CEH - Notes
This is a chapter-wise index for Certified Ethical Hacker topics, linking to notes in this vault.
01. Introduction to Ethical Hacking
- Ethical Hacking
- Penetration Testing
- Vulnerability Assessment vs Penetration Testing
- Red Team vs Blue Team
- Information Security
- CIA Triad
- Risk Assessment
- Threat Modeling
- Security Policies
- Compliance Frameworks
- NIST Cybersecurity Framework
- ISO 27001
- PCI DSS
- GDPR
- Advanced Persistence Threat
- Advanced Persistence Threat/Lifecycle
- Cyber Threat Intelligence
- Indicators of Compromise
- MITRE ATT&CK Framework
- Cyber Killchain
- Hunting
- Response
- Digital Forensics
- Browser Forensics
- HDD Forensics
- Photo Forensics
- Email Forensics
02. Footprinting and Reconnaissance
- Information Gathering
- Footprinting - Countermeasures
- Active Reconnaissance
- banner grabbing
- Subdomain enumeration
- Open Source Intelligence
- Passive Reconnaissance
- Footprinting - Example Script
- Footprinting through Professional Sites
- Passive Reconnaissance - Business Activities
- whois
- DNS - Tools
- dnsrecon
- dnsenum
- fierce
- FinalRecon
- Infoga
- Maltego
- net/sec/amass
- net/sec/tools/theharvester
- netcraft
- recon-ng
- Recon-Dog
- Spiderfoot
- Taranis
- OSINT - Facebook
03. Scanning Networks
- metasploit - port scan
- metasploit - network scanning
- net/sec/tools/nmap
- nmap flags
- nmap - output
- nmap - port scan outputs
- nmap - syn scan
- net/sec/tools/nmap - Full-Open Scan
- net/sec/tools/nmap - evading firewalls, IDS, IPS
- Nmap Scripting Engine
- hping3
- Unicornscan
- Network Scanning Tools
- Host-level scanning
- Firewalking
- Idle Scan
- Xmas Scan
- TCP Maimon Scan
- Inverse TCP Scan
04. Enumeration
- network enumeration
- Subdomain enumeration
- enum4linux
- dirb
- net/sec/tools/gobuster
- nikto
- ffuf
- Netbios
- nbtstat
- NETBIOS Session Service
- net/windows/Server Message Block
- smbmap
- net/windows/tools/smbclient
- net/protocols/Simple Network Management Protocol
- snmpwalk
- Lightweight Directory Access Protocol
- ldapsearch
- rpcclient
- xmlrpc
- Active Directory
- Domain Controller
- LDAP
- SMB
- RDP
05. Vulnerability Analysis
- Vulnerability Assessment
- Vulnerability Assessment Tools
- Vulnerability Assessment Report
- Vulnerability-Management Life Cycle
- CVSS
- CVSS - metrics
- CVE
- Nessus
- openvas
- Qualys
- burpsuite
- Host-Based Vulnerability Assessment Tools
- Application-Layer Vulnerability Assessment Tools
- Depth assessment tools
- Scope Assessment Tools
06. System Hacking
- Example Winpeas output
- net/sec/tools/metasploit
- Metasploit - Pivoting
- net/sec/mimikatz
- net/sec/Password Cracking
- hashcat
- hashcat - attack modes
- Golden ticket attack
- Kerberoasting
- AS-REP Roasting
- Rootkit
- Steganography
- Steganalysis
- DLL Hijacking
- Application Shimming
- BeRoot
- LinPostEXP
- Ghostpack Seatbelt
- Lateral Movement
- Command and Control
- Data Exfiltration
- Living off the Land
- Fileless Attacks
- DCSync
- Data Protection API
- Kerberos
- NTLM
- Pass-the-Hash
- Pass-the-Ticket
- Golden ticket attack
- Silver Ticket
- Alternate Data Streams
- Windows Registry
- Windows - Services
- Windows Event Logs
- Powershell
- WMI
- Group Policy
- Windows Privilege Escalation
07. Malware Threats
- Malware
- Malware Vectors
- AI-based malware
- Mutated AI Based Malware
- Fileless malware
