Durée de la formation : 13,69h

The Certified Secure Software Lifecycle Professional (CSSLP) certification is designed for software development and security professionals, including software architects, developers, project managers, security managers, quality assurance testers, and anyone responsible for ensuring the security of software applications throughout the development lifecycle. This comprehensive course with instructor Jerod Brennen helps you prepare to tackle the official CSSLP exam. Explore the core concepts and fundamental skills required for each of the eight domains of the exam: Secure Software Concepts; Secure Software Lifecycle Management; Secure Software Requirements; Secure Software Architecture and Design; Secure Software Implementation; Secure Software Testing; Software Deployment, Operations, and Maintenance; and Secure Software Supply Chain.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Durée de la formation : 3,4h

Building security testing into the software development lifecycle is the best way to protect your app and your end users. This course identifies tools and techniques that developers can use to minimize the cost and impact of security testing—while maximizing its impact and effectiveness. Instructor Jerod Brennen focuses on dynamic application security testing, using security scanning, penetration testing, and vulnerability testing to validate code and uncover vulnerabilities. He explains the difference between positive and negative, manual and automated, and production and nonproduction testing, so you can choose the right kind for your workflow. The hands-on sections—with demos of popular tools such as OWASP ZAP and Burp Suite—prepare you to apply the lessons in the real world.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Durée de la formation : 7,89h

Want to build apps so secure they make cybercriminals cry? This isn't your average security course–it's the insider's comprehensive playbook to crafting high quality applications. Learn how to identify and remediate the vulnerabilities that creep into modern applications, arming you with the same battle-tested strategies the pros use (think OWASP Top Ten). Get ready to dive into hands-on testing exercises, where you'll put this knowledge to the test. Tackle the cutting-edge threats facing APIs and LLM applications, helping you stay one step ahead of the cybercriminals. By the end of this course, you'll be equipped with the knowledge you need to ensure the apps you're building are both resilient and ready to deflect attacks.

Topics include:
  • Identify and assess the most critical security risks in modern web applications, mobile applications, APIs, and LLM applications, drawing on industry standards such as those maintained by OWASP.
  • Design and implement secure coding practices and security controls throughout the software development lifecycle (SDLC), incorporating DevSecOps principles to improve application quality while reducing security costs.
  • Apply specific mitigation techniques for common vulnerabilities like injection attacks, broken authentication, sensitive data exposure, and insecure configuration.
  • Leverage security testing methodologies such as SAST, DAST, and IAST to proactively detect and remediate vulnerabilities before applications are deployed to production.
  • Understand emerging threats in application security, such as attacks targeting large language models and mobile application vulnerabilities, and develop strategies to address them.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Durée de la formation : 3,68h

Building security testing into the software development life cycle is the best way to protect your app and your end users. This course identifies tools and techniques that developers can use to minimize the cost and impact of security testing—while maximizing its impact and effectiveness. In this course, instructor Jerod Brennen focuses on offline testing activities: preparing test plans, policies, and other documentation and conducting offline source code reviews. He also explains how to conduct offline testing for the OWASP Top Ten vulnerabilities. Along the way, you can become familiar with best practices around security in the SDLC. The hands-on sections—with demos of popular tools such as Codacy and SonarQube—prepare you to apply the lessons in the real world.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Durée de la formation : 3,24h

The OWASP Top 10 is the cybersecurity industry's most recognized framework for web application security risks, and understanding it is essential for anyone building modern software. In this beginner-friendly course, learn the 2025 edition through clear explanations, real-world breach case studies, and actionable prevention techniques. Join application security expert Caroline Wong as she breaks down each of the 10 vulnerability categories, explains how attackers exploit them, and outlines practical steps you can take to prevent these risks in your own applications. Along the way, discover how to integrate OWASP Top 10 security practices throughout the secure software development lifecycle and prioritize defenses based on your organization's needs. By the end of this course, you'll be equipped with the skills and confidence to recognize, discuss, and address the most common threats to web applications.

