🏫 Programming & Software Development

Digital Forensic and Ethical Hacking

Master the Red vs. Blue lifecycle: from Active Directory compromise to digital forensic investigation, mapped to MITRE ATT&CK

Duration

Weekly Hours

4 Hours

M

Course Incharge

Muzammil Bilwani

Digital Forensic and Ethical Hacking

📋 Prerequisites

Intermediate IT knowledge, Networking fundamentals (TCP/IP), and basic Linux/Windows CLI experience

📖 Course Description

A 20-week, industry-aligned track blending offensive security (Ethical Hacking) with defensive investigation (Digital Forensics), mapped throughout to the MITRE ATT&CK framework. Students learn to think like an adversary, breaching perimeters, escalating privileges, and compromising Active Directory, then switch to the Blue Team to acquire memory, recover deleted data, and perform malware analysis. The program closes with a live Red-vs-Blue Capture-The-Flag capstone and a professional forensic case report, preparing graduates for Penetration Tester, SOC Analyst, and Digital Forensics roles, and for certifications such as OSCP, CEH, and GCFA.

What You Will Learn

Execute Red Team tactics across the full attack lifecycle: Reconnaissance, Exploitation, and Active Directory compromise

Master Blue Team skills: Memory Forensics, Disk Imaging, and Network Forensics

Attack and defend Enterprise environments including Active Directory, Kerberos, and BloodHound attack paths

Perform Static and Dynamic Malware Analysis using Ghidra and behavioral analysis techniques

Implement Incident Response playbooks, MITRE ATT&CK mapping, and maintain Chain of Custody

Utilize industry-standard tools: Metasploit, Burp Suite, Volatility 3, Autopsy, and BloodHound/Impacket

Course Outline

1

Ethical Hacking Foundations & Rules of Engagement

  • Ethics & Legal Boundaries: Scope of Work (SoW), Rules of Engagement, and relevant cyber law
  • Penetration Testing Methodologies: PTES, OSSTMM, and the Cyber Kill Chain
  • Reporting Fundamentals: Structuring a professional penetration test report
  • MITRE ATT&CK for Offense: Mapping attacker tactics and techniques to a common framework
  • Hands-on: Draft a Scope of Work and Rules of Engagement document for a simulated client engagement
2

Kali Linux & Attack Lab Build-Out

  • Lab Architecture: Virtualization with VirtualBox/VMware and network isolation
  • Attack Platform Setup: Kali Linux, Parrot Security, and vulnerable targets (Metasploitable)
  • Essential Tooling: Navigating Kali Linux toolset and package management
  • Snapshotting & Safety: Isolated Host-Only networks and safe lab practices
  • Hands-on: Build a multi-OS virtual attack lab with isolated snapshots ready for engagement
3

OS Internals for Offense & Defense

  • Windows Internals: Registry, LSASS, and the SAM database
  • Linux Internals: Kernel, /proc, and syslog architecture
  • Command-Line Tradecraft: Advanced Bash and PowerShell for security work
  • Living-off-the-Land: Using native OS tools during assessments
  • Hands-on: Write a script to audit and harden a target system by reviewing services and permissions
4

Passive Reconnaissance & OSINT

  • OSINT Methodology: Google Dorking, Shodan, and public-record intelligence gathering
  • Target Profiling: Building an accurate footprint without touching the target
  • Automated Recon: Using theHarvester for email and subdomain discovery
  • Cyber Kill Chain: Mapping reconnaissance to the first stage of an attack
  • Hands-on: Perform a full passive OSINT engagement on a target organization using theHarvester and Shodan
5

Active Scanning with Nmap

  • Scanning Fundamentals: Active vs. passive scanning approaches
  • Stealth Techniques: Evasive Nmap scan types and timing controls
  • Nmap Scripting Engine (NSE): Automating service and vulnerability discovery
  • Service Fingerprinting: Identifying software versions and OS flavors
  • Hands-on: Perform a stealthy Nmap scan of a target network without triggering basic intrusion detection
6

Enumeration Techniques

  • Service Enumeration: Extracting valuable data from SMB, FTP, and web services
  • Windows Enumeration: NetBIOS and enum4linux for share and user discovery
  • User & Group Discovery: Identifying accounts and privilege structures
  • Documentation: Structuring enumeration findings for the next assessment phase
  • Hands-on: Enumerate a target network using enum4linux and NetBIOS tools to map users and shares
7

Vulnerability Assessment & Management

  • Assessment Methodology: Structured vulnerability assessment workflows
  • Scanning at Scale: Using Nessus Essentials for automated vulnerability discovery
  • Vulnerability Research: Cross-referencing findings with Searchsploit and the CVE database
  • Risk Prioritization: Scoring and ranking vulnerabilities by exploitability and impact
  • Hands-on: Run a full Nessus scan against a lab network and produce a prioritized vulnerability report
8

Network Traffic Manipulation & MITM

  • Man-in-the-Middle Attacks: ARP poisoning and DNS spoofing techniques
  • Packet Crafting: Building custom packets with Scapy
  • Traffic Analysis: Using Wireshark to identify clear-text credentials in a capture
  • SSL Stripping: Understanding certificate-based attack and defense
  • Hands-on: Intercept and analyze live lab traffic with Wireshark to harvest exposed credentials
9

