr., 19 Apr., 16 Aug., 16 Aug., 18 Oct., 18 Oct.



This programme is an original creation, developed by the teaching teams at ORSYS Formation. Any reproduction, representation, adaptation or use, in whole or in part, without the prior written authorisation of ORSYS, is strictly prohibited. ORSYS reserves the right to take any action necessary to protect its intellectual property rights.