BEGINNER TO INTERMEDIATE
⏱ 16 WEEKS
40 MODULES
Ethical Hacking
Learn to think like an attacker, then prove it in a report
Most introductory security courses teach tools. This one teaches methodology, because tools change and methodology does not. You work through the full engagement lifecycle the way a real penetration test runs: scope it, enumerate it, exploit it, escalate, then write the report that a client actually pays for. Every module ends in a lab, and the course ends with a full mock engagement and a written deliverable.
👤Who this is for
- →Developers and sysadmins who want to understand how their systems get broken
- →Students targeting a first security role and needing demonstrable practical skill
- →Blue team analysts who want to understand the offensive side of what they defend
- →Anyone preparing for eJPT, PJPT, or building toward OSCP
⚡Prerequisites
•Comfortable with the Linux command line
•Basic networking knowledge (TCP/IP, ports, DNS)
•No prior security experience required
Curriculum
16 units · 64 topics · 16 weeks
UNIT 01
Foundations and methodology
✦PTES and OWASP testing standards
✦Rules of engagement and scoping
✦Lab setup with Kali Linux
✦Note-taking and evidence discipline
UNIT 02
Networking fundamentals
✦TCP/IP model and packet anatomy
✦Common protocols and ports
✦Subnetting and CIDR notation
✦Wireshark capture and analysis
UNIT 03
Passive reconnaissance
✦OSINT gathering with public sources
✦Google dorking and Shodan
✦Email harvesting and credential leaks
✦DNS and WHOIS enumeration
UNIT 04
Active reconnaissance
✦Nmap scan types and timing
✦Service fingerprinting and version detection
✦SMB, FTP, and SSH enumeration
✦Subdomain and asset discovery
UNIT 05
Vulnerability scanning
✦Nessus and OpenVAS configuration
✦Interpreting scan results and false positives
✦Manual verification of findings
✦Attack surface mapping and prioritisation
UNIT 06
Exploitation fundamentals
✦Metasploit architecture and modules
✦Manual exploitation without frameworks
✦Payload generation with msfvenom
✦Bind and reverse shell techniques
UNIT 07
Web application security
✦OWASP Top 10 in depth
✦SQL injection and blind SQLi
✦Cross-site scripting (XSS) variants
✦Authentication and session attacks
UNIT 08
Advanced web attacks
✦Server-side request forgery (SSRF)
✦File inclusion and upload vulnerabilities
✦Command injection and template injection
✦Burp Suite professional workflow
UNIT 09
Windows privilege escalation
✦Service misconfiguration exploitation
✦Token impersonation and Potato attacks
✦Registry-based escalation vectors
✦Automated enumeration with WinPEAS
UNIT 10
Linux privilege escalation
✦SUID/SGID binary abuse
✦Cron job and path hijacking
✦Kernel exploit identification
✦Capability and sudo misconfigurations
UNIT 11
Post-exploitation
✦Lateral movement fundamentals
✦Pass-the-Hash and credential reuse
✦Persistence mechanisms
✦Data exfiltration techniques
UNIT 12
Active Directory basics
✦AD enumeration with BloodHound
✦Kerberoasting and AS-REP roasting
✦Pass-the-Ticket attacks
✦Domain privilege escalation paths
UNIT 13
Wireless and network attacks
✦Wi-Fi cracking (WPA2/WPA3)
✦Man-in-the-middle with ARP spoofing
✦LLMNR/NBT-NS poisoning with Responder
✦Relay attacks and NTLM abuse
UNIT 14
Professional reporting
✦CVSS scoring methodology
✦Writing the executive summary
✦Technical body with proof-of-concept evidence
✦Remediation roadmap and risk ratings
UNIT 15
Mock engagement
✦Full black-box assessment of a multi-host lab
✦Chaining findings across network segments
✦Time-boxed engagement simulation
✦Report delivery and peer review
UNIT 16
Certification preparation
✦eJPT exam strategy and time management
✦PJPT methodology alignment
✦Building toward OSCP readiness
✦Portfolio and lab documentation