You are leaving our Website
Using an external Link:
You are now leaving our website. The following page is operated by a third party. We accept no responsibility for the content, data protection, or security of the linked page..
URL:
SC400: Cyber Threat Analyst (CTA) UPDATE
Training: Security
The workshop practically teaches how attackers think and operate. In hands-on labs participants learn OSINT, phishing as well as WLAN and USB attacks and develop their own Raspberry Pi tools. Additionally, the course covers AI-supported attacks on LLMs and agentic systems as well as effective protective measures according to OWASP Top 10 for LLM and MITRE ATLAS.
Start: 2026-08-31 | 10:00 am
End: 2026-09-04 | 01:30 pm
Location: Nuremberg
Price: 2.950,00 € plus VAT.
Start: 2026-11-23 | 10:00 am
End: 2026-11-27 | 01:30 pm
Location: Nuremberg
Price: 2.950,00 € plus VAT.
Agenda:
Chapter 1
Live hacking demo
Basics (the hackers view)
From MIT hacker on the roof to Emotet
World map of hacker groups
How not to get caught
Cyber Kill Chain /Attack Matrix (MITRE ATT&CK)
Legal fundamentals
Ethical hacking rules
Proper documentation
How BugBountys work
Open Source Intelligence
Darknet, Google™-Dorking, Shodan, Robtex, RIPE
TheHarvester, Maltego
Web research with AI tools: usage of AI assistants for prioritization, source finder and automation of research streams
Chapter 2
Strategy and tactics
Phishing /E-Mail-Attacking
Basics of e-mail attacks
E-Mail-protection (spam/junk/DMARC/SPF/blacklist)
Legal and ethical aspects
We build a malicious macro (Conceptual)
Phishing -- vishing -- smishing
Phishing as awareness module
Setup of own GoPhish server
Creating campaigns
Working with templates
Hacking with LLMs: possible uses of language models for social engineering scripts, template generation, and automation support
AI-Powered Social Engineering: Deepfakes and Voice Cloning – How They Work, Real-World Use Cases, and Detection (Demo)
Chapter 3
USB hacking
USB-Ninja, BashBunny, Keylogger
RubberDucky /Digispark
Data theft by insider threats
Network sniffing and scanning general
Basics: ARP-Poisoning, Routing, IP-Tables, Firewalls
Tools: NMAP, Wireshark, own Raspberry tools (instead of SharkJack)
Tunneling (ICMP, DNS)
Infection persistence
Schedule tasks, backdoors, covering tracks
Automated pentest solutions: overview of automation frameworks, CI/CD integrations and orchestration of scan/exploit pipelines (concept, demo)
Chapter 4
Lateral movement + pivilege escalation
Attacks on authorization systems, using Active Directory and Entra ID as examples
Identity-based attacks: MFA fatigue, session/token theft
Password complexity and attacks
Introduction to Metasploit
Password cracking and rainbow tables
Web hacking introduction
OWASP TopTen, BurpSuite, CrossSite, SQL-Injection
Automated web tests & AI assistance: usage of automatic scanners, scriptable Burp workflows and AI-supported analysis aids (overview & practical examples)
Chapter 5
Hacking AI systems
Overview of the attack surface of AI and LLM applications
Orientation to OWASP Top 10 for LLM Applications and MITRE ATLAS
Why classical vulnerability models are insufficient for AI
Attacks on LLM applications (Demo / Conceptual)
Prompt injection (direct and indirect), jailbreaks and guardrail bypasses
Prompt/system prompt extraction and handling of sensitive outputs
Attacks on agentic AI systems
Excessive agency and abuse of tool/plugin integrations (e.g., via MCP)
Confused deputy problem and supply chain risks in models, datasets and prompts
Attacks on the model itself (Overview)
Data poisoning, model extraction, membership inference, evasion attacks
Defense and hardening of AI applications
Guardrails, input/output filtering, least privilege and least capability
AI red teaming as a methodological approach
Detection of AI-generated content (reference to Chapter 2)
Legal and ethical assessment
Ethical hacking rules in the AI context, relation to the requirements of the EU AI Act
Webrecherche mit KI-Tools: Nutzung von KI-Assistenten zur Priorisierung, Quellenfinder und Automatisierung von Rechercheströmen
Chapter 6
Vulnerabilities in applications: buffer overflows
Pentesting vs. vulnerability scans
Cryptography: certificates /encryption
Final test
Give-Aways / Materialien:
You will receive the following materials additionally:Security trophies
Raspberry-Kit incl. ink display and pre-configured images (Pwnagotchi / Björn) — tool construction kit for own LAN/WLAN prototypes
DigiSpark with demo payloads
Kali-Linux-VM, cheat sheets and scripts
Permanent access to link platform with over 300 services and tools
Certificate
Objectives:
Understanding the mindset and techniques of attackers
Practical application of classic hacking methods in legal, controlled lab environments
Ability to design and use your own Raspberry-based proof-of-concept tools (Lab Scope)
Classification and use of modern tools: LLMs to support recon/phishing templates, AI tools for web research, and automated pentest solutions
Knowledge of legal frameworks, documentation requirements and ethical hacking standards
Target audience:
The workshop SC400 Cyber Threat Analyst (CTA) targets IT professionals and specialists who want to learn and understand approaches, methods and techniques of hackers in order to verify the security of their own systems and to better assess the effectiveness of their own countermeasures. For IT forensics specialists it provides the perspective through the lens of the perpetrator and thus the knowledge to conduct investigations more precisely and efficiently. The course is also relevant for anyone who develops, operates, or secures AI applications within their organization and wants to gain a practical understanding of the attack surface of these systems.
Prerequisites:
Our workshop SC400 Cyber Threat Analyst (CTA) is a basic course. Knowledge of IP networks, the WWW and common operating systems is required; in-depth Linux or Windows knowledge is not mandatory. Curiosity and passion for hacking are crucial.
Description:
Learn how hackers think and operate from experienced white hats. The course SC400 Cyber Threat Analyst (CTA) combines theoretical inputs with intensive hands-on labs: from OSINT research through phishing campaigns to WLAN and USB attack scenarios. Participants build their own Raspberry-based prototype tools in the course and test them in secure labs, learn how to use Pwnagotchi/Björn images, and evaluate implications for protective measures.
Additionally, modern trends are covered: How do LLMs support recon and social engineering processes? How can AI-powered web research tools accelerate information gathering? What role do automated pentest solutions play in daily security operations?
A dedicated module focuses on the emerging class of attacks targeting AI systems themselves. Participants explore topics ranging from prompt injection and jailbreaks to the abuse of agentic AI and its tool integrations, as well as attacks against AI models. Using the OWASP Top 10 for LLM Applications and the MITRE ATLAS framework, they learn to identify the attack surfaces of AI and LLM applications and derive practical hardening and defensive measures. All exercises are conducted within a legal, controlled lab environment and in accordance with ethical hacking principles.
Assessment / Certificate
The course concludes with a practical final test that combines theoretical and laboratory technical questions. Upon successful completion, participants receive a certificate of participation.
Guaranteed implementation:
from 2 Attendees
Booking information:
Duration:
5 Days
Price:
2.950,00 € plus VAT.
For in-person attendance, lunch and beverages are included in the price.
Exam (Optional):
100,00 € plus VAT.
Testimonials:
Impressions:
Authorized training partner
Memberships
Shopping cart
SC400: Cyber Threat Analyst (CTA)
was added to the shopping cart.