This programme prepares participants to understand and apply ethical hacking methodologies used by professional penetration testers and security analysts. Covering the full CEH v13 body of knowledge, participants will learn how attackers think, how to identify vulnerabilities before they are exploited, and how to report findings to stakeholders. Aligned with EC-Council CEH v13 exam objectives.
HRD Corp SBL-Khas Claimable
Introduction to Ethical Hacking
Hacking phases, attack types, threat actors, and the legal and ethical framework governing penetration testing in Malaysia and globally.
Footprinting and Reconnaissance
Passive and active information gathering techniques. Open-source intelligence (OSINT), Google dorking, DNS enumeration, and social engineering basics.
Scanning Networks
Network scanning methodologies, port scanning, OS fingerprinting, and vulnerability identification using tools such as Nmap and Nessus.
Enumeration
Extracting system information including usernames, network shares, services, and security configurations from target systems.
Vulnerability Analysis
Identifying and classifying vulnerabilities using scoring frameworks (CVSS) and vulnerability databases. Hands-on use of scanning tools.
System Hacking
Password cracking, privilege escalation, maintaining access, and covering tracks. Understanding attacker techniques to build better defences.
Malware Threats
Types of malware including viruses, ransomware, trojans, and spyware. How malware spreads, executes, and how to detect and mitigate infections.
Sniffing and Session Hijacking
Network sniffing techniques, ARP poisoning, session token theft, and countermeasures for securing network communications.
Social Engineering
Human manipulation tactics used in attacks. Phishing, vishing, pretexting, and building organisational defences against social engineering.
Web Application Hacking
OWASP Top 10 vulnerabilities, SQL injection, cross-site scripting (XSS), and web application attack and defence techniques.
Wireless Network Hacking
Wi-Fi security weaknesses, WPA2 cracking, rogue access points, and securing corporate wireless networks.
Cryptography
Encryption algorithms, PKI basics, hashing, digital signatures, and common cryptographic attacks.
Capture the Flag (CTF) Exercise. Participants complete a structured ethical hacking challenge on a simulated lab environment, applying skills from all modules to identify, exploit, and document vulnerabilities in a controlled setting.
Fee RM 2,500 per participant
Minimum enrolment 3 participants
Duration 5 Days
Level Intermediate (basic networking and IT knowledge required)
HRD Corp Claimable Yes
Certificate included Yes
Note Exam voucher for CEH v13 certification exam is not included in the training fee. Participants may purchase the exam voucher separately through EC-Council.