{"product_id":"hands-on-hacking-fundamentals","title":"Hands-On Hacking Fundamentals","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Hands-On Hacking Fundamentals\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Orange Cyberdefense Trainers\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eThis introductory hacking course is focused on the fundamentals of the security landscape, how hackers think and the tools, tactics and techniques they use. By the end of the course, you will have a good grasp of how vulnerabilities and exploits work, how attackers think about networks and systems and have compromised several of them from an infrastructure, web application and Wi-Fi perspective.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eStart your journey into information security with a hands-on course that will expose you to the technical fundamentals of penetration testing and security practises in the realms of networking, infrastructure, web applications and wireless technologies.\u003c\/p\u003e\n\u003ch3\u003eKey Points\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHow to think like a hacker\u003c\/li\u003e\n\u003cli\u003eAI as a tool in cybersecurity\u003c\/li\u003e\n\u003cli\u003eFinding vulnerabilities and exploiting them\u003c\/li\u003e\n\u003cli\u003eHow to approach a pentesting methodology in real world scenarios\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eThis is an introductory course for those starting the journey into penetration testing or those working in environments where understanding how hackers think and the tools, tactics and techniques they use are of essence. Learn how to attack and utilise the concepts to enhance your defensive understandings.\u003c\/p\u003e\n\u003cp\u003eThe course presents the background information, technical skills and basic concepts required to those desiring a foundation in the world of information security.\u003c\/p\u003e\n\u003cp\u003eBy the end of the course, you will have a good grasp of how vulnerabilities and exploits work, how attackers think about networks and systems, and have compromised several of them, from infrastructure, web applications to Wi-Fi.\u003c\/p\u003e\n\u003cp\u003eEnjoy complementary extended access to our lab environment after completion of the course to revisit and practice the skills you acquired during training.\u003c\/p\u003e\n\u003cp\u003eThis course aims to expose you to the methodologies used by active penetration testers on their day-to-day journey with clients and assessments.\u003c\/p\u003e\n\u003cp\u003eJoin us and hack hard!\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eModule 1: Introduction To Hacking\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.1\u003c\/strong\u003e Think like a hacker. Changing the mindset of students into that of an attacker.\u003cbr\u003e\u003cstrong\u003e3.2\u003c\/strong\u003e What is Kali Linux.\u003cbr\u003e\u003cstrong\u003e3.3\u003c\/strong\u003e Introduction to Linux terminal and common commands\u003cbr\u003e\u003cstrong\u003e3.4\u003c\/strong\u003e Common tools and what you will be exposed to.\u003cbr\u003e\u003cstrong\u003e3.5\u003c\/strong\u003e Making use of AI as a tool in cybersecurity\u003cbr\u003e\u003cstrong\u003e3.6\u003c\/strong\u003e Information Security from a hacker’s perspective.\u003cbr\u003e\u003cstrong\u003e3.7\u003c\/strong\u003e Types of threat actors\u003cbr\u003e\u003cstrong\u003e3.8\u003c\/strong\u003e Risk and business-related security\u003cbr\u003e\u003cstrong\u003e3.9\u003c\/strong\u003e Hacking of history and methodologies.\u003c\/p\u003e\n\u003ch3\u003ePractical 1 – Engage the Brain\u003c\/h3\u003e\n\u003cp\u003eThis practical engages out of the box thinking and picking up on patterns. This allows a student to get into the right mindset to start the hacking journey.\u003c\/p\u003e\n\u003ch3\u003eModule 2: Understanding Finding Targets\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.10\u003c\/strong\u003e Linux 101 – Intro to a terminal.\u003cbr\u003e\u003cstrong\u003e3.11\u003c\/strong\u003e What is a target, a vulnerability, and an exploit.\u003cbr\u003e\u003cstrong\u003e3.12\u003c\/strong\u003e Introduction to finding targets through OSINT by using public information (Google Dorks\/Shodan etc.)\u003cbr\u003e\u003cstrong\u003e3.13\u003c\/strong\u003e Understanding the basics of DNS and target identification.\u003cbr\u003e\u003cstrong\u003e3.14\u003c\/strong\u003e Footprint techniques and the methodology.\u003cbr\u003e\u003cstrong\u003e3.15\u003c\/strong\u003e Tools used to identify and enumerate targets.\u003cbr\u003e\u003cstrong\u003e3.16\u003c\/strong\u003e Domain squatting\u003c\/p\u003e\n\u003ch3\u003ePractical 2 – Recon \u0026amp; Footprint\u003c\/h3\u003e\n\u003cp\u003eUse passive means of gathering information about the target and associated targets. Utilizing AI as a tool to streamline the process of gathering information.