Certified Ethical Hacker Complete Course Outline

EC-Council Certification Training

CEH v13

Certified Ethical Hacker — Complete Course Outline (20 Modules)

Foundation Recon & Scanning System & Network Web · Wireless · Cloud
20Modules
5Phases
312-50Exam
1Capstone
⚖️ Ethics & Legal Notice — এই course শুধুমাত্র authorized ও legal penetration testing এবং defensive security শেখার জন্য। যেকোনো technique কেবল নিজের বা written permission থাকা system-এ practice করতে হবে। অননুমোদিত access সম্পূর্ণ বেআইনি ও শাস্তিযোগ্য।
Phase 1

Foundation & Reconnaissance

01

Introduction to Ethical Hacking

  • Information Security fundamentals
  • CIA Triad (Confidentiality, Integrity, Availability)
  • Cyber Kill Chain methodology
  • Hacker classes ও ethical hacking concepts
  • Attack types ও threat categories
  • Penetration testing phases
  • Information security controls ও laws
  • Compliance: PCI-DSS, ISO 27001, GDPR overview
02

Footprinting & Reconnaissance

  • Footprinting concepts ও methodology
  • Passive বনাম Active reconnaissance
  • OSINT (Open Source Intelligence)
  • Search engine ও Google dorking basics
  • WHOIS, DNS ও network footprinting
  • Website ও email footprinting
  • Social media reconnaissance
  • Footprinting countermeasures
🧪 Lab (authorized target)
  • WHOIS ও DNS information gathering
  • OSINT recon on own domain
03

Scanning Networks

  • Network scanning concepts
  • Host discovery techniques
  • Port ও service scanning (nmap basics)
  • Scanning types: TCP, SYN, UDP
  • OS fingerprinting (banner grabbing)
  • Network mapping ও topology
  • Scan evasion concepts
  • Scanning countermeasures
🧪 Lab (own network)
  • Nmap দিয়ে lab network discovery ও port scan
04

Enumeration

  • Enumeration concepts
  • NetBIOS ও SMB enumeration
  • SNMP enumeration
  • LDAP ও DNS enumeration
  • NTP ও SMTP enumeration
  • Service ও user enumeration
  • Enumeration countermeasures
Phase 2

Vulnerabilities & System Hacking

05

Vulnerability Analysis

  • Vulnerability assessment concepts
  • Vulnerability classification
  • Assessment types ও lifecycle
  • Vulnerability scoring (CVSS, CVE, CWE)
  • Vulnerability scanning tools overview
  • Scan report analysis
  • Assessment vs penetration testing
🧪 Lab
  • Vulnerability scanner দিয়ে lab system assess
06

System Hacking

  • System hacking methodology
  • Password attack concepts ও defense
  • Password cracking types (dictionary, brute-force overview)
  • Privilege escalation concepts
  • Maintaining access overview
  • Clearing logs ও anti-forensics awareness
  • Defensive countermeasures ও hardening
শুধুমাত্র নিজের lab/authorized system-এ, defensive understanding-এর জন্য।
07

Malware Threats

  • Malware concepts ও categories
  • Trojan, Virus, Worm — কীভাবে কাজ করে (conceptual)
  • Ransomware overview
  • Fileless malware ও APT concepts
  • Malware analysis basics (static/dynamic)
  • Detection techniques
  • Anti-malware ও countermeasures
08

Sniffing

  • Network sniffing concepts
  • Active vs passive sniffing
  • MAC ও ARP attack concepts
  • DHCP ও DNS attack overview
  • Packet analysis (Wireshark)
  • Sniffing detection ও defense
🧪 Lab
  • Wireshark দিয়ে own traffic capture ও analysis
Phase 3

Social Engineering & Network Attacks

09

Social Engineering

  • Social engineering concepts
  • Human-based ও computer-based techniques
  • Phishing ও spear phishing awareness
  • Impersonation ও pretexting
  • Insider threats
  • Identity theft overview
  • Awareness training ও countermeasures
10

Denial-of-Service (DoS/DDoS)

