EC-Council Certification Training
CEH v13
Certified Ethical Hacker — Complete Course Outline (20 Modules)
Foundation→
Recon & Scanning→
System & Network→
Web · Wireless · Cloud
20Modules
5Phases
312-50Exam
1Capstone
⚖️ Ethics & Legal Notice — এই course শুধুমাত্র authorized ও legal penetration testing এবং defensive security শেখার জন্য। যেকোনো technique কেবল নিজের বা written permission থাকা system-এ practice করতে হবে। অননুমোদিত access সম্পূর্ণ বেআইনি ও শাস্তিযোগ্য।
Phase 1
Foundation & Reconnaissance
01
Introduction to Ethical Hacking
▾- Information Security fundamentals
- CIA Triad (Confidentiality, Integrity, Availability)
- Cyber Kill Chain methodology
- Hacker classes ও ethical hacking concepts
- Attack types ও threat categories
- Penetration testing phases
- Information security controls ও laws
- Compliance: PCI-DSS, ISO 27001, GDPR overview
02
Footprinting & Reconnaissance
▾- Footprinting concepts ও methodology
- Passive বনাম Active reconnaissance
- OSINT (Open Source Intelligence)
- Search engine ও Google dorking basics
- WHOIS, DNS ও network footprinting
- Website ও email footprinting
- Social media reconnaissance
- Footprinting countermeasures
🧪 Lab (authorized target)
- WHOIS ও DNS information gathering
- OSINT recon on own domain
03
Scanning Networks
▾- Network scanning concepts
- Host discovery techniques
- Port ও service scanning (
nmapbasics) - Scanning types: TCP, SYN, UDP
- OS fingerprinting (banner grabbing)
- Network mapping ও topology
- Scan evasion concepts
- Scanning countermeasures
🧪 Lab (own network)
- Nmap দিয়ে lab network discovery ও port scan
04
Enumeration
▾- Enumeration concepts
- NetBIOS ও SMB enumeration
- SNMP enumeration
- LDAP ও DNS enumeration
- NTP ও SMTP enumeration
- Service ও user enumeration
- Enumeration countermeasures
Phase 2
Vulnerabilities & System Hacking
05
Vulnerability Analysis
▾- Vulnerability assessment concepts
- Vulnerability classification
- Assessment types ও lifecycle
- Vulnerability scoring (CVSS, CVE, CWE)
- Vulnerability scanning tools overview
- Scan report analysis
- Assessment vs penetration testing
🧪 Lab
- Vulnerability scanner দিয়ে lab system assess
06
System Hacking
▾- System hacking methodology
- Password attack concepts ও defense
- Password cracking types (dictionary, brute-force overview)
- Privilege escalation concepts
- Maintaining access overview
- Clearing logs ও anti-forensics awareness
- Defensive countermeasures ও hardening
শুধুমাত্র নিজের lab/authorized system-এ, defensive understanding-এর জন্য।
07
Malware Threats
▾- Malware concepts ও categories
- Trojan, Virus, Worm — কীভাবে কাজ করে (conceptual)
- Ransomware overview
- Fileless malware ও APT concepts
- Malware analysis basics (static/dynamic)
- Detection techniques
- Anti-malware ও countermeasures
08
Sniffing
▾- Network sniffing concepts
- Active vs passive sniffing
- MAC ও ARP attack concepts
- DHCP ও DNS attack overview
- Packet analysis (
Wireshark) - Sniffing detection ও defense
🧪 Lab
- Wireshark দিয়ে own traffic capture ও analysis
Phase 3
Social Engineering & Network Attacks
09
Social Engineering
▾- Social engineering concepts
- Human-based ও computer-based techniques
- Phishing ও spear phishing awareness
- Impersonation ও pretexting
- Insider threats
- Identity theft overview
- Awareness training ও countermeasures
10
Denial-of-Service (DoS/DDoS)
▾- DoS ও DDoS concepts
- Attack techniques ও categories (conceptual)
