Professional Certificate 10 Modules 139 Lessons

Advanced Cybersecurity and Ethical Hacking

Description

Program summary

This online program explains the attack–defense logic of cybersecurity with a risk-focused approach. You will study threat modeling, vulnerability management, testing methodologies, and practical hardening principles within ethical boundaries and organizational processes. The goal is to develop sound security judgment, structured assessment habits, and professional reporting discipline.
Format: Delivered online. If a specific program includes live sessions, an on-campus visit, or any in-person component, this will be clearly stated on the program page.
What you will gain:
• Prioritize risks using threat models and structured assessment
• Apply vulnerability management from discovery to remediation
• Use practical hardening and reporting checklists
• Understand ethical testing boundaries and documentation discipline
Who should attend:
Security analyst candidates, system/network administrators, blue-team roles, and professionals transitioning into cybersecurity.
Course outline
1. Security fundamentals: CIA triad, attack surface, control domains
2. Threat modeling: assets, threats, vulnerabilities, prioritization
3. Vulnerability management: scanning, triage, remediation planning
4. Ethical testing methods: scenarios and reporting approach
5. Defense basics: hardening, logging/monitoring principles
6. Applied practice: audit checklist + report outline + action plan

Modules

10

What is included

Lessons

139

Review the module structure and lesson flow before enrollment.

Content sections

4

Review the sections below and open only the one you need. The summary panel on the side keeps the long explanation separate and readable.

Course Curriculum

Module roadmap

Review the module structure and lesson flow before enrollment.

Module 1

Cybersecurity Foundations and Threat Landscape

14 Lessons

Module 2

Networking and Infrastructure Security

15 Lessons

Module 3

Ethical Hacking and Penetration Testing

16 Lessons
Advanced Cybersecurity and Ethical Hacking

Next step

Add to Cart

€ 149,00
Immediate access to the secure purchase flow.
Guided checkout flow for institutional and individual buyers.
A clear curriculum preview before checkout.

You can add the product to your cart and proceed to the payment step.

Certificate Preview

Sample certificate

Preview the institution-issued certificate style learners can expect after successfully completing the program.

What is included

Course Curriculum

Review the module structure and lesson flow before enrollment.

10 Modules 139 Lessons
1

The Cybersecurity Imperative: Why Threats Are Growing and What Is at Stake

2

The CIA Triad: Confidentiality, Integrity and Availability in Practice

3

Threat Actors: Nation-States, Cybercriminals, Hacktivists and Insiders

4

Attack Taxonomy: Tactics, Techniques and Procedures in the ATT&CK Framework

5

The Cyber Kill Chain: Mapping the Anatomy of an Attack

6

Vulnerability, Exploit and Risk: Understanding the Relationship

7

Security Frameworks: NIST CSF, ISO 27001, CIS Controls and Their Differences

8

Defence in Depth: Layered Security Architecture Principles

9

Zero Trust Architecture: Never Trust, Always Verify

10

Security Operations: SOC Structure, Roles and Responsibilities

11

Cybersecurity Laws and Regulations: GDPR, NIS2, CCPA and Sector Requirements

12

Cybersecurity Economics: The Business Case for Security Investment

13

Threat Intelligence: Sources, Feeds, IOCs and Operational Use

14

Security Awareness and Human Risk: Phishing Simulations and Training Programmes

1

TCP/IP Fundamentals for Security Professionals: Protocols, Ports and Packets

2

Network Architecture: Segmentation, DMZs, VLANs and Security Zones

3

Firewall Technologies: Packet Filtering, Stateful Inspection and NGFW

4

Intrusion Detection and Prevention Systems: Signatures, Anomalies and Tuning

5

VPNs and Secure Remote Access: IPsec, SSL/TLS and Zero Trust Network Access

6

DNS Security: Hijacking, Tunnelling, DNSSEC and Protective DNS

7

Network Traffic Analysis: Wireshark, NetFlow and Detecting Anomalies

8

Wireless Security: WPA3, Evil Twin Attacks, Rogue APs and EAP

9

Switch and Router Security: Hardening Cisco and Network Device Configuration

10

Software-Defined Networking and Cloud Network Security

11

Network Forensics: Packet Capture, Reconstruction and Evidence Preservation

12

DDoS Attacks: Types, Amplification Techniques and Mitigation Strategies

13

Network Penetration Testing Methodology: Reconnaissance to Reporting

14

Physical Security and Cable Security: Protecting the Physical Layer

15

Network Security Automation: Python for Packet Analysis and Tool Development

1

Ethical Hacking Fundamentals: Scope, Rules of Engagement and Legal Frameworks

2

Penetration Testing Methodologies: PTES, OWASP and OSSTMM

3

Reconnaissance and OSINT: Maltego, Shodan, theHarvester and Google Dorking

4

Scanning and Enumeration: Nmap, Nessus, OpenVAS and Service Fingerprinting

5

Vulnerability Analysis: CVSS Scoring, CVE Databases and Prioritisation

6

Exploitation Fundamentals: Metasploit Framework, Modules and Payloads

7

Password Attacks: Brute Force, Dictionary, Credential Stuffing and Rainbow Tables

