Cybersecurity · CYC-02

Ethical Hacking and Penetration Testing Fundamentals

18 hours 3 days
Last updated
Ethical Hacking และ Penetration Testing เบื้องต้น

Ethical Hacking and Penetration Testing Fundamentals is a 18-hour training course by IT Genius Institute. An organization can only defend well when it understands how attackers think and operate. This course teaches ethical penetration testing following a standard…

Training schedule

No public rounds are open right now — register your interest and we will contact you when the next round opens, or request an in-house session for your team.

Corporate training quote

An organization can only defend well when it understands how attackers think and operate. This course teaches ethical penetration testing following a standard methodology: defining scope and obtaining written authorization, reconnaissance, scanning and vulnerability assessment, testing network and web application vulnerabilities against the OWASP Top 10, controlled post-exploitation, and writing a report with recommendations the IT team can actually act on. All practice takes place in a closed

lab environment provided by the institute, using industry-standard tools such as Kali Linux, Nmap, Burp Suite, Metasploit and OWASP ZAP, with Thai legal boundaries and professional ethics emphasized throughout. Important note: penetration testing without authorization is an offence under the Computer Crime Act; learners must apply this knowledge only to systems for which they hold written permission. (3 days, 6 hours per day, 18 hours in total, Intermediate level.)

Objectives

  • Understand Thai legal boundaries and professional ethics of penetration testing and why written authorization matters
  • Explain the standard testing methodology (reconnaissance, scanning, exploitation, post-exploitation, reporting)
  • Prepare and operate a closed test lab with Kali Linux and simulated target machines
  • Perform passive and active reconnaissance systematically
  • Scan networks and assess vulnerabilities with Nmap and vulnerability scanners
  • Test network and server vulnerabilities with Metasploit within an agreed scope
  • Test web application vulnerabilities against the OWASP Top 10 with Burp Suite and OWASP ZAP
  • Understand password attacks, social engineering and Wi-Fi risks and their defenses
  • Write a test report with risk ranking and actionable remediation recommendations

Who this course is for

  • System administrators and IT teams who want to understand the attacker perspective to defend better
  • Information security officers and SOC teams
  • Software developers and QA engineers who need to test the security of systems they own
  • Anyone starting a penetration testing career and preparing for security certifications
  • IT auditors who must assess technical risk

Prerequisites

  • Working understanding