- Botnet overview
- Volumetric, protocol ও application-layer attacks
- Detection techniques
- Mitigation ও countermeasures
11
Session Hijacking
▾- Session hijacking concepts
- Application ও network-level hijacking (conceptual)
- Session token security
- Man-in-the-Middle overview
- Detection ও defense
- Secure session management
12
Evading IDS, Firewalls & Honeypots
▾- IDS, IPS ও firewall concepts
- Honeypot types ও purpose
- Evasion techniques (awareness)
- Defensive tuning ও detection
- Security monitoring best practices
Phase 4
Web, Application & Wireless
13
Hacking Web Servers
▾- Web server architecture ও concepts
- Common web server vulnerabilities
- Misconfiguration ও patch management
- Web server attack methodology (conceptual)
- Hardening ও secure configuration
- Countermeasures
14
Hacking Web Applications
▾- Web application architecture
- OWASP Top 10 overview
- Authentication ও session flaws
- Input validation issues
- Web app testing methodology
- Secure coding ও defense
🧪 Lab (intentionally vulnerable app)
- DVWA / OWASP Juice Shop-এ safe practice
15
SQL Injection
▾- SQL injection concepts
- Injection types (conceptual overview)
- Detection techniques
- Parameterized queries ও prepared statements
- Input sanitization
- SQLi countermeasures ও secure design
🧪 Lab (own vulnerable app)
- Lab environment-এ SQLi detection ও mitigation
16
Hacking Wireless Networks
▾- Wireless concepts ও standards
- Wireless encryption: WEP, WPA, WPA2, WPA3
- Wireless threats (conceptual)
- Rogue AP ও evil twin awareness
- Wireless security testing methodology
- Wi-Fi hardening ও countermeasures
17
Hacking Mobile Platforms
▾- Mobile attack surface
- Android ও iOS security architecture
- Mobile threats ও risks (OWASP Mobile Top 10)
- App security testing overview
- MDM (Mobile Device Management)
- Mobile security best practices
Phase 5
IoT, Cloud & Cryptography
18
IoT & OT Hacking
▾- IoT concepts ও architecture
- OT (Operational Technology) ও SCADA overview
- IoT attack surface ও threats
- Common IoT vulnerabilities
- Security testing methodology
- IoT/OT defense ও countermeasures
19
Cloud Computing
▾- Cloud computing concepts (IaaS, PaaS, SaaS)
- Container ও serverless overview
- Cloud threats ও attack vectors
- Shared responsibility model
- Cloud security testing
- Cloud security controls ও best practices
20
Cryptography
▾- Cryptography concepts
- Symmetric ও asymmetric encryption
- Hashing (MD5, SHA family)
- PKI ও digital certificates
- Disk ও email encryption
- Cryptanalysis overview
- Cryptographic attacks (conceptual) ও defense
Final Project
🎯 Final Capstone — Authorized Pentest Simulation
Trainee-কে একটি fully authorized lab environment-এ end-to-end ethical hacking assessment করতে দেওয়া হবে — recon থেকে reporting পর্যন্ত।
Recon
- Footprinting
- OSINT
- Scanning ও enumeration
Assessment
- Vulnerability analysis
- CVSS scoring
- Risk rating
Testing
- Web app (DVWA)
- Network lab
- Wireless lab
Defense
- Hardening
- Countermeasures
- Detection tuning
Reporting
- Findings documentation
- Remediation advice
- Executive summary
Ethics
- Scope ও authorization
- Responsible disclosure
- Legal compliance
Final Outcome —
এই course শেষে একজন trainee একটি authorized environment-এ ethical hacking methodology বুঝে security assess করতে, vulnerability identify করতে ও defensive countermeasures সুপারিশ করতে পারবে — এবং CEH (312-50) exam-এর জন্য প্রস্তুত থাকবে।