8

Privilege Escalation on Windows: Misconfigurations, Token Abuse and UAC Bypass

9

Privilege Escalation on Linux: SUID, Cron Jobs and Kernel Exploits

10

Lateral Movement: Pass-the-Hash, Pass-the-Ticket and Living off the Land

11

Persistence Mechanisms: Registry Keys, Scheduled Tasks and Backdoors

12

Command and Control: C2 Frameworks, Cobalt Strike and Traffic Obfuscation

13

Exfiltration Techniques and Data Staging

14

Post-Exploitation and Covering Tracks

15

Writing Penetration Test Reports: Findings, CVSS Scores and Remediation Advice

16

Custom Exploit Development: Buffer Overflows and Shellcode Basics

1

Web Application Architecture: HTTP, APIs, Authentication and Session Management

2

OWASP Top 10 2021: Overview, Trends and What Changed

3

Injection Attacks: SQL Injection, Command Injection and XXE

4

Authentication and Session Flaws: Broken Auth, JWT Attacks and Session Fixation

5

Cross-Site Scripting: Reflected, Stored and DOM-Based XSS

6

Insecure Direct Object References and Broken Access Control

7

Security Misconfiguration: Default Credentials, Exposed Admin Panels and Verbose Errors

8

Cross-Site Request Forgery: Mechanisms, Impact and CSRF Tokens

9

Insecure Deserialisation and Server-Side Request Forgery

10

API Security Testing: REST, GraphQL and SOAP Vulnerabilities

11

Web Application Fuzzing: Burp Suite Intruder, ffuf and Automated Discovery

12

Burp Suite Professional: Proxy, Scanner, Repeater and Collaborator

13

Secure Code Review: Identifying Vulnerabilities in Source Code

14

Web Application Firewall Bypass Techniques and WAF Evaluation

15

OAuth 2.0 and OpenID Connect Vulnerabilities: Token Leakage and Misconfiguration

1

Windows Security Architecture: Active Directory, Kerberos and Access Control

2

Active Directory Attacks: Kerberoasting, AS-REP Roasting and DCSync

3

Windows Hardening: CIS Benchmarks, Group Policy and Defender ATP

4

Linux Security: Hardening, SELinux, AppArmor and Audit Framework

5

Endpoint Detection and Response: How EDR Works and How It Is Evaded

6

Antivirus Evasion: Obfuscation, Encoding and Living-off-the-Land Techniques

7

Fileless Malware and Memory-Based Attacks

8

Mobile Device Security: iOS and Android Attack Surfaces and MDM

9

IoT Security: Firmware Analysis, Default Credentials and Protocol Vulnerabilities

10

Patch Management Strategy: Vulnerability Prioritisation and Deployment

11

Host-Based Forensics: Artefacts, Timelines and Windows Event Logs

12

Endpoint Hardening Automation: Ansible, PowerShell DSC and Scripts

1

Cloud Security Fundamentals: Shared Responsibility Model and Cloud Trust Boundaries

2

AWS Security: IAM Misconfigurations, S3 Exposure and GuardDuty

3

Azure Security: Entra ID, Defender for Cloud and Common Attack Paths

4

GCP Security: IAM, Cloud Armor and Security Command Centre

5

Cloud Penetration Testing: Rules of Engagement, Tools and Methodology

6

Container Security: Docker Escape, Kubernetes RBAC and Image Scanning

7

Serverless Security: Lambda, Function Injection and Event Data Abuse

8

Cloud Storage Attacks: Misconfigured Buckets, SAS Tokens and Blob Exposure

9

Cloud Identity Attacks: Token Hijacking, Privilege Escalation and Federation Abuse

10

Cloud Security Posture Management: CSPM Tools and Drift Detection

11

DevSecOps: Integrating Security into CI/CD Pipelines

12

Cloud Incident Response: Evidence Collection and Forensics in Cloud Environments

13

Multi-Cloud Security Strategy: Visibility, Consistency and Unified Policy Enforcement