Topics include:
  • Define the OWASP Top 10 2025 edition and its role as the industry-standard framework for identifying and prioritizing web application security risks.
  • Identify each of the 10 OWASP Top 10 vulnerability categories and describe common real-world examples of how they are exploited in breach scenarios.
  • Apply secure coding practices and configuration standards to prevent OWASP Top 10 vulnerabilities in web applications.
  • Analyze recent security breach headlines and map them to relevant OWASP Top 10 categories to identify patterns and emerging attack trends.
  • Evaluate how OWASP Top 10 risks change over time and assess the factors that drive certain vulnerabilities to rise, merge, or decline in industry relevance.
  • Communicate security risks and remediation priorities effectively to software developers, QA testers, and non-technical stakeholders.
  • Create a security integration plan that addresses OWASP Top 10 risks at each phase of the software development lifecycle, from requirements through operations.
  • Develop a role-specific action plan that makes OWASP Top 10 security practices actionable in daily development, testing, and operational activities.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Durée de la formation : 1,5h

Software developers know how essential secure coding practices are. Luckily, with today's tools, secure code doesn't take a lot of time or effort. There are security frameworks for developers to use. Static and dynamic code analysis tools to test code are available, as well as security patterns that can be implemented at the design level. In this course, Jungwoo Ryoo, who teaches IT, cyber security, and risk analysis at Penn State, introduces secure software development tools and frameworks and teaches secure coding practices like input validation, separation of concerns, and single access point. Learn how to recognize different kinds of security threats and fortify your code. Find out how to put a system in place to test your software for vulnerabilities. Plus, explore new trends in software security and reinforce what you’ve learned with demos and case studies.

Topics include:
  • Define common software security terms.
  • Recognize and describe the major software security threats.
  • Define what security design patterns are in general, and explain why they are a valuable resource for software security.
  • Define what architectural patterns are, and explain the relation between design patterns and architectural patterns.
  • Explore what the Common Vulnerabilities and Exposures and the Common Weakness Enumeration databases are, and explain why they are considered invaluable for software security.
  • Discuss buffer overflow attacks and their consequences.
  • Summarize how to best defend against sensitive information exposure.
  • Differentiate between white-box testing and black-box testing.
  • Identify the major software security concerns with IoT.
  • Explain how to best comply with rules and regulations such as GDPR, HIPAA, and PCI DSS.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Principles of Secure Coding offers a comprehensive exploration of secure coding practices, emphasizing the importance of incorporating security throughout the entire development process. This course will equip you with the skills and mindset necessary to protect your applications against potential threats, setting you on the path towards developing robust and resilient software.

Dive into essential security concepts such as authentication, authorization, encryption, and encoding. Learn the importance of version control and best practices for maintaining sensitive information. Engage with real-life and fictional security horror stories, including an exclusive tale from YouTube sensation Tom Scott, to gain insight into the potential consequences of insecure coding.

Explore secure coding techniques using C# as our primary language while emphasizing broader applicability to other programming languages. Delve into methods for safeguarding data, preventing information leaks, and mitigating vulnerabilities. Develop an understanding of security testing and code review processes to ensure your applications remain secure and compliant.

Continuing the course, we'll investigate the OWASP Top Ten security risks for 2021, enabling you to recognize and address recurring security issues. By diving deep into these prevalent concerns, you'll gain invaluable insight into the mindset and thought processes that often lead to security problems.

New! A bonus module examining three new online authentication methods and how they work, as well as how they fit into the context of encryption and security. Have you ever wondered how Google or Microsoft Authenticator works? We will dig into what is happening under the covers.

Seize the opportunity to enhance your software development skills with this course. Enroll today and propel your skills to new heights!

In this course, you will learn:

  • Software developers looking to expand their knowledge in secure coding practices
  • IT professionals seeking to understand and implement secure coding techniques
  • Computer science students wanting to specialize in application security
  • Web and mobile app developers aiming to enhance the security of their applications
  • IT managers and team leads responsible for overseeing secure development practices
  • Cybersecurity enthusiasts interested in learning about secure coding principles
  • Freelance developers striving to ensure the security of their clients' projects
Demande de formation