  • DoS ও DDoS concepts
  • Attack techniques ও categories (conceptual)
  • Botnet overview
  • Volumetric, protocol ও application-layer attacks
  • Detection techniques
  • Mitigation ও countermeasures
11

Session Hijacking

  • Session hijacking concepts
  • Application ও network-level hijacking (conceptual)
  • Session token security
  • Man-in-the-Middle overview
  • Detection ও defense
  • Secure session management
12

Evading IDS, Firewalls & Honeypots

  • IDS, IPS ও firewall concepts
  • Honeypot types ও purpose
  • Evasion techniques (awareness)
  • Defensive tuning ও detection
  • Security monitoring best practices
Phase 4

Web, Application & Wireless

13

Hacking Web Servers

  • Web server architecture ও concepts
  • Common web server vulnerabilities
  • Misconfiguration ও patch management
  • Web server attack methodology (conceptual)
  • Hardening ও secure configuration
  • Countermeasures
14

Hacking Web Applications

  • Web application architecture
  • OWASP Top 10 overview
  • Authentication ও session flaws
  • Input validation issues
  • Web app testing methodology
  • Secure coding ও defense
🧪 Lab (intentionally vulnerable app)
  • DVWA / OWASP Juice Shop-এ safe practice
15

SQL Injection

  • SQL injection concepts
  • Injection types (conceptual overview)
  • Detection techniques
  • Parameterized queries ও prepared statements
  • Input sanitization
  • SQLi countermeasures ও secure design
🧪 Lab (own vulnerable app)
  • Lab environment-এ SQLi detection ও mitigation
16

Hacking Wireless Networks

  • Wireless concepts ও standards
  • Wireless encryption: WEP, WPA, WPA2, WPA3
  • Wireless threats (conceptual)
  • Rogue AP ও evil twin awareness
  • Wireless security testing methodology
  • Wi-Fi hardening ও countermeasures
17

Hacking Mobile Platforms

  • Mobile attack surface
  • Android ও iOS security architecture
  • Mobile threats ও risks (OWASP Mobile Top 10)
  • App security testing overview
  • MDM (Mobile Device Management)
  • Mobile security best practices
Phase 5

IoT, Cloud & Cryptography

18

IoT & OT Hacking

  • IoT concepts ও architecture
  • OT (Operational Technology) ও SCADA overview
  • IoT attack surface ও threats
  • Common IoT vulnerabilities
  • Security testing methodology
  • IoT/OT defense ও countermeasures
19

Cloud Computing

  • Cloud computing concepts (IaaS, PaaS, SaaS)
  • Container ও serverless overview
  • Cloud threats ও attack vectors
  • Shared responsibility model
  • Cloud security testing
  • Cloud security controls ও best practices
20

Cryptography

  • Cryptography concepts
  • Symmetric ও asymmetric encryption
  • Hashing (MD5, SHA family)
  • PKI ও digital certificates
  • Disk ও email encryption
  • Cryptanalysis overview
  • Cryptographic attacks (conceptual) ও defense

🎯 Final Capstone — Authorized Pentest Simulation

Trainee-কে একটি fully authorized lab environment-এ end-to-end ethical hacking assessment করতে দেওয়া হবে — recon থেকে reporting পর্যন্ত।

Recon

  • Footprinting
  • OSINT
  • Scanning ও enumeration

Assessment

  • Vulnerability analysis
  • CVSS scoring
  • Risk rating

Testing

  • Web app (DVWA)
  • Network lab
  • Wireless lab

Defense

  • Hardening
  • Countermeasures
  • Detection tuning

Reporting

  • Findings documentation
  • Remediation advice
  • Executive summary

Ethics

  • Scope ও authorization
  • Responsible disclosure
  • Legal compliance
Final Outcome — এই course শেষে একজন trainee একটি authorized environment-এ ethical hacking methodology বুঝে security assess করতে, vulnerability identify করতে ও defensive countermeasures সুপারিশ করতে পারবে — এবং CEH (312-50) exam-এর জন্য প্রস্তুত থাকবে।
CEH v13 — Certified Ethical Hacker Training Outline  ·  For authorized & legal security education only