1

Cryptography Fundamentals: Symmetric, Asymmetric, Hashing and Their Applications

2

TLS/SSL Deep Dive: Handshake, Certificates, Cipher Suites and Common Weaknesses

3

Public Key Infrastructure: CAs, Certificate Chains and Revocation

4

Common Cryptographic Attacks: Padding Oracle, Timing Attacks and Weak Keys

5

Password Hashing: bcrypt, Argon2, PBKDF2 and Why MD5 Is Not Enough

6

Cryptography in Practice: Encrypted Storage, Communications and Code Signing

7

Post-Quantum Cryptography: NIST Standards and the Quantum Threat

8

Blockchain Cryptography: Hash Functions, Digital Signatures and Consensus

9

Hardware Security Modules: TPMs, HSMs and Secure Enclaves

10

Key Management: Generation, Distribution, Rotation and Destruction

11

Steganography and Covert Channels: Hiding Data in Plain Sight

12

Applied Cryptography: Building Secure Systems with Cryptographic Primitives

1

Malware Types and Taxonomy: Viruses, Worms, Ransomware, RATs and Rootkits

2

Setting Up a Safe Malware Analysis Lab: VM Isolation and Sandboxing

3

Static Malware Analysis: File Headers, Strings, Imports and YARA Rules

4

Dynamic Malware Analysis: Process Monitor, Wireshark and Behavioural Analysis

5

Automated Sandboxes: Any.run, Cuckoo and VirusTotal Behaviour Reports

6

Reverse Engineering Fundamentals: Assembly Language for Security Analysts

7

Disassemblers and Decompilers: Ghidra, IDA Pro and Binary Ninja

8

Ransomware Analysis: Encryption Routines, C2 Communication and Decryption

9

Rootkit Analysis: Kernel-Mode Malware and Detection Evasion

10

Malware Attribution and Threat Actor Tracking

11

Writing YARA Rules: Signature-Based Malware Detection

12

Memory Forensics: Volatility, Process Injection and Hidden Artefacts

13

Advanced Persistent Threat Analysis: TTPs, Dwell Time and APT Attribution

1

Incident Response Lifecycle: NIST Framework, Preparation and Playbooks

2

Building an Incident Response Plan: Roles, Communication and Escalation

3

Digital Forensics Fundamentals: Evidence Handling, Chain of Custody and Imaging

4

Windows Forensics: Registry, Prefetch, LNK Files and Browser Artefacts

5

Linux Forensics: Log Analysis, Bash History and Filesystem Artefacts

6

Network Forensics: PCAP Analysis, DNS Logs and Lateral Movement Detection

7

SIEM Configuration and Use: Splunk, Microsoft Sentinel and Elastic SIEM

8

Threat Hunting Fundamentals: Hypothesis-Driven Hunting and TTP-Based Search

9

Threat Hunting with Sigma Rules and the MITRE ATT&CK Framework

10

Ransomware Incident Response: Containment, Negotiation and Recovery

11

Insider Threat Investigations: UEBA, Data Loss Prevention and Evidence

12

Post-Incident Review: Root Cause Analysis and Lessons Learned

13

Deception Technologies: Honeypots, Honeytokens and Active Defence

1

Social Engineering: Phishing, Vishing, Smishing and Pretexting

2

Phishing Campaign Design: GoPhish, Email Spoofing and Payload Delivery

3

Physical Penetration Testing: Tailgating, Lock Picking and RFID Cloning

4

Red Team Operations: Planning, Objectives and Adversary Simulation

5

Purple Teaming: Collaborative Defence and Attack Testing

6

Bug Bounty Hunting: Platforms, Scope, Reporting and Earning Potential

7

CTF Strategy: Capture the Flag Competitions and Skills Development

8

Cybersecurity Certifications: CEH, OSCP, CISSP, CompTIA Security+ and Beyond

9

OSCP Preparation: Methodology, Lab Strategy and Exam Approach

10

Building a Cybersecurity Home Lab: Tools, VMs and Practice Environments

11

AI and Cybersecurity: Offensive AI, Defensive AI and Emerging Threats

12

Cybersecurity Career Pathways: Pentester, Analyst, Architect and CISO

13

Supply Chain Security: Software Bill of Materials, Dependency Attacks and SolarWinds Lessons

14

Cybersecurity for OT and ICS: SCADA, Modbus and Critical Infrastructure Protection

15

Responsible Disclosure and Bug Bounty Ethics: CVD Policies and Legal Boundaries

16

Course Conclusion: Your Path in Advanced Cybersecurity

Program details

Content sections

Review the sections below and open only the one you need. The summary panel on the side keeps the long explanation separate and readable.

Click the Add to Cart button. Complete the purchase process by filling in the required information. Once your payment has been confirmed, your login credentials and access details will be sent to the email address you provided during registration. Use the information sent via email to log in to the learning platform and start the course immediately.
The programs are open to: University students, Recent graduates, Public and private sector employees, Engineers, technicians, and specialists, Managers and management candidates, Professionals seeking to advance their careers, Individuals looking to enhance their digital skills, Anyone interested in gaining competencies in a new field.
Participants who successfully complete the program will: Gain up-to-date knowledge and skills relevant to their field; Develop professional competencies in line with international standards; Adapt to digital transformation and the evolving requirements of the future workforce; Acquire new skills that support career development and professional growth; Receive a verifiable digital certificate documenting their learning achievements; Strengthen their commitment to lifelong learning and continuous professional development. Certificates are issued in digital format and can be verified online through the certificate verification system.
The training programs are offered in Turkish and English and are delivered entirely online. Participants who successfully complete the program will receive a digital certificate. No physical certificate or printed document will be issued or delivered. Upon completion of the application and registration process, access information and login credentials for the training platform will be sent to the email address provided during registration. Participants may access the platform using the credentials provided and follow all training activities online throughout the program.