Durée de la formation : 2,03h

This course is an introduction to secure development practices related to various aspects of software development. Security architect Frank Moley introduces you to risk analysis, including proactive risk identifications. Frank then looks at the most common types of vulnerabilities that plague applications today, including client/server issues, with a heavy focus on web-based and embedded and IoT focused development. The course then gets into a primer of cryptography, the role it plays in security, and its proper use by looking at the vulnerabilities around its misuse. Frank finishes the course by looking at strategies for each phase of the software development lifecycle to build a secure application development lifecycle while considering the modern development practices.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Learn how to investigate, respond to, and hunt for threats using Microsoft Sentinel, Microsoft Defender XDR and  Microsoft Defender for Cloud. In this course you will learn how to mitigate cyberthreats using these technologies. Specifically, you will configure and use Microsoft Sentinel as well as utilize Kusto Query Language (KQL) to perform detection, analysis, and reporting. The course was designed for people who work in a Security Operations job role and helps learners prepare for the exam SC-200: Microsoft Security Operations Analyst.

The Microsoft Security Operations Analyst collaborates with organizational stakeholders to secure information technology systems for the organization. Their goal is to reduce organizational risk by rapidly remediating active attacks in the environment, advising on improvements to threat protection practices, and referring violations of organizational policies to appropriate stakeholders. Responsibilities include threat management, monitoring, and response by using a variety of security solutions across their environment. The role primarily investigates, responds to, and hunts for threats using Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Cloud, and third-party security products. Since the Security Operations Analyst consumes the operational output of these tools, they are also a critical stakeholder in the configuration and deployment of these technologies.

En tant que responsable de la sécurité ou DSI, vous devez mettre en place une politique de cybersécurité pour répondre aux menaces qui pèsent sur votre informatique. Pour cela, Pierre Cabantous vous propose de faire un tour de la cybersécurité en entreprise. Dans ce cours, vous étudierez la démarche d'un pirate, avant et après l'intrusion dans un système, à la suite de l'exploitation d'une vulnérabilité. Vous verrez comment gérer ces vulnérabilités par rapport à un niveau de risque que vous apprendrez à calculer. Vous aborderez aussi une des principales menaces encourues aujourd'hui par tout service accessible en ligne : les attaques par déni de service. Puis vous découvrirez comment protéger votre organisation aux niveaux technique et organisationnel, en suivant des bonnes pratiques, des process ainsi que des normes européennes comme le RGPD.

This course is in French only. If this is not a problem for you, by all means go ahead and apply.

Social engineering is a technique hackers use to manipulate end users and obtain information about an organization or computer systems. In order to protect their networks, IT security professionals need to understand social engineering, who is targeted, and how social engineering attacks are orchestrated. In this course, cybersecurity expert Lisa Bock discusses the methods a hacker might use, including embedding malicious links and attachments in emails and using mobile devices and social media to deploy an attack. She discusses the concept of "misuse of trust"—how hackers use charm, power, and influence to penetrate an organization—and why you need to be extra cautious with the disgruntled employee. Finally, Lisa discusses countermeasures security professionals can take to address these attacks. Note: This course maps to the Social Engineering competency of the Certified Ethical Hacker exam. You can review the exam objectives on the official EC-Council website.

Topics include:
  • Visualizing the victim
  • Recognizing an attack
  • Using charm, power, and influence
  • Manipulating with social media
  • Preventing insider attacks
  • Stealing identities
  • Pen testing with social engineering
  • Taking countermeasures

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Mobile devices are used for our most sensitive transactions, including email, banking, and social media. But they have a unique set of vulnerabilities, which hackers are all too willing to exploit. Security professionals need to know how to close the gaps and protect devices, data, and users from attacks. Join cybersecurity expert Malcolm Shore as he explores the two dominant mobile operating systems, Android and iOS, and shows ways to protect devices through analysis and testing. Watch this course to review the basics of mobile OS models, the toolsets you need for testing, and the techniques for detecting and preventing the majority of security flaws. These methods are recognized by EC Council as integral part of those looking to earn their Certified Ethical Hacker certification. The complete CEH BOK can be found at https://www.eccouncil.org/Certification/certified-ethical-hacker/CEH-What-You-Will-Learn.

