Skip to main content
GMI-TECHNOLOGIES: A GMI-INVESTMENTS Company
F2 · 2 days (VM workshop)

From technical scan to risk register

This 2-day, fully hands-on course gives you real technical mastery of the scanning tools AuditForge orchestrates, and the method to turn their raw output into a risk register a leadership committee can act on — not just a list of flaws.

What this course covers

How to scope a scan campaign: perimeter, rules of engagement, authorizations
In-depth mastery of Nmap, Nuclei and testssl.sh for vulnerability discovery and qualification
Cloud posture scanning with Prowler on a simulated environment (LocalStack), never touching a real cloud account
Building an actionable risk register from raw scan results

Detailed program

Day 1 — Scan methodology and tool mastery

1Scoping a scan campaign: perimeter, rules of engagement, authorizations
2Nmap in depth: scan types, service/version detection, NSE scripts
3Nuclei: template-based scanning, tuning severity and false-positive rate
4testssl.sh: TLS/SSL configuration audit, cipher suites, certificate chain
5Workshop: first scan campaign on the virtual network lab
6Case study #1

Day 2 — From raw findings to a risk register

1Prowler: cloud posture scanning on a simulated environment (LocalStack), CIS AWS benchmark
2Translating technical severity (CVSS) into business risk (likelihood × impact)
3Building a risk register line: asset, vulnerability, threat, likelihood, impact, treatment plan, owner
4Field workshop: full campaign on the lab, building a real risk register
5Case studies #2 and #3
6Building a recognized technical auditor profile
Flagship product

AuditForge

Automated orchestration of security audits and multi-framework compliance

AuditForge orchestrates your open-source technical tools (network, application, cloud scans) while guaranteeing rigorous traceability between detected vulnerabilities and business risks. The solution serves consulting firms as well as internal security leaders, on a secure and sovereign architecture, with progressive feature rollout.

  • 8 business modules: mapping, compliance, vulnerabilities, risks & SoA, GDPR, reporting, client portal
  • 6 integrated frameworks: ISO 27001/27002, PCI-DSS 4.0.1, GDPR, CIS Controls v8.1, NIST CSF 2.0
  • Technical scan orchestration (Nmap, Nuclei, testssl.sh, Prowler)
  • Sovereign architecture, strict data isolation per firm
Discover AuditForge

Materials provided to participants

Detailed program, course deck, case studies and workshop guide are provided to every registered participant, ahead of and during the course.

Detailed program (PDF)
Course deck (PPTX)
Case studies (PDF)
Virtual network lab procedure (PDF)
Full participant handbook (PDF)

A question about this course?