EH Ch -1

module 1

INTRODUCTION TO ETHICAL HACKING


Syllabus

Introduction to Ethical Hacking, Federal Laws, Ethical Hacking Concepts, Elements of Information Security, Intrusion and Attacks, Types and Profiles of Attackers and Defenders, Attack Targets and Types, the Anatomy of an Attack, Ethical Hacking and Penetration Testing.



The Dark Turn: 1980s and the Criminalization of "Hacker"


Media Sensationalism and Pop Culture Influence


Watch the video


Legislative Action: The Criminalization of Hacking


CYBER LAW IN INDIA – Overview

--


Cyber Law Framework & Implementation


Digital Personal Data Protection Act, 2023 (DPDP Act)


Future of Cyber Law in India


ETHICAL HACKING CONCEPTS — What is Ethical Hacking?


Types of Ethical Hacking


Typical Phases (Engagement Lifecycle)

  1. Scoping & Rules of Engagement: Define targets, limits, legal permissions, deliverables.
  2. Reconnaissance (Passive/Active): Footprinting, OSINT, service discovery.
  3. Scanning & Enumeration: Port scans, service/version detection, user/enumeration.
    --
  4. Exploitation: Validate vulnerabilities by safe exploitation or proof-of-concept.
  5. Post-exploitation & Privilege Escalation: Assess impact, lateral movement potential.
  6. Reporting & Remediation: Clear reproducible findings, risk rating, remediation steps.
  7. Retest: Confirm fixes applied.

Tools & Techniques (Representative)


Ethics, Laws & Best Practices


Elements of information security


Elements of Information Security


intrusions and attacks?

Pasted image 20251029091617.png
Crime Triangle


Core Elements of an Attack

--

⚠️ All three — Motive, Means, and Opportunity — must align for an intrusion to occur.


Introduction — Types & Profiles of Attackers and Defenders

Black Hat Hackers

Script Kiddies

--

Hacktivists

--

Cyber Terrorists / Cyber Warriors

--

Cyber Criminals

--

White Hat Hackers

--

Pentesters (Red Team)

--

Blue Team

--

Purple Team

--

Gray Hat Hackers


Attack Targets & Types


Network Attacks


Application Attacks


Host (Endpoint) Attacks


The anatomy of an attack

The anatomy of an attack, sometimes referred to as the Cyber Kill Chain


Reconnaissance


Weaponization


Delivery


Exploitation


Installation


Command & Control (C2)


Actions on Objectives


Assets/Pasted image 20251029092611.png

ETHICAL HACKING & PENETRATION TESTING


TYPES OF PENETRATION TESTING


PENETRATION TEST PLANNING

Key questions before testing:


DEFENSIVE TECHNOLOGIES


SECURITY STRATEGY OVERVIEW