Skip to main content
BEGINNER TO INTERMEDIATE
16 WEEKS
40 MODULES

Ethical Hacking

Learn to think like an attacker, then prove it in a report

Most introductory security courses teach tools. This one teaches methodology, because tools change and methodology does not. You work through the full engagement lifecycle the way a real penetration test runs: scope it, enumerate it, exploit it, escalate, then write the report that a client actually pays for. Every module ends in a lab, and the course ends with a full mock engagement and a written deliverable.

📦
40
Modules
16
weeks
📋
16
Units
🎯
64
Topics

👤Who this is for

  • Developers and sysadmins who want to understand how their systems get broken
  • Students targeting a first security role and needing demonstrable practical skill
  • Blue team analysts who want to understand the offensive side of what they defend
  • Anyone preparing for eJPT, PJPT, or building toward OSCP

Prerequisites

Comfortable with the Linux command line
Basic networking knowledge (TCP/IP, ports, DNS)
No prior security experience required

Curriculum

16 units · 64 topics · 16 weeks

UNIT 01

Foundations and methodology

PTES and OWASP testing standards
Rules of engagement and scoping
Lab setup with Kali Linux
Note-taking and evidence discipline
UNIT 02

Networking fundamentals

TCP/IP model and packet anatomy
Common protocols and ports
Subnetting and CIDR notation
Wireshark capture and analysis
UNIT 03

Passive reconnaissance

OSINT gathering with public sources
Google dorking and Shodan
Email harvesting and credential leaks
DNS and WHOIS enumeration
UNIT 04

Active reconnaissance

Nmap scan types and timing
Service fingerprinting and version detection
SMB, FTP, and SSH enumeration
Subdomain and asset discovery
UNIT 05

Vulnerability scanning

Nessus and OpenVAS configuration
Interpreting scan results and false positives
Manual verification of findings
Attack surface mapping and prioritisation
UNIT 06

Exploitation fundamentals

Metasploit architecture and modules
Manual exploitation without frameworks
Payload generation with msfvenom
Bind and reverse shell techniques
UNIT 07

Web application security

OWASP Top 10 in depth
SQL injection and blind SQLi
Cross-site scripting (XSS) variants
Authentication and session attacks
UNIT 08

Advanced web attacks

Server-side request forgery (SSRF)
File inclusion and upload vulnerabilities
Command injection and template injection
Burp Suite professional workflow
UNIT 09

Windows privilege escalation

Service misconfiguration exploitation
Token impersonation and Potato attacks
Registry-based escalation vectors
Automated enumeration with WinPEAS
UNIT 10

Linux privilege escalation

SUID/SGID binary abuse
Cron job and path hijacking
Kernel exploit identification
Capability and sudo misconfigurations
UNIT 11

Post-exploitation

Lateral movement fundamentals
Pass-the-Hash and credential reuse
Persistence mechanisms
Data exfiltration techniques
UNIT 12

Active Directory basics

AD enumeration with BloodHound
Kerberoasting and AS-REP roasting
Pass-the-Ticket attacks
Domain privilege escalation paths
UNIT 13

Wireless and network attacks

Wi-Fi cracking (WPA2/WPA3)
Man-in-the-middle with ARP spoofing
LLMNR/NBT-NS poisoning with Responder
Relay attacks and NTLM abuse
UNIT 14

Professional reporting

CVSS scoring methodology
Writing the executive summary
Technical body with proof-of-concept evidence
Remediation roadmap and risk ratings
UNIT 15

Mock engagement

Full black-box assessment of a multi-host lab
Chaining findings across network segments
Time-boxed engagement simulation
Report delivery and peer review
UNIT 16

Certification preparation

eJPT exam strategy and time management
PJPT methodology alignment
Building toward OSCP readiness
Portfolio and lab documentation

What you will be able to do

1Perform a full black-box or grey-box penetration test end to end
2Exploit common vulnerabilities across networks and web applications
3Chain individual findings into a demonstrable compromise
4Produce a professional report with CVSS-scored findings and remediation guidance

🛠 Tools you will use

Kali LinuxNmapBurp SuiteMetasploitWiresharkHydraJohn the RipperBloodHoundResponder

🏆 Certification pathways

This course builds directly toward:

eJPTPJPTOSCP

Frequently asked questions

Do I need prior security experience to take this course?

No. The course starts from methodology and lab setup and assumes no security background. What you do need is comfort with the Linux command line and a working understanding of networking basics such as TCP/IP, ports, and DNS. If you can navigate a shell and explain what an IP address is, you can start.

Is this enough to pass the OSCP?

It builds the foundation but is not a direct OSCP preparation course. The methodology, enumeration discipline, and privilege escalation content map closely to what OSCP tests, and it puts you in a strong position for eJPT or PJPT first. OSCP additionally demands significant independent lab time, which no course substitutes for.

Is the training hands-on or lecture-based?

Every module ends in a lab. The final weeks are a full mock engagement against a multi-host environment, finishing with a written report that gets reviewed and marked the way a real client deliverable would be.

Is this legal to learn and practise?

Yes, when practised in environments you own or are explicitly authorised to test. The course covers rules of engagement and authorisation as a first-week topic, because testing systems without written permission is a criminal offence in most jurisdictions regardless of intent. All labs are self-contained.

What lab environment do I need?

A machine capable of running two or three virtual machines simultaneously. You will build a Kali Linux attack box and a set of vulnerable target VMs. All lab images and setup instructions are provided. A minimum of 16 GB RAM and 100 GB free disk space is recommended.

Is this course available online or in person?

The course is delivered as a blended format: structured video content with written modules that you work through at your own pace, combined with live lab sessions and instructor support. Remote delivery is standard. Corporate in-person delivery can be arranged on request.

Can my company sponsor this training for a team?

Yes. Group and corporate rates are available. Team enrolments include shared lab environments and can be scoped to focus on the modules most relevant to your organisation's technology stack. Contact directly to discuss team sizes and scheduling.

Do I get a certificate on completion?

You receive a certificate of completion confirming the modules covered and the final engagement deliverable. The course also directly prepares you for industry certifications (eJPT, PJPT, OSCP) which carry independent verification from their respective bodies.

Interested in this training?

Reach out to discuss scheduling, format, and pricing. Corporate and group rates available.

Get in touch →View all courses

Other courses