The class would mainly include hands-on demonstrations and labs on selected honeypots that form a wide array of capabilities against hackers. From low-interaction honeypots that stall hackers, to medium and high interaction honeypots that aim to provide hackers a false sense of safety that would make them reveal their tools and techniques. This wide variety of demonstrations and labs would be tested through a final project in which students would have to demonstrate independent thinking, based on the knowledge gained, to protect their own assets.
המועדים הקרובים
קורס לארגונים בלבד
ניתן להזמין את הקורס במתכונת של קבוצה מארגון בלבד, בהתאמה אישית לצורך המקצועי ובלו"ז מותאם.
לפרטים נוספים: [email protected]
משך הקורס
שעות לימוד:
40
מספר מפגשים:
קורס בוקר:
5
מתכונת הקורס
הקורסים המוזמנים לארגונים מותאמים באופן אישי ומלא לצרכי הארגון, מערכי הלימוד גמישים וניתן לשלב בהם תכנים רלוונטיים וייעודיים.
- מרצים מומחים ומנוסים מהתעשייה
- למידה מתקדמת בהתאמה אישית
- התפתחות ושדרוג מקצועי
- חוויית למידה חדשנית ומקיפה
- ליווי וייעוץ מקצועי
- חומרי לימוד ייחודיים ובלעדיים
Overview
On Completion, Delegates will be able to

Students will understand the security concepts behind honeypots' usage and get familiar with the deployment, operation, advantages, and pitfalls of selected open-source and commercial products in order to build a comprehensive deception security framework

Students will understand the concepts and purposes of using honeypots as part of a computer security suite in an organization.

Students will get familiar with the main open source and commercial products in the field.

Students will deploy and operate selected low, medium, and high interaction honeypots to acknowledge their up and down sides.

Students will consolidate the data gathered from sensors during the class and come with security research observations.

Students will demonstrate the utilization of honeypots as research tools to protect their own digital assets while trying to capture the assets of others.
Who Should Attend

