Cybersecurity Academy - Path Traversal & Command Injection
This workshop is delivered as part of both the Blue Team and Red Team specializations. Participants follow a dedicated learning path, with practical activities and learning objectives tailored to their chosen specialization.
Blue Team – Network Forensics and Malware Investigation :
Blue Team – Network Forensics and Malware Investigation :
This hands-on cybersecurity investigation track develops practical skills in analyzing network traffic and investigating evidence of compromise. Using PCAP-based scenarios, students learn to identify reconnaissance activity such as SYN scans, isolate suspicious communications with Wireshark filters, investigate malicious downloads, and reconstruct attacker activity from captured network traffic.
The track also introduces basic malware analysis and threat intelligence techniques. Students examine malicious files and scripts, investigate malware behavior and command-and-control communications, identify exploited vulnerabilities and relevant MITRE ATT&CK techniques, and trace activities ranging from initial access and remote command execution to attempted privilege escalation and cryptocurrency mining. The practical focus mirrors the investigative workflow used by security analysts when determining whether a system has been compromised and understanding the actions performed by an attacker.
Red Team – Path Traversal and Command Injection
A hands-on web security exploitation module focused on understanding, identifying, and exploiting path traversal and OS command injection vulnerabilities in deliberately vulnerable web applications. Students investigate how improper input handling can expose unintended files or allow operating-system commands to be executed. The module covers traversal sequences, encoding and validation bypasses, arbitrary file access, command injection, blind command injection, and out-of-band techniques, while emphasizing the distinction between the two vulnerability classes.
A hands-on web security exploitation module focused on understanding, identifying, and exploiting path traversal and OS command injection vulnerabilities in deliberately vulnerable web applications. Students investigate how improper input handling can expose unintended files or allow operating-system commands to be executed. The module covers traversal sequences, encoding and validation bypasses, arbitrary file access, command injection, blind command injection, and out-of-band techniques, while emphasizing the distinction between the two vulnerability classes.
Learning Outcomes
By the end of the course, students will be able to:
Blue Team – Network Forensics and Malware Investigation
- Identify reconnaissance patterns in PCAP files, including TCP SYN scanning activity.
- Analyze network conversations to distinguish attacker and victim systems.
- Apply Wireshark filters to isolate relevant packets, hosts, ports, and suspicious communications.
- Determine open ports and identify the first responsive service discovered during reconnaissance.
- Investigate suspicious HTTP requests and identify indicators of attempted exploitation.
- Identify vulnerabilities exploited during an attack and relate the activity to appropriate MITRE ATT&CK techniques.
- Analyze network traffic to determine evidence of initial access and remote command execution.
- Investigate malicious file downloads and identify suspicious files transferred through HTTP traffic.
- Assess malware characteristics using file information, hashes, threat intelligence, and observed network behavior.
- Identify malware families, contacted domains, external IP addresses, and other indicators associated with malicious activity.
- Analyze malicious scripts to understand payload delivery, system reconnaissance, architecture detection, persistence, and cleanup activity.
- Investigate command-and-control communications and interpret encoded or encrypted data associated with malware activity.
- Identify malware execution mechanisms and examine the use of downloaded or embedded components.
- Analyze privilege-escalation attempts and reconstruct the commands and tools used by an attacker.
- Assess the overall impact and objectives of an intrusion, including resource hijacking and cryptocurrency mining.
Red Team – Path Traversal and Command Injection
- Explain path traversal and OS command injection and distinguish between them.
- Identify vulnerable parameters involving file paths and system commands.
- Detect and exploit path traversal vulnerabilities in controlled environments.
- Understand relative and absolute path traversal techniques.
- Recognize encoding, filtering, normalization, and validation weaknesses.
- Understand how vulnerable file-handling functionality can expose sensitive files.
- Identify OS command injection and common command-separation techniques.
- Distinguish direct and blind command injection scenarios.
- Understand time-based, output-based, and out-of-band detection techniques.
- Account for differences between Unix/Linux and Windows command environments.
- Use Burp Suite to intercept, modify, and analyze HTTP requests.
- Explain effective defenses such as input allow listing, path canonicalization, safe file system APIs, and avoiding unnecessary shell execution.
- Apply a structured methodology for testing these vulnerabilities in authorized environments.
Training Method
Blue Team participants work with controlled network captures and malware artifacts. They begin with foundational PCAP analysis and traffic identification before progressing to filtering, reconnaissance analysis, suspicious HTTP activity, malware investigation, threat intelligence, command-and-control analysis, and attacker activity reconstruction. Guided exercises encourage students to investigate evidence independently, correlate network and malware findings, troubleshoot investigative challenges, and build a coherent timeline of compromise.
Red Team participants follow a hands-on lab-based methodology built around
deliberately vulnerable web applications. Students modify HTTP requests,
observe application behavior, and investigate how user-controlled input
reaches file system and operating-system functionality. Burp Suite is
used to analyze and manipulate requests throughout the exercises. The
emphasis is on understanding why vulnerabilities occur and why
particular techniques work, rather than simply reproducing payloads.
Certification
Certificate of ParticipationPrerequisites
This training has no prerequisitesPlanning and location
Session
1
03/09/2026
-
Thursday
09:00 - 17:00
09:00 - 17:00