- Static malware analysis
- Dynamic Malware Analysis
- Malware code emulation
- Malware code instrumentation
- virus
- Worm
- Trojan Horse
- BotNet
- Crypter
- Metamorphic Virus
- Polymorphic Virus
- Fake AntiVirus
- Ransomware
- Spyware
- Adware
- Keylogger
- Logic Bomb
- Backdoor
- Remote Access Trojan
- Banking Trojan
- xHelper
- Senna Spy
- Robber
- Malware Sandboxing
- YARA Rules
- Malware Analysis Tools
- Supply Chain Attacks
- Zero-Day Exploits
08. Sniffing
- Packet sniffing
- Active Sniffing Attack
- Passive Sniffing Attack
- net/sec/tools/Wireshark
- tcpdump
- ettercap
- dsniff
- bettercap
- macof
- MAC Flooding
- Hardware/Laptop/ARP Spoofing
- network traffic analysis - cheatsheet
- network traffic analysis - tools
- Yersinia
- DHCP Starvation
- CAM Table Overflow
- Switch Port Stealing
- VLAN Hopping
- VLAN
- VLANPWN
- STP Attacks
- Spanning Tree Protocol
- CDP Attacks
- Cisco Discovery Protocol
- Network Taps
- Promiscuous Mode
- Monitor Mode
- Cisco
- CISCO IOS
- Cisco switch - PORT Security
- Cisco Adaptive Wireless IPS
09. Social Engineering
- Social Engineering
- Phishing
- Spear Phishing
- Vishing
- Smishing
- Pretexting
- Quid Pro Quo
- Identity Theft
- Insider Threat
- setoolkit
- shellphish
- StormBreaker
10. Denial-of-Service
- Denial of Service
- Distributed Denial of Service
- IDS Evasion - DOS
- Slow Loris
- Smurf Attack
- Ping of Death
- DNS Amplification Attack
- Peer to Peer Attack
- Ransom DDoS Attack
- Permanent denial-of-service attack
- Distributed Reflection Denial-of-Service
- Dosfuscation
- DoS Countermeasure Strategies
11. Session Hijacking
- Session Hijacking
- Session Hijacking Prevention
- Session Fixation Attack
- Session Riding
- TCP-IP Hijacking
- UDP Hijacking
- DNS-Server Hijacking
- PetitPotam
- Man in The Middle
- SSL Stripping
- Session Tokens
- Cookie Hijacking
- net/sec/Cross Side Scripting
- XSS Payloads
- XSS - Filter Evasion
- DOM-based XSS
- net/sec/xss/Reflected XSS
- Blind XSS
- XSStrike
- Browser Exploitation Framework
12. IDS, Firewalls, and Honeypots
- Intrusion Detection System
- Firewall
- Packet Filtering Firewall
- Circuit-Level Gateway Firewall
- Application-Level Firewall
- Stateful Multilayer Inspection Firewall
- Software Firewall
- Web Application Firewall
- Honeypot
- Blumira Honeypot Software
- Snort
- Snort Rules
- sre/firewall/firewall-cmd
- IDS Evasion Attack
- IDS Evasion Techniques
- IDS Evasion - DOS
- IDS Evasion - False Positive Generation
- IDS Evasion - Obfuscation
- Session Splicing
- Firewalking
- ACK tunneling
- Insertion Attack
- Fragmentation Attack
- Network Security Monitoring
- SIEM
- Network Access Control
- Data Loss Prevention
- Network Segmentation
- Zero Trust Architecture
- Endpoint Detection and Response
- Security Orchestration
13. Hacking Web Servers
- Apache Server
- nginx
- java/Tomcat Server
- Shellshock
- net/sec/tools/metasploit
- wpscan
- nikto
- net/sec/tools/gobuster
- dirb
- wordpress - penetration testing
14. Hacking Web Applications
- OWASP - Top Ten
- OWASP Web Top Ten
- OWASP API - Top Ten
- OWASP Application Security Verification Standard
- OWASP ZAP
- burpsuite
- Cross-Site Request Forgery
- Server-Side Request Forgery
- net/sec/Command Injection
- Path traversal
- Insecure Direct Object References
- XML External Entity Injection
- SQLMAP
- SQLMAP - Injection Types
