Course Overview
Cyber threats continue to evolve in sophistication and scale, making proactive security testing a critical component of modern cybersecurity strategies. Organisations must be able to identify vulnerabilities before malicious actors exploit them, and ethical hacking provides a structured approach to assessing and strengthening security controls. Ethical hackers use the same techniques and tools as attackers, but within authorised and controlled environments to improve organisational resilience and security posture.
The CEH: Certified Ethical Hacker v12 Programme by Transformentors Academy provides participants with a comprehensive understanding of ethical hacking methodologies, penetration testing concepts, and vulnerability assessment techniques. The programme explores the complete ethical hacking lifecycle, from reconnaissance and information gathering to vulnerability identification, exploitation concepts, and remediation strategies.
Through practical exercises, demonstrations, and real-world scenarios, participants will examine network security, system vulnerabilities, web application security, wireless networks, malware threats, and emerging technologies such as IoT and Operational Technology (OT) environments. The programme also emphasises ethical responsibilities, legal considerations, and best practices for conducting security assessments in a professional environment.
By the end of the programme, participants will be equipped with the knowledge and skills required to identify security weaknesses, assess organisational risks, recommend mitigation measures, and contribute effectively to strengthening cybersecurity defences.
Agenda
Day — 1 Introduction to Ethical Hacking
- Understanding the definition, purpose, and importance of ethical hacking in cybersecurity.
- Exploring the role of ethical hacking in identifying vulnerabilities and strengthening organisational security.
- Understanding the roles, responsibilities, and professional ethics of ethical hackers.
- Examining the core concepts and methodologies used in ethical hacking engagements.
- Understanding the fundamental elements of information security, including confidentiality, integrity, and availability.
- Reviewing key laws, regulations, and legal considerations related to ethical hacking activities.
- Exploring cloud computing concepts and understanding common cloud security risks and challenges.
- Introducing cryptography concepts, ciphers, encryption methods, and secure communication protocols.
Day — 2 Reconnaissance Techniques
- Understanding the purpose of reconnaissance and information gathering in ethical hacking assessments.
- Exploring footprinting concepts and techniques used to collect publicly available information about target environments.
- Examining common footprinting and reconnaissance tools used in security assessments.
- Understanding the steps involved in conducting footprinting activities on a target network.
- Exploring network scanning methods used to identify hosts, services, ports, and network configurations.
- Reviewing common network scanning tools and their practical applications.
- Understanding techniques used to identify systems beyond firewalls and intrusion detection systems (IDS).
- Exploring enumeration concepts, tools, and techniques for gathering detailed information from target systems and services.
- Understanding how reconnaissance findings support vulnerability assessment and security testing activities.
- Practical Exercise: Applying reconnaissance, footprinting, scanning, and enumeration techniques in a controlled environment.
Day — 3 System Hacking Phases and Attack Techniques
- Understanding the process of vulnerability research and security analysis.
- Identifying common vulnerabilities and security weaknesses within systems and networks.
- Exploring methodologies used to assess and validate potential security exposures.
- Understanding the phases of system hacking and how vulnerabilities may be exploited in authorised security assessments.
- Examining techniques used to identify security loopholes in target environments.
- Exploring different types of malware and their impact on systems, networks, and business operations.
- Understanding malware behaviours, infection methods, and propagation techniques.
- Learning the principles and processes of malware analysis within a controlled environment.
- Exploring countermeasures and defensive strategies for detecting, preventing, and mitigating malware threats.
- Reviewing system auditing practices and security monitoring techniques used to identify malware-related incidents and suspicious activities.
Day — 4 Network and Perimeter Hacking
- Understanding network security concepts and common vulnerabilities within network infrastructures.
- Exploring packet-sniffing concepts and their role in identifying network security weaknesses.
- Understanding how network traffic analysis supports vulnerability assessment and security monitoring.
- Defining social engineering and examining common social engineering attack techniques.
- Exploring different types of social engineering attacks and their impact on organisations.
- Identifying effective defence strategies and awareness measures against social engineering threats.
- Understanding the principles, risks, and business impact of Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks.
- Exploring session hijacking concepts, common attack techniques, and associated security risks.
- Understanding best practices for securing session management and protecting user communications.
- Examining how security controls such as Intrusion Detection Systems (IDS), firewalls, and honeypots are used to protect networks.
- Understanding common techniques attackers may use to bypass security controls and the defensive measures organisations can implement to strengthen protection.
Day — 5 Hacking of Web Applications, Wireless Networks, Mobile Platforms, IoT and OT
- Understanding common web server and web application attacks and their countermeasures.
- Exploring SQL injection attacks and vulnerability detection techniques.
- Understanding wireless security, encryption methods, and wireless attack concepts.
- Applying best practices to secure Wi-Fi and wireless networks.
- Identifying common attack vectors targeting mobile devices and applications.
- Exploring techniques for improving mobile platform security.
- Understanding security risks affecting IoT and Operational Technology (OT) environments.
- Reviewing common IoT and OT attack methods and defensive measures.
- Examining tools and techniques used in security assessments of web, wireless, mobile, IoT, and OT systems.
Learning Outcomes
By the end of this programme, participants will be able to:
- Understand the role and importance of ethical hacking in modern cybersecurity practices.
- Recognise the legal, ethical, and regulatory considerations associated with ethical hacking activities.
- Apply reconnaissance, footprinting, scanning, and enumeration techniques to gather information about target environments.
- Understand the phases of system hacking, including vulnerability identification, access acquisition, and exploitation concepts.
- Conduct vulnerability assessments and analyse security weaknesses within systems and networks.
- Identify common malware threats and understand techniques used in malware analysis and detection.
- Understand network attack methodologies, including packet sniffing, social engineering, and denial-of-service attack techniques.
- Assess security vulnerabilities affecting web servers, web applications, wireless networks, and mobile platforms.
- Recognise security risks associated with Internet of Things (IoT) and Operational Technology (OT) environments.
- Recommend appropriate mitigation strategies and security controls to strengthen organisational cyber resilience.
Who Should Attend
This programme is designed for cybersecurity and information security professionals responsible for protecting systems, networks, applications, and organisational assets, including:
- Mid-Level Information Security Auditors.
- Cybersecurity Auditors.
- Security Administrators and IT Security Administrators.
- Cyber Defence Analysts and Warning Analysts.
- Information Security Analysts and Security Analysts.
- Cybersecurity Analysts and SOC Analysts.
- Infosec Security Administrators.
- Network Security Engineers and Network Engineers.
- Senior Security Consultants and Cybersecurity Consultants.
- Information Security Managers.
- Solution Architects and Security Architects.
- Professionals involved in vulnerability assessment, security monitoring, incident response, and cyber risk management.