Rapid7 Security Training

Scheduled Training

Rapid7 offers the following security training:

NeXpose API Training

California Dates - 2008

  • Sept 10 - 11
  • Dec 10 - 11

Boston Dates - 2008

  • August 21 - 22
  • November 6 - 7

This 2 day intensive class led by a CISSP certified Rapid7 consultant provides all of the information needed to successfully design and implement Application Programmers Interface (API) interaction in an enterprise network. In addition to the API itself, there will be an indepth review of a use case where Rapid7 has used the API to create a self service scanning portal.

This class is appropriate for organizations that wish to extgend the base NeXpose functionality or integrate NeXpose with other commercial or in-house security tools. This hands-on class is geared towards a very technical audience and the students should have a solid background in security architecture, databases and especially programming.

For more information, download the NeXpose API Training Course datasheet. To register for this training, call 866 7Rapid7 (866.772.7437) or speak with your account representative.

Penetration Testing Training

Boston - October 7 - 9

Black Hat hackers don’t play by the rules; they have the newest exploits and are constantly changing their tactics. The NeXpose Certified Hacker training class is aimed at giving security and networking professionals exposure to the "Hacker Mentality".

By taking this course we will teach you to critically analyze a corporate security stance and external footprint using the tools of the trade. You will understand what some of the basic tools that even the newest Script Kiddie will use to try to gain access to a target environment, how they are used and what drives the attacker behind them. These skills can then be brought back to any environment and used to fix holes, enhance policies and practices, and perform high-level interim internal security audits.

This three day course is organized into:

  • Day 1 - dedicated to collecting information on a target before an attack. An attacker will attempt to gather as much publicly and / or privately available information as possible.
  • Day 2 - aimed at enumerating possible weaknesses in a target. More often this phase is an "Active" process and may be the first "warning signals" of an impending attack.
  • Day 3 - concerned with actual exploitation and taking over of target machines. This phase is the culmination of the course using information "gathered" the first two days.

To register for this training, call 866 7Rapid7 (866.772.7437) or speak with your account representative.

Open Web Application Security Project (OWASP) Training

Boston - September 25 - 26

In today’s global economy, attackers today are targeting web application vulnerabilities more than operating systems and networks. These vulnerabilities can be exploited to obtain confidential information and compromise organizational integrity. As a result, organizations must integrate robust security measures into the Web application development process.

This powerful one or two day course provides in-depth, hands-on experience with the concepts behind securing Web-based applications and host servers. We focus on the most common web application security problems, including the OWASP Top Ten:

  • Cross Site Scripting (XSS)
  • Injection Flaws
  • Malicious File Execution
  • Insecure Direct Object Reference
  • Cross Site Request Forgery
  • Information Leakage and Improper Error Handling
  • Broken Authentication and Session Management
  • Insecure Cryptographic Storage
  • Insecure Communications
  • Failure to Restrict URL Access

We introduce and demonstrate hacking techniques, illustrating how application vulnerabilities can be exploited so students fully understand how to avoid introducing such vulnerabilities into their development methodologies.

To register for this training, call 866 7Rapid7 (866.772.7437) or speak with your account representative.

Level 1 Security Education, Awareness and Training

Boston - November 20 - 21

This one hour course is meant to develop security awareness for every person in the organization such that security bcomes everyone's responsibility. You will learn the language of security, how to recognize a potential security issue and what to do when you discover one. Understanding where security issues come from and how to avoid exposing your company's computer network to potential attackers helps your company avoid the cost of an attack.

To register for this training, call 866 7Rapid7 (866.772.7437) or speak with your account representative.