0% found this document useful (0 votes)
10 views2 pages

Penetration Testing Course Overview

The CSC304 Penetration Testing course aims to equip students with skills to conduct penetration tests, identify vulnerabilities, and exploit them using various tools. The curriculum covers scoping, vulnerability scanning, analyzing results, and reporting, along with practical labs on social engineering, network penetration, and web application attacks. Students will also learn to recommend remediation strategies and perform post-report activities.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views2 pages

Penetration Testing Course Overview

The CSC304 Penetration Testing course aims to equip students with skills to conduct penetration tests, identify vulnerabilities, and exploit them using various tools. The curriculum covers scoping, vulnerability scanning, analyzing results, and reporting, along with practical labs on social engineering, network penetration, and web application attacks. Students will also learn to recommend remediation strategies and perform post-report activities.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CSC304:PENETRATION TESTING

L:2 T:0 P:2 Credits:3

Course Outcomes: Through this course students should be able to

CO1 :: understand the scope and gather information to conduct the penetration test

CO2 :: identify the vulnerabilities present in the target and evaluate network traffic

CO3 :: demonstrate proficiency in exploiting vulnerabilities using various tools and techniques

CO4 :: apply wireless network and mobile device vulnerability scanning techniques to identify
security issues

CO5 :: practice system hacking tools and scripts to pivot attacks

CO6 :: deduce the findings by making clear and concise penetration test reports

Unit I
Scoping organizational/customer requirements : define organizational pentesting, acknowledge
compliance requirements, compare standards and methodologies, describe ways to maintain
professionalism
Defining the rules of engagement : assess environmental considerations, outline the rules of
engagement, prepare legal documents
Footprinting and gathering Intelligence : discover the target, gather essential data, compile
website information, discover open-source intelligence tools
Unit II
Evaluating human and physical vulnerabilities : exploit the human psyche, summarize physical
attacks, use tools to launch a social engineering attack
Preparing the vulnerability Scan : plan the vulnerability scan, detect defenses, utilize scanning
tools
Scanning logical vulnerabilities : scan identified targets, evaluate network traffic, uncover wireless
assets
Unit III
Analyzing scanning results : discover NMAP and NSE, enumerate network hosts, analyze output
from scans
Avoiding detection and covering tracks : evade detection, use steganography to hide and
conceal, establish a covert channel
Exploiting the LAN and cloud : enumerating hosts, attack LAN protocols, compare exploit tools,
discover cloud vulnerabilities, explore cloud-based attacks
Unit IV
Testing wireless networks : discover wireless attacks, explore wireless tools

Targeting mobile devices : recognize mobile device vulnerabilities, launch attacks on mobile
devices, outline assessment tools for mobile devices
Attacking specialized systems : identify attacks on the IOT, recognize other vulnerable systems,
explain virtual machine vulnerabilities
Web application-based attacks : recognize web vulnerabilities, launch session attacks, plan
injection attacks, identify tools
Unit V
Performing system hacking : system hacking, use remote access tools, analyze exploit code

Scripting and software development : analyzing scripts and code samples, create logic constructs,
automate penetration testing
Leveraging the attack: pivot and penetrate : test credentials, move throughout the system,
maintain persistence
Communicating during the pentesting process : define the communication path, communication
triggers, use built-in tools for reporting
Unit VI
Summarizing report components : identify report audience, list report contents, define best
practices for reports

Session 2024-25 Page:1/2


Unit VI Recommending remediation : employ technical controls, administrative and operational controls,
physical controls
Performing post-report delivery activities : post-engagement cleanup, follow-up actions

List of Practicals / Experiments:

List of Practicals
• Lab: Performing Social Engineering using SET

• Lab: Discovering Information using Nmap

• Lab: Performing Vulnerability Scans and Analysis

• Lab: Penetrating an Internal Network

• Lab: Exploiting Web Authentication

• Lab: Exploiting Weaknesses in a Website

• Lab: Exploiting Weaknesses in a Database

• Lab: Using SQL Injection

• Lab: Performing an AiTM Attack

• Lab: Performing Password Attacks

• Lab: Using Reverse and Bind Shells

• Lab: Performing Post-Exploitation Activities

• Lab: Establishing Persistence

• Lab: Performing Lateral Movement

References:
1. THE HACKER PLAYBOOK 2: PRACTICAL GUIDE TO PENETRATION TESTING by PETER KIM,
CREATESPACE INDEPENDENT PUBLISHING PLATFORM

Session 2024-25 Page:2/2

You might also like