Students should have at least one year of hands-on experience securing Azure workloads and experience with security controls for workloads on Azure.
תכנית הלימודים
Module 1: Introduction to Deception-based Security
- What is a Honeypot?
- What is its added value to the organization?
- What should we pay attention to when deploying deception security
- Overview of the type of deceptions (low-medium-high interactions) deployed today.
Module 2: Low-Interaction Honeypots
- Demonstration and hands-on labs on selected low-interaction honeypots: Artiellery, BearTrap, PortSpoof, SpiderTrap, Weblabryinth, and WordPot [All under the ADHD distribution]
- The purpose: Stalling the hacker
- Up and Down sides of each implementation
- What can we take from low-interaction honeypots to our organizations?
Module 3: Medium-Interaction Honeypots
- Demonstration and hands-on labs on selected medium-interaction honeypots: Glastopf Web App and Windows KFSensor
- The purpose: Making the hacker feel safe to expose hacking tools
- Lesson 1&2: Glastopf Web-App – template-based vs. vulnrability emulator based web honeypot. We will unpack the mechanisms, PHP SandBox usage, and four types of vulnrability emulation: RFI, LFI, Index, and Unknown type of attacks.
- Lesson 3: Windows KFSensor – Emulation of a variety of Windows Services under a heavily monitored Windows Machine
- What can we take from medium-interaction honeypots to our organizations?
Module 4: High-Interaction Honeypots
- Demonstration and hands-on labs on selected high-interaction honeypots: HonSSH, MazeRunner [Cymmetria]
- The purpose: Making the hacker feel safe and analyzing the exposed hacking tools.
- Lesson 1 & 2: HonSSH – An advanced Terminal-based honeypot of SSH tunneling – will be studied in conjuction with OpenVZ decoys to build a full data center and capture the behaivor of hackers as they are trying to log into system servers and turn them into Bots.
- Lesson 3: MazeRunner [Cymmteria] – Emulation of a variety of Data Center services, applied with agentless breadcumbs (Cookies, Credentials, Shared Folder Connections, and etc.) to give a full deception scenerio to the hacker.
Module 5: Honeytokens
- Demonstration of the concept of Honeytokens – how is it used? What is the added value?
- The purpose: Revealing and locating stoled sensitive informaiton
- 0.5 lesson: Overview of the Honeybadger server to trace geo-location and Docz.py generator of inserting webbugs into *.Docx documents. Molehunt tool can also attach documents to suspect list from within the organizaiton.
Module 6: Final Project
- Students would demonstrate the gained knowledge by defending their own assets based solely on honeypots technologies.
- They will be divided into teams – each team will design its own infrastructure to protect its flag.
- Each team would have one Kali-Linux machine to capture the flag of the other team.
- Score Criteria: 80% – Accuracy of defense report based on the attacking strategy of the other team. 20% – The ability to capture the other team’s flag.
- Security analysts who are familiar with defense mechanisms and attacking patterns
- Linux, Windows, Python, and Networking knowledge
יכול לעניין אותך גם...
קורסים ואירועים נוספים בתחום
270 שעות אקדמאיות
קורס הנהלת חשבונות סוג 1+2 בכיר משלב אינטגרציה מלאה של כלי בינה מלאכותית (AI) ואוטומציה החדשניים ביותר בעולם הפיננסי, ביניהם...
40 שעות אקדמאיות
מטרת הקורס הינה, להכשיר אנשי NOC באמצעות הקניית ידע בתשתיות IT, תקשורת ארגונית וכלי ניטור. הקורס מקנה הבנה מעשית של...
16 שעות אקדמאיות
רוב המנהלים למדו על AI. מעטים בנו אחד. ארגונים שמנצחים בעידן ה-AI לא עובדים יותר קשה – הם בונים מנגנון...
16 שעות אקדמאיות
רוב המנהלים למדו על AI. מעטים בנו אחד. ארגונים שמנצחים בעידן ה-AI לא עובדים יותר קשה – הם בונים מנגנון...
220 שעות אקדמאיות
פלטפורמת Salesforce CRM הינה המערכת המובילה והנפוצה ביותר לניהול לקוחות, ומאפשרת לארגונים לנהל בצורה יעילה מידע על לקוחות, להפיק דוחות...
40 שעות אקדמאיות
קורס "בניית אסיסטנט ארגוני" מעניק למשתתפים הבנה תיאורטית עמוקה לצד כלים מעשיים לבנייה והטמעה של סוכני AI ואסיסטנטים ארגוניים, ללא...
16 שעות אקדמאיות
This intensive program is built for experienced engineers who've outgrown AI as a glorified search engine. The course focuses on...
AWS Skill Builder is the most comprehensive cloud training solution available, designed to make learning an integral part of organizational...
40 שעות אקדמאיות
מתודולוגיית ה-Vibe Coding, מאפשרת בניית מוצרים דיגיטליים ללא צורך בידע מוקדם בכתיבת קוד, באמצעות ניהול והנחיה נכונה של כלי בינה...
616 שעות אקדמאיות
עולם המשחקים הדיגיטליים משתנה במהירות. כלי בינה מלאכותית כמו ChatGPT, Midjourney, GitHub Copilot וכלי GenAI נוספים מאפשרים כיום לפתח רעיונות,...
40 שעות אקדמאיות
The 5-day, hands-on course, is designed for software developers familiar with Node.js or Python. The program moves from a foundation...
רוצה עוד מידע על קורס בהתאמה אישית לארגון שלך?
נשמח לייעץ, ללוות ולענות על כל השאלות
ניהול הגדרות פרטיות
באתר זה נעשה שימוש בטכנולוגיות איסוף מידע כגון Cookies, לרבות על ידי צדדים שלישיים, כדי לספק לך חווית גלישה טובה יותר וכן למטרות סטטיסטיקה, אפיון ופרסום.
המשך הגלישה באתר מהווה את הסכמתך לכך. מידע נוסף ואפשרויות לניהול השימוש באמצעים אלה נכללים במדיניות הפרטיות.
פונקציונליות
Always active
האחסון הטכני או הגישה הכרחיים באופן מוחלט למטרה הלגיטימית של לאפשר שימוש בשירות ספציפי שביקש המנוי או המשתמש באופן מפורש, או למטרה הבלעדית של ביצוע העברת תקשורת ברשת תקשורת אלקטרונית.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
סטטיסטיקה
האחסון הטכני או הגישה משמשים אך ורק למטרות סטטיסטיות אנונימיות.
The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
שיווק
האחסון הטכני או הגישה נדרשים ליצירת פרופילי משתמשים כדי לשלוח פרסום מותאם אישית, או כדי לעקוב אחרי המשתמש באתר זה או במספר אתרים למטרות שיווק דומות.
כנס הטכנולוגיה של Oracle וג׳ון ברייס
Oracle
AI Week
2026
שבוע אחד. עולמות של AI, Data, Cloud ופיתוח.
MIX. MATCH. BUILD YOUR OWN AI AGENDA
AI LABS & HANDS-ON
22–25.11
ג׳ון ברייס, תל אביב
ORACLE AI WEEK
16–18.11
מלון דניאל, הרצליה