Skip to content

Hands-On Hacking Fundamentals

Description

Name of Training: Hands-On Hacking Fundamentals
Trainer: Orange Cyberdefense Trainers
Dates: November 08-09, 2026
Time: 9:00 am - 5:00 pm
Venue: Exhibition World Bahrain
Cost: 1200 BHD

Important Note: This training is exclusively available to government entities and participants from GCC countries.

1. Short Summary

This introductory hacking course is focused on the fundamentals of the security landscape, how hackers think and the tools, tactics and techniques they use. By the end of the course, you will have a good grasp of how vulnerabilities and exploits work, how attackers think about networks and systems and have compromised several of them from an infrastructure, web application and Wi-Fi perspective.

2. Course Description

Start your journey into information security with a hands-on course that will expose you to the technical fundamentals of penetration testing and security practises in the realms of networking, infrastructure, web applications and wireless technologies.

Key Points

  • How to think like a hacker
  • AI as a tool in cybersecurity
  • Finding vulnerabilities and exploiting them
  • How to approach a pentesting methodology in real world scenarios

This is an introductory course for those starting the journey into penetration testing or those working in environments where understanding how hackers think and the tools, tactics and techniques they use are of essence. Learn how to attack and utilise the concepts to enhance your defensive understandings.

The course presents the background information, technical skills and basic concepts required to those desiring a foundation in the world of information security.

By the end of the course, you will have a good grasp of how vulnerabilities and exploits work, how attackers think about networks and systems, and have compromised several of them, from infrastructure, web applications to Wi-Fi.

Enjoy complementary extended access to our lab environment after completion of the course to revisit and practice the skills you acquired during training.

This course aims to expose you to the methodologies used by active penetration testers on their day-to-day journey with clients and assessments.

Join us and hack hard!

3. Course Outline

Module 1: Introduction To Hacking

3.1 Think like a hacker. Changing the mindset of students into that of an attacker.
3.2 What is Kali Linux.
3.3 Introduction to Linux terminal and common commands
3.4 Common tools and what you will be exposed to.
3.5 Making use of AI as a tool in cybersecurity
3.6 Information Security from a hacker’s perspective.
3.7 Types of threat actors
3.8 Risk and business-related security
3.9 Hacking of history and methodologies.

Practical 1 – Engage the Brain

This practical engages out of the box thinking and picking up on patterns. This allows a student to get into the right mindset to start the hacking journey.

Module 2: Understanding Finding Targets

3.10 Linux 101 – Intro to a terminal.
3.11 What is a target, a vulnerability, and an exploit.
3.12 Introduction to finding targets through OSINT by using public information (Google Dorks/Shodan etc.)
3.13 Understanding the basics of DNS and target identification.
3.14 Footprint techniques and the methodology.
3.15 Tools used to identify and enumerate targets.
3.16 Domain squatting

Practical 2 – Recon & Footprint

Use passive means of gathering information about the target and associated targets. Utilizing AI as a tool to streamline the process of gathering information.

Module 3: Understanding Scanning

3.17 Understanding network communications and the network stack.
3.18 Fingerprinting a target
3.19 Using Nmap as a fingerprinting tool.
3.20 Understanding vulnerability discovery.

Practical 3 – Scanning

Use active means of gathering information through fingerprinting and scanning tools about the identified target. Employing AI as a means to quickly research tool usage and for assistance with unknown command line tools.

Module 4: Understanding Vulnerabilities

3.21 Understanding what a vulnerability is and how it differs from an exploit.
3.22 Automated scanners & the dangers of automation.
3.23 Common mistakes with automated scanner reports.
3.24 Known vulnerabilities and their prevalence.
3.25 Intro to a known vulnerability.

Practical 4 – Identifying a Known Vulnerability

This practical and its objectives allows a student to discover an infamous vulnerability.

Module 5: Understanding Exploits

3.26 What are exploits and where to find them.
3.27 Public exploits (ExploitDB)
3.28 Understanding shells (what is a reverse and what is a bind shell)
3.29 Introduction to the Metasploit Framework.
3.30 Using Metasploit as a place to find public exploits.
3.31 Exploits vs payloads.
3.32 Understanding exploits.
3.33 Understanding the basic hacking methodology.

Practical 5 – Exploiting Known Vulnerabilities

This practical and its objectives allow a student to exploit an infamous vulnerability and transition from simple remote command execution to complete remote control over a target host.

