top of page
EC-Council Ethical Hacking Essentials

EC-Council Ethical Hacking Essentials

Course Code

Duration

ECC-EHE

5 days

About the Course

Ethical Hacking Essentials is an introductory cybersecurity course that covers ethical hacking and penetration testing fundamentals. It offers hands-on experience in computer and network security concepts such as threats, vulnerabilities, password cracking, web applications, and more. No IT/cybersecurity experience is required for course.


Gain hands-on skills through 12 comprehensive modules and 47 labs that simulate real-world scenarios, enabling you to apply concepts, think like an attacker, and confidently apply ethical techniques. Apply and test your skills in real-world CTF capstone challenges that simulate live attacks and build true hacking. Validate these newly acquired skills through proctored exams and earn a globally recognized certification to add to your resume early in your career.


Skill you'll learn in the Ethical Hacking Essentials program


  • Information Security principles such as CIA triad, AAA model, threat vectors, and layered defense strategies, including Zero Trust and Defense-in-Depth.

  • Cryptography fundamentals, including symmetric/assymetric encryption, hash functions, digital signatures, and their role in security systems and data.

  • Threat sources and vulnerability types, identifying motives behind cyberattacks, vectors of exploitation, and their organizational impact.

  • Ethical hacking foundations, including hacker classifications, responsibilities and the full ethical lifecycle from reconnaissance to covering tracks.

  • Attack models and frameworks, utilizing methodologies like Cyber Kill Chain, MITRE ATT&CK, and IoC analysis for understanding adversary behaviour.

  • Malware categories and techniques, including Trojans, worms, viruses, ransomware, spyware, rootkits, and countermeasures against them.

  • Password cracking approaches, covering brute-force, dictionary, and hybrid attacks, supported by tools and defence strategies.

  • Social engineering tactics, such as phishing, SMiShing, fake apps, insider threats, identity theft, and mitigation using SET and other tools.

  • Network-level attack techniques, including sniffing, ARP spoofing, DoS/DDoS, session hijacking, and relevant tools and detection methods.

  • Web and application-layer security, exploring OWASP Top 10 risks, SQL injection types, web server misconfigurations and testing tools.

  • Wireless and Bluetooth attack methods, including rogue APs, MAC spoofing, jamming and mobile security controls like MDM.

  • IoT and OT system vulnerabilities, including device-level threats, IIoT challenges, Purdue Model layers, and botnet-based attcks.

  • Cloud and container security, understanding Docker/Kubernetes, OWASP cloud risks, attacks like cryptojacking and MITC, and security tools.

  • Penetration testing essentials, covering testing types, methodologies, phases, ethical considerations, risk handling, and when to conduct test.


Target Audience


  • High school students, college, and university students.

  • IT, technology, cybersecurity teams with little or no prior work experience.

  • Anyone who wants to start their cybersecurity career and master the fundamentals of security online.

  • Professionals who want to get into the cybersecurity field but are unsure where to start their education journey.

  • Anyone who wants to prepare for a cybersecurity career and aid their IT education.


Course Outline


Module 1: Information Security Fundamentals

  • Overview of information security.

  • Defense strategies in information security.

  • Threats, threat sources, and vulnerabilities.

  • Cryptography concepts.

  • Information security laws, regulations, and standards.


Module 2: Ethical Hacking Fundamentals

  • Hacking concepts and hacker classes.

  • Ethical hacking concepts, scope, and limitations.

  • Phases of hacking cycle.

  • Hacking methodologies and frameworks.


Module 3: Malware Threats and Countermeasures

  • Malware concepts, types, and attack mechanisms.

  • Malware propagation techniques and indicators.

  • Malware countermeasures.

  • Lab Exercises:

    • Create and deploy malware to compromise target systems.

    • Detect, analyze, and remove malware from systems.


Module 4: Ethical Hacking Phase

  • Reconnaissance.

  • Footprinting, and OSINT techniques.

  • Scanning and enumeration methodologies.

  • Vulnerability scanning and assessment concepts.

  • Gaining access, maintaining access, and covering tracks.

  • Countermeasures across hacking phases.

  • Lab Exercises

    • Gather information using advanced Google hacking techniques.

    • Perform DNS footprinting, host discovery, port scanning, and banner grabbing.

    • Perform NetBIOS and SNMP enumeration.

    • Perform vulnerability scanning and exploitation.

    • Perform image steganography.


Module 5: Password Cracking Techniques and Countermeasures

  • Introduction to password cracking

  • Password cracking techniques.

  • Password cracking countermeasures.

  • Lab Exercises

    • Perform password attacks and audit password strength.


Module 6: Social Engineering Techniques and Countermeasures

  • Social engineering concepts.

  • Social engineering techniques.

  • Insider threats and identity theft.

  • Social engineering countermeasures.

  • Lab Exercises

    • Perform social engineering to capture user credentials

    • Detech phishing attacks.


Module 7: Network Level Attacks and Countermeasures

  • Packet sniffing concepts.

  • DoS and DDoS attack methods.

  • Session hijacking techniques and attack methods.

  • Network attack detection and countermeasures.

  • Lab Exercises

    • Perform MAC flooding to compromise the security of network switches.

    • Perform ARP poisoning and detect ARP spoofing attempts.

    • Perform DHCP starvation attack.

    • Launch and defend against DoS/DDoS attacks.

    • Perform and detect session hijacking.


Module 8: Web Application Attacks and Countermeasures

  • Web server attacks.

  • Web application attack techniques and exploitation methods and countermeasures.

  • SQL Injection attacks and countermeasures.

  • Lab Exercises

    • Perform web server and web application attacks.

    • Exploit and detect web application vulnerabilites

    • Peform SQL injection attacks and detection.


Module 9: Wireless Attacks and Countermeasures

  • Introduction to wireless networks.

  • Wireless network security fundamentals.

  • Common wireless attack techniques.

  • Bluetooth threats and wireless security risks.

  • Wireless attack countermeasures.

  • Lab Exercises

    • Analyze wireless network traffic.

    • Perform wireless attacks to compromise network security.


Module 10: Mobile, IoT, and OT Attacks and Countermeasures

  • Mobile attack vectors and vulnerabilities.

  • Mobile device management (MDM) and BYOD security.

  • Mobile attack countermeasures.

  • IoT attacks and countermeasures.

  • OT attacks and countermeasures.

  • Lab Exercises

    • Perform mobile device exploitation and security hardening.

    • Capture and analyze IoT device traffic.


Module 11: Cloud Computing Threats and Countermeasures

  • Cloud and computing concepts.

  • Containerization in cloud computing.

  • Cloud computing threats and attacks.

  • Cloud attack countermeasures.

  • Lab Exercises

    • Perform cloud resource enumeration and exploitation


Module 12: Penetration Testing Fundamentals

  • Introduction to Penetration Testing.

  • Types, phases, and approaches to penetration testing.

  • Guidelines and recommendations for penetration testing.


Exam Details

Pre-requisite: No prior cybersecurity knowledge or IT work experience required.

Exam Code: 112-52

Number of Questions: 75

Duration: 2 hours

Test Format: Multiple choice


Please contact us to schedule your exam, book a private corporate class, or join a public class.



bottom of page