Topics include:
  • Statistic and dynamic analysis of mobile applications
  • Testing on Android
  • Analyzing Android applications
  • Securing iOS applications
  • Jailbreaking iOS for command-line access
  • Analyzing iOS apps

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Wireless networks are convenient and popular, but poor configuration and encryption leave them open to attack. Hackers can use Wi-Fi vulnerabilities to infiltrate your entire network. Security professionals need to know how to detect, prevent, and counter these kinds of attacks using the latest tools and techniques—the subject of this course with cybersecurity expert Malcolm Shore. Malcolm covers everything from configuring basic security to understanding how hackers extract passwords, harvest connections at rogue access point, and attack networks via Bluetooth. He also explains how to select the right antennae for testing and introduces some sophisticated Windows and Linux tools to scan for vulnerabilities, including Acrylic, Ekahau, and Wireshark. By the end of the course, you should be able to shore up your wireless connections and gain confidence that your local network is safe to use. Note: This course is part of our test prep series for the Certified Ethical Hacker exam. Review the complete exam objectives at https://www.eccouncil.org/programs/certified-ethical-hacker-ceh/.

Topics include:
  • Selecting an antenna
  • Configuring security
  • Extracting WEP and network passwords
  • Testing passwords
  • Harvesting connections from rogue access points
  • Attacking networks via Bluetooth
  • Capturing wireless packets with Acrylic Wi-Fi
  • Heat mapping with Ekahau
  • Wi-Fi sniffing with Wireshark
  • Testing the Internet of Things

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

SMALS STANDARDS

L'équipe IAM, à savoir Identity & Access Management, ainsi que la cellule Network Security vous sont présentées.
Les deux équipes sont impliquées dans la pratique appliquée de la sécurité applicative chez Smals.

The number of IoT (Internet of Things) devices deployed is increasing exponentially, which presents significant security challenges. In this course, Lisa Bock covers topics related to the IoT and OT hacking domain from the CEH body of knowledge. Lisa dives into the myriad of security challenges that the IoT faces, highlighting the importance of conducting ethical hacking to unearth vulnerabilities within IoT and operational technology (OT) devices. The course covers strategies for managing OT and industrial control systems (ICS). Furthermore, Lisa outlines methods for executing attacks on IoT/OT systems along with ways to safeguard systems against potential attacks, to ensure participants are well-equipped to protect these technologies. To help apply these concepts, Lisa provides a list of resources for best practice frameworks and guidance on securing IoT/OT systems. At the end of the course, you will have a robust arsenal to navigate the complex landscape of IoT security.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

In this course, you will learn to:

● Secure your computer, your network, and your data from 99% of all attacks on the Internet
● Find and fix weaknesses and harden your computer's security
● Keep yourself safe online, at home, at school, or at work
● Test for security vulnerabilities using the tricks the bad guys use
● Avoid phishing, viruses, ransomware, and online scams

Demande de formation

Security is a major concern in the DevOps world. There is a constant push for companies to move more quickly, and security teams struggle to keep up with testing. This has led to the rise of a new field: DevSecOps. This course introduces the concept of DevSecOps and explains how an organization can build out a DevSecOps program that helps teams integrate security into the application development pipeline. Learn about the role of APIs, containers, security as code, and automation, and how a continuous integration and delivery framework can help your organization run security tests as often as developers want. Instructor Tim Chase also introduces some free tools and resources for starting your DevSecOps journey.

Topics include:
  • Recognize which groups make up DevOps.
  • Identify what should be included in the DevSecOps process.
  • Explain how API and security testing function.
  • Indicate the challenges and benefits of CI/CD.
  • Recognize the central repository for containers.
  • Describe how to secure IaC.
  • Identify where DevSecOps test results are placed.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.

Durée de la formation : 2,22h

Ethical hacking involves testing to see if an organization's network is vulnerable to outside attacks. It's one of the most desired skills in an IT security professional. In this course, security ambassador Lisa Bock guides you through the System Hacking competency from the CEH Body of Knowledge. Find out how hackers are able to hack into a system and gain access. Learn about privilege escalation, keyloggers, and spyware. Plus, explore countermeasures that IT security professionals can take to prevent these attacks.

Ce cours n´est disponible qu´en anglais. Si ce n´est pas un problème pour vous, soumettez votre demande.