- SQLMAP - cheatsheet
- sqlmap - data enumuration
- uniscan - Tutorial
- HTML Smuggling
- Authentication bypass vulnerability
- PHP - Type juggling vulnerability
- Insecure Deserialization attacks
15. SQL Injection
- net/sec/Sql Injection
- In-band SQL injection
- Blind SQL Injection
- SQLMAP
- SQLMAP - cheatsheet
- SQLMAP - Injection Types
- SQLMAP - Examples
- Havij
- Parameterized queries
16. Hacking Wireless Networks
- Wi-Fi
- 802.11
- Wired Equivalent Privacy
- Airmon-ng
- CoWPAtty
- WIBR+
- WPA_Supplicant
- Bluetooth Attacks
- Bluejacking
- Bluesnarfing
- Disassociation Attack
- Misconfigured AP Attack
- Piggybacking
- Access point
- Basic Service Set Identifier
17. Hacking Mobile Platforms
- Android/Android Development
- apple/ios/ios Programming
- Android - Exploits
- Android - Root
- scrcpy
- App integrity Check
- Dalvik VM
- AndroidManifest.xml
- Android - Binder
- Android - Services
- Android - Content Provider
- Android Activity
- Android Activity - Intent
- Android - Broadcast Receivers
- Android - Deeplink
- OWASP Mobile - Top Ten
- oxygen forensic device extractor
18. IoT and OT Hacking
- Internet of Things
- IoT Application Areas and Devices
- IoT Architecture
- IoT Communications Model
- IoT Technologies and Protocols
- IoT Device Management
- IoT Hacking Methodology
- IoT Attack Countermeasures
- IoT Security Threats
- IoT Vulnerabilities
- IoT Sniffing
- IoT Traffic Analysis
- IoT Framework Security Considerations
- IoT Hardware Security Best Practices
- IoT Secure Development Practices
- OWASP IoT - Top Ten
- OWASP IoT Attack Surface Areas
- Identifying IoT Communication Buses and Interfaces
- iotseeker
- metasploit - IoT
- NB-IoT
- Operational Technology
- Industrial Control System
- Industrial Demilitarized Zone
- Industrial Internet Security Framework
- Supervisory Control and Data Acquisition
- Programmable Logic Controllers
- Distributed Control Systems
- Human–Machine Interfaces
- Intelligent Electronic Devices
- SCADA Traffic Analysis
- OT - Challanges
- OT - Vulnerabilities
- OT - Side Channel Attack
- OT - MITRE ATT&CK
- OT Security Solutions
- OT Supply Chain Attacks
- OT Malware
- OT-ISAC
- IIOT
- Securing IIOT Environment
- ICS Fuzzing
- ICS Hardware Hacking
- ICS - Zero-Trust Network
- nmap - SCADA
- RIOT
19. Cloud Computing
- Cloud/Cloud Computing
- AWS Security
- Azure Security
- Google Cloud Security
- Container Security
- Docker Security
- Kubernetes Security
- Cloud Storage Security
- Identity and Access Management
- Cloud Misconfigurations
- OWASP Cloud - Top Ten
- OWASP Kubernetes - Top Ten
- OWASP Serverless - Top Ten
20. Cryptography
- Cryptographic Algorithms
- Symmetric Encryption
- Asymmetric Encryption
- Data Encryption Standard
- Advanced Encryption Standard – Galois Counter Mode Protocol
- net/sec/PKI/TLS
- net/sec/PKI/TLS/Self-Signed Certificate
- Internet Protocol Security
- john - Hash Format
- keytool
- sre/Tools/openssl
- Cipher Modes
- Enabling SSL/TLS in Keycloak
- java/spring/Debugging SSL in Spring
- Hash Functions
- Digital Signatures
- Public Key Infrastructure
- Certificate Authority
- Digital Certificates
- Key Management
- Cryptanalysis
- Chosen-key Attack
- Chi-square Attack
- Brute Force Attack
- Dictionary Attack
- Rainbow Table
- Salt
- Hashing Algorithms
- MD5
- SHA
- HMAC
- RSA
- Elliptic Curve Cryptography
- Diffie-Hellman