Practical 6 – Exploitation Using Metasploit

As an introduction in using attack frameworks, students get the chance to play with one of the industry's most well-known tools. After learning how to manually identify a vulnerability and exploit it, students are taught how to expedite that process using an exploitation framework.

3.34 Understanding Log4j, what happened and why when this vulnerability was released.
3.35 Diving into how the Log4j vulnerability works.
3.36 An overview of how the exploit takes advantage of the vulnerability.

Practical 7 – Exploiting Log4j

Through knowledge gained thus far, the student will need to identify the vulnerable service and attempt to exploit it using a publicly available exploit to gain complete control over the affected host.

Module 6 – Hacking Web Technologies

3.37 Understanding web applications, Architecture and HTTP protocol.
3.38 Deep understanding of the HTTP Request and Response messages.
3.39 Understanding the risk of web applications.
3.40 Understanding the core functionality of protocols like HTTP and how an attacker would use this.
3.41 What are cookies / encodings.
3.42 Learn about PitM proxies and information gathering. Including the use of Burp to view raw request and response messages.
3.43 OWASP’s Top 10 vulnerability list.
3.44 Finding more information on a specific target - underlying technologies etc.
3.45 What is enumeration and how to use it (WFUZZ, google hacking database)
3.46 Input validation flaws and other common web vulnerabilities.
3.47 Understanding three of the most common web vulnerabilities; how they work, how to find them and how to exploit them.

Practical 8 – Proxies

An introduction into using Person-in-the-Middle (PitM) Proxies. Allows students to explore under the hood of web requests and response.

Practicals 9 & 10 – Finding and Attacking Web Related Vulnerabilities

This hands-on practical session guides students through the discovery and exploitation of web vulnerabilities, with a focus on varying difficulty levels to accommodate both beginners and advanced learners. The aim is to uncover and exploit weaknesses that lead to system compromises and the exfiltration of sensitive information. Among the key vulnerabilities we cover are Insecure Direct Object References (IDOR) and Cross-Site Scripting (XSS).

Module 7 – Wi-Fi Hacking

3.48 What is Wi-Fi, how does it work.
3.49 Understanding Wi-Fi concepts.
3.50 How to monitor traffic and selectively watch for information.
3.51 Capturing someone else's HTTP traffic, and gathering sensitive information.
3.52 Capturing and cracking a Wi-Fi password.

Practicals 11 & 12 – Wi-Fi Exploitation

These practicals are about discovering, intercepting and exploiting wireless networks. Giving students the chance to capture traffic and exploit networks using industry standard toolsets.

Module 8 – Closing Notes and Further Learning

3.53 Continued learning.
3.54 Continued practice.
3.55 The next steps in the career paths for ethical hacking and penetration testing.

4. Difficulty Level

Beginner - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.

5. Suggested Prerequisites

No hacking experience is required for this course; this is a beginner's course. But enthusiasm is a must! It's not necessary, but ideally, some technical background will help, in particular experience with the Windows or Linux command line. However, we're used to meeting students at their level.

6. What Students Should Bring

To fully engage in our courses, students need a computer with a web browser they are comfortable using. All practical exercises are hosted in the cloud, and our class portal delivers course content. This minimal requirement ensures a seamless and effective learning experience.

7. What the Trainer Will Provide

During the training, students will be provided with:

  • Participants in our training courses will get access to a comprehensive set of resources through our user-friendly web class portal, offering educational materials like slides, practical exercises, walkthroughs, tools, and detailed course notes.
  • The portal remains accessible beyond training sessions, allowing learners to revisit content at their own pace. Additionally, each student receives an individualized lab environment, designed for hands-on practical exercises, enhancing their practical skills and proficiency in the subject matter during the training course.

8. Trainer(s) Bio

SensePost, an elite ethical hacking team of Orange Cyberdefense have been training at BlackHat since 2002. We pride ourselves on ensuring our content, our training environment and trainers are all epic in every way possible. The trainers you will meet are working penetration testers, responsible for numerous tools, talks and 0day releases. This provides you with real experiences from the field along with actual practitioners who will be able to support you in a wide range of real-world security discussions. We have years of experience building environments and labs tailored for learning, after all education is at the core of SensePost and Orange Cyberdefense.

9. Registration Terms and Conditions

9.1 Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.

9.2 Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.

9.3 All trainings are non-refundable after October 21, 2026.

9.4 Training tickets may be transferred to another student. Please email us at training@defcon.org for specifics.

9.5 If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).

9.6 Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.

9.7 DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.

9.8 By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.

Sale price 1,200 BD

Options
Back to top