\u003c\/p\u003e\n\u003ch3\u003eModule 3: Understanding Scanning\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.17\u003c\/strong\u003e Understanding network communications and the network stack.\u003cbr\u003e\u003cstrong\u003e3.18\u003c\/strong\u003e Fingerprinting a target\u003cbr\u003e\u003cstrong\u003e3.19\u003c\/strong\u003e Using Nmap as a fingerprinting tool.\u003cbr\u003e\u003cstrong\u003e3.20\u003c\/strong\u003e Understanding vulnerability discovery.\u003c\/p\u003e\n\u003ch3\u003ePractical 3 – Scanning\u003c\/h3\u003e\n\u003cp\u003eUse active means of gathering information through fingerprinting and scanning tools about the identified target. Employing AI as a means to quickly research tool usage and for assistance with unknown command line tools.\u003c\/p\u003e\n\u003ch3\u003eModule 4: Understanding Vulnerabilities\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.21\u003c\/strong\u003e Understanding what a vulnerability is and how it differs from an exploit.\u003cbr\u003e\u003cstrong\u003e3.22\u003c\/strong\u003e Automated scanners \u0026amp; the dangers of automation.\u003cbr\u003e\u003cstrong\u003e3.23\u003c\/strong\u003e Common mistakes with automated scanner reports.\u003cbr\u003e\u003cstrong\u003e3.24\u003c\/strong\u003e Known vulnerabilities and their prevalence.\u003cbr\u003e\u003cstrong\u003e3.25\u003c\/strong\u003e Intro to a known vulnerability.\u003c\/p\u003e\n\u003ch3\u003ePractical 4 – Identifying a Known Vulnerability\u003c\/h3\u003e\n\u003cp\u003eThis practical and its objectives allows a student to discover an infamous vulnerability.\u003c\/p\u003e\n\u003ch3\u003eModule 5: Understanding Exploits\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.26\u003c\/strong\u003e What are exploits and where to find them.\u003cbr\u003e\u003cstrong\u003e3.27\u003c\/strong\u003e Public exploits (ExploitDB)\u003cbr\u003e\u003cstrong\u003e3.28\u003c\/strong\u003e Understanding shells (what is a reverse and what is a bind shell)\u003cbr\u003e\u003cstrong\u003e3.29\u003c\/strong\u003e Introduction to the Metasploit Framework.\u003cbr\u003e\u003cstrong\u003e3.30\u003c\/strong\u003e Using Metasploit as a place to find public exploits.\u003cbr\u003e\u003cstrong\u003e3.31\u003c\/strong\u003e Exploits vs payloads.\u003cbr\u003e\u003cstrong\u003e3.32\u003c\/strong\u003e Understanding exploits.\u003cbr\u003e\u003cstrong\u003e3.33\u003c\/strong\u003e Understanding the basic hacking methodology.\u003c\/p\u003e\n\u003ch3\u003ePractical 5 – Exploiting Known Vulnerabilities\u003c\/h3\u003e\n\u003cp\u003eThis practical and its objectives allow a student to exploit an infamous vulnerability and transition from simple remote command execution to complete remote control over a target host.\u003c\/p\u003e\n\u003ch3\u003ePractical 6 – Exploitation Using Metasploit\u003c\/h3\u003e\n\u003cp\u003eAs an introduction in using attack frameworks, students get the chance to play with one of the industry's most well-known tools. After learning how to manually identify a vulnerability and exploit it, students are taught how to expedite that process using an exploitation framework.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.34\u003c\/strong\u003e Understanding Log4j, what happened and why when this vulnerability was released.\u003cbr\u003e\u003cstrong\u003e3.35\u003c\/strong\u003e Diving into how the Log4j vulnerability works.\u003cbr\u003e\u003cstrong\u003e3.36\u003c\/strong\u003e An overview of how the exploit takes advantage of the vulnerability.\u003c\/p\u003e\n\u003ch3\u003ePractical 7 – Exploiting Log4j\u003c\/h3\u003e\n\u003cp\u003eThrough knowledge gained thus far, the student will need to identify the vulnerable service and attempt to exploit it using a publicly available exploit to gain complete control over the affected host.\u003c\/p\u003e\n\u003ch3\u003eModule 6 – Hacking Web Technologies\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.37\u003c\/strong\u003e Understanding web applications, Architecture and HTTP protocol.\u003cbr\u003e\u003cstrong\u003e3.38\u003c\/strong\u003e Deep understanding of the HTTP Request and Response messages.\u003cbr\u003e\u003cstrong\u003e3.39\u003c\/strong\u003e Understanding the risk of web applications.\u003cbr\u003e\u003cstrong\u003e3.40\u003c\/strong\u003e Understanding the core functionality of protocols like HTTP and how an attacker would use this.\u003cbr\u003e\u003cstrong\u003e3.41\u003c\/strong\u003e What are cookies \/ encodings.\u003cbr\u003e\u003cstrong\u003e3.42\u003c\/strong\u003e Learn about PitM proxies and information gathering. Including the use of Burp to view raw request and response messages.\u003cbr\u003e\u003cstrong\u003e3.43\u003c\/strong\u003e OWASP’s Top 10 vulnerability list.\u003cbr\u003e\u003cstrong\u003e3.44\u003c\/strong\u003e Finding more information on a specific target - underlying technologies etc.