Web App Basics & Architecture

  • Modern Web Architecture: Client-server models, APIs, and session state
  • Vulnerable-by-Design Practice: Working with DVWA to explore common flaws
  • HTTP Deep-Dive: Requests, responses, headers, and cookies
  • Reporting: Structuring web application findings for a client report
  • Hands-on: Explore DVWA from Low to Medium security levels and document each vulnerability class
10

SQL Injection & Database Attacks

  • Database-Driven Attacks: Understanding how SQL Injection compromises back-end data
  • Exploitation Practice: Automating discovery and extraction with SQLMap
  • Secure Development: Parameterized queries and input validation as mitigation
  • Reporting: Documenting SQLi findings with remediation guidance
  • Hands-on: Use SQLMap to identify and exploit a SQL Injection vulnerability in a guided lab
11

Cross-Site Scripting & Client-Side Attacks

  • XSS Fundamentals: Reflected, stored, and DOM-based Cross-Site Scripting
  • Session Hijacking: Exploiting cookies and session tokens
  • Defensive Coding: Output encoding and Content Security Policy (CSP)
  • Client-Side Attack Chains: Combining XSS with phishing for real-world impact
  • Hands-on: Exploit reflected and stored XSS vulnerabilities and demonstrate session hijacking
12

Burp Suite Mastery

  • Traffic Interception: Configuring Burp Suite as a testing proxy
  • Repeater & Intruder: Manipulating and automating request testing
  • Extensions & Automation: Extending Burp Suite for efficient assessments
  • Reporting Workflow: Moving from Burp findings to a client-ready report
  • Hands-on: Use Burp Suite Community Edition to intercept, manipulate, and exploit a vulnerable web application
13

Password Security & Credential Attacks

  • Password Security Fundamentals: Hashing, salting, and storage best practices
  • Offline Cracking: Using Hashcat and John the Ripper for credential recovery
  • Credential Harvesting: Memory-based extraction concepts (Mimikatz)
  • Defense: Multi-factor authentication and credential-attack mitigation
  • Hands-on: Crack a set of captured password hashes using Hashcat and John the Ripper
14

Metasploit & Payload Engineering

  • Metasploit Framework: Modules, exploits, payloads, and encoders
  • Payload Engineering: Building custom payloads with MSFVenom
  • Evasion Basics: Bypassing basic antivirus and endpoint defenses
  • Post-Exploitation: Meterpreter commands and session management
  • Hands-on: Deploy a Meterpreter shell on a remote lab target and practice post-exploitation commands
15

Windows & Linux Privilege Escalation

  • Windows Privilege Escalation: Misconfigured services, tokens, and WinPEAS
  • Linux Privilege Escalation: SUID binaries, cron jobs, and LinPEAS
  • Kernel Exploits: Understanding when and how kernel-level escalation applies
  • Mitigation: Hardening checklists to close common escalation paths
  • Hands-on: Escalate privileges from a standard user to admin/root on Windows and Linux lab targets
16

Active Directory Attacks

  • Active Directory Fundamentals: Domain Controllers, Forests, and Kerberos authentication
  • AD Recon: Mapping attack paths with BloodHound
  • Credential Attacks: Kerberoasting, AS-REP Roasting, and Pass-the-Hash
  • Enterprise Defense: Detecting and mitigating common AD attack chains
  • Hands-on: Map and execute an attack path from a standard domain user to Domain Admin using BloodHound and Impacket
17

Wireless Security Attacks

  • Wireless Threat Landscape: WEP, WPA2, and WPA3 attack surfaces
  • Handshake Capture: Using Aircrack-ng to capture and crack WPA2 handshakes
  • Rogue Access Points: Evil twin and deauthentication attack techniques
  • Reporting: Documenting wireless assessment findings and remediation
  • Hands-on: Capture and crack a WPA2 handshake with Aircrack-ng, then document the attack path
18

Digital Forensics Fundamentals & Evidence Acquisition

  • Forensics Lifecycle: Order of Volatility and evidence-handling principles
  • Chain of Custody: Legal requirements and evidence hashing (MD5/SHA-256)
  • Evidence Acquisition: RAM capture and disk imaging with FTK Imager
  • Case Management: Setting up and organizing an investigation in Autopsy
  • Hands-on: Perform a live RAM and disk acquisition, hash the evidence, and document chain of custody
19

Memory, Malware & Network Forensics

  • Memory Forensics: Analyzing RAM dumps with Volatility 3 (psscan, netscan, malfind)
  • Malware Analysis: Static and dynamic analysis fundamentals, with an introduction to Ghidra
  • Network Forensics: Reconstructing an attack timeline from PCAP data
  • Threat Detection: Automating analysis with Zeek and RITA
  • Hands-on: Use Volatility 3 to uncover a hidden process and C2 connection in a memory image, then trace it through network logs
20

Incident Response, Case Reporting & Capstone CTF

  • Incident Response: The six-stage IR lifecycle from Preparation to Lessons Learned
  • Case Reporting: Writing a professional forensic report for legal/corporate use
  • Capstone CTF: A full Red vs. Blue simulation, breach a system, then investigate your own tracks
  • Career Readiness: Certification pathways (OSCP, GCFA, CEH) and portfolio building
  • Hands-on: Complete the Capstone CTF, then submit and present a full exploitation-to-forensics case report

📊 Grading Criteria

ComponentPercentage
Quizzes20%
Class Participation / Attendance15%
Projects25%
Final Projects40%
Total100%

Ready to Register in This Course?

Join thousands of students who have transformed their careers. Start your journey today!