Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Coursera

Exploit Development, Malware, & Defensive Strategies

Packt via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This course features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. Expand your offensive security expertise by mastering reconnaissance, API security testing, and responsible vulnerability discovery. Through practical demonstrations and hands-on labs, you'll learn how security professionals identify attack surfaces, assess modern APIs, document security findings, and participate in ethical bug bounty programs while following responsible disclosure practices. The course begins with information gathering techniques, including Whois lookups, DNS enumeration, site reporting, and firewall analysis to build a comprehensive understanding of target environments. You'll then dive into API penetration testing by configuring test environments, using Burp Suite and Postman, and evaluating common API security risks such as Broken Object Level Authorization (BOLA), broken authentication, excessive data exposure, mass assignment, CORS misconfigurations, SQL injection, and improper asset management. The final section focuses on applying these skills in realistic scenarios. You'll learn professional penetration test reporting, explore legitimate cybersecurity career paths, and observe live bug bounty methodologies involving reconnaissance, JavaScript analysis, open redirect testing, XSS, broken access control, IDOR, authentication reviews, and responsible vulnerability reporting. Throughout the course, emphasis is placed on ethical testing within authorized environments and industry best practices. This course is ideal for aspiring penetration testers, bug bounty hunters, cybersecurity analysts, and security professionals with prior knowledge of web application security and networking. Familiarity with HTTP, APIs, Linux, and foundational penetration testing concepts is recommended. The course is designed at an Advanced difficulty level. By the end of the course, you will be able to perform structured reconnaissance, assess API security using professional tools, identify and validate common API and web vulnerabilities, prepare professional penetration testing reports, and apply ethical bug bounty methodologies within authorized security testing environments.

Syllabus

  • Object Oriented Programming
    • In this module, we will introduce Object-Oriented Programming (OOP) concepts, including classes, methods, and inheritance in Python. You'll learn how to apply these principles to build efficient and reusable hacking tools while also mastering error handling techniques.
  • Modules
    • In this module, we will explore the world of Python modules, focusing on how to write, use, and manage them to streamline your ethical hacking scripts. You'll also learn the benefits of using external libraries and the key differences between running scripts directly and importing them.
  • MAC Changer
    • In this module, we will cover the essentials of MAC address manipulation, including how to change MAC addresses for anonymity. You’ll gain hands-on experience with Python, using subprocess and regex techniques to automate the process and enhance your security practices.
  • Network Scanner
    • In this module, we will introduce network scanning techniques, focusing on ARP and broadcast requests to identify devices on a network. You'll also enhance your scanning scripts with new features and ensure they are compatible with Python 3 for more effective cybersecurity assessments.
  • Man In The Middle
    • In this module, we will delve into the tactics behind MITM attacks, demonstrating how to intercept network traffic using ARP poisoning. You will learn how to script these attacks effectively, incorporating error handling and user input for more sophisticated MITM scenarios.
  • Packet Listener
    • In this module, we will dive into packet listening and analysis using Wireshark and Python. You’ll also learn techniques for securing your network traffic against potential listeners while mastering the intricacies of network packet analysis.
  • Keylogger
    • In this module, we will cover the creation of a keylogger using Python, focusing on capturing and logging keystrokes. You’ll also learn how to save, send, and optimize keyloggers, with an emphasis on ethical considerations and proper testing.
  • Backdoor
    • In this module, we will explore backdoor creation, from writing the backdoor script to developing a listener for remote access. You’ll learn how to interact with target systems, retrieve data, and upload files, with an emphasis on error handling and Python 3 compatibility.
  • Packaging & Malicious Files
    • In this module, we will explore how to package and disguise malicious files for deployment, focusing on techniques like changing icons and file extensions. You’ll also learn how to create executable payloads and configure them for persistence in compromised systems.
  • Closing & Ethical Hacker's Handbook
    • In this final module, we will close the course with parting thoughts on the importance of ethical hacking practices. You will be guided towards responsible cybersecurity endeavors and provided with key resources to continue your learning journey.

Taught by

Packt - Course Instructors

Reviews

Start your review of Exploit Development, Malware, & Defensive Strategies

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.