This course equips penetration testers with the skills necessary to exploit client-side vulnerabilities and gain initial access by targeting employee systems and behaviors, bypassing more secure public-facing servers. You will begin with an overview of client-side attacks, learning to gather information and fingerprint to uncover exploitable client-side configurations. The course delves into social engineering, teaching the principles, various attack methods, and the implementation of phishing campaigns using tools like GoPhish. Additionally, you'll learn to develop and weaponize VBA macros, create macro-enabled MS Office documents, and use ActiveX Controls for macro execution. Advanced techniques will include creating droppers and using HTML Applications in your attacks. Practical training on payload delivery methods like HTML Smuggling will also be covered. Ideal for penetration testers and red teamers, this course combines theoretical knowledge, real-world scenarios, and hands-on lab exercises to proficiently target and exploit the weakest link in an organization’s security—the employees.
Free courses from frontend to fullstack and AI
Stuck in Tutorial Hell? Learn Backend Dev the Right Way
Overview
Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
Taught by
Alexis Ahmed