(não existem exames)
Recognition
Active recognition
Passive recognition
Identification of vulnerabilities
Tools
Exploitation
o Metasploit
o Rapid pentesting
o Windows oneliners
Attacking the perimeter
o Bypass firewall
Attacking the endpoint
Creating malicious documents
Bypass antivirus
Escalation of privileges
UAC bypass
Lateral movement
DCOM
WMI, PSEXEC
Information gathering
Domain admin
Identifying where the information is
Web Audit
Vulnerabilities
Automated identification
Exploitation
WIFi Audit
PSK attacks
o WEP, WPA
o WPS
EAP attacks
o Rogue Aps