\u003cbr\u003e\u003cstrong\u003e3.45\u003c\/strong\u003e What is enumeration and how to use it (WFUZZ, google hacking database)\u003cbr\u003e\u003cstrong\u003e3.46\u003c\/strong\u003e Input validation flaws and other common web vulnerabilities.\u003cbr\u003e\u003cstrong\u003e3.47\u003c\/strong\u003e Understanding three of the most common web vulnerabilities; how they work, how to find them and how to exploit them.\u003c\/p\u003e\n\u003ch3\u003ePractical 8 – Proxies\u003c\/h3\u003e\n\u003cp\u003eAn introduction into using Person-in-the-Middle (PitM) Proxies. Allows students to explore under the hood of web requests and response.\u003c\/p\u003e\n\u003ch3\u003ePracticals 9 \u0026amp; 10 – Finding and Attacking Web Related Vulnerabilities\u003c\/h3\u003e\n\u003cp\u003eThis hands-on practical session guides students through the discovery and exploitation of web vulnerabilities, with a focus on varying difficulty levels to accommodate both beginners and advanced learners. The aim is to uncover and exploit weaknesses that lead to system compromises and the exfiltration of sensitive information. Among the key vulnerabilities we cover are Insecure Direct Object References (IDOR) and Cross-Site Scripting (XSS).\u003c\/p\u003e\n\u003ch3\u003eModule 7 – Wi-Fi Hacking\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.48\u003c\/strong\u003e What is Wi-Fi, how does it work.\u003cbr\u003e\u003cstrong\u003e3.49\u003c\/strong\u003e Understanding Wi-Fi concepts.\u003cbr\u003e\u003cstrong\u003e3.50\u003c\/strong\u003e How to monitor traffic and selectively watch for information.\u003cbr\u003e\u003cstrong\u003e3.51\u003c\/strong\u003e Capturing someone else's HTTP traffic, and gathering sensitive information.\u003cbr\u003e\u003cstrong\u003e3.52\u003c\/strong\u003e Capturing and cracking a Wi-Fi password.\u003c\/p\u003e\n\u003ch3\u003ePracticals 11 \u0026amp; 12 – Wi-Fi Exploitation\u003c\/h3\u003e\n\u003cp\u003eThese practicals are about discovering, intercepting and exploiting wireless networks. Giving students the chance to capture traffic and exploit networks using industry standard toolsets.\u003c\/p\u003e\n\u003ch3\u003eModule 8 – Closing Notes and Further Learning\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003e3.53\u003c\/strong\u003e Continued learning.\u003cbr\u003e\u003cstrong\u003e3.54\u003c\/strong\u003e Continued practice.\u003cbr\u003e\u003cstrong\u003e3.55\u003c\/strong\u003e The next steps in the career paths for ethical hacking and penetration testing.\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eNo hacking experience is required for this course; this is a beginner's course. But enthusiasm is a must! It's not necessary, but ideally, some technical background will help, in particular experience with the Windows or Linux command line. However, we're used to meeting students at their level.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cp\u003eTo fully engage in our courses, students need a computer with a web browser they are comfortable using. All practical exercises are hosted in the cloud, and our class portal delivers course content. This minimal requirement ensures a seamless and effective learning experience.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eDuring the training, students will be provided with:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eParticipants in our training courses will get access to a comprehensive set of resources through our user-friendly web class portal, offering educational materials like slides, practical exercises, walkthroughs, tools, and detailed course notes.\u003c\/li\u003e\n\u003cli\u003eThe portal remains accessible beyond training sessions, allowing learners to revisit content at their own pace. Additionally, each student receives an individualized lab environment, designed for hands-on practical exercises, enhancing their practical skills and proficiency in the subject matter during the training course.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003cp\u003eSensePost, an elite ethical hacking team of Orange Cyberdefense have been training at BlackHat since 2002. We pride ourselves on ensuring our content, our training environment and trainers are all epic in every way possible. The trainers you will meet are working penetration testers, responsible for numerous tools, talks and 0day releases. This provides you with real experiences from the field along with actual practitioners who will be able to support you in a wide range of real-world security discussions. We have years of experience building environments and labs tailored for learning, after all education is at the core of SensePost and Orange Cyberdefense.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942347153651,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/SensePost-Training-Logo-White.png?v=1786560356","url":"https:\/\/me.shop.defcon.org\/products\/hands-on-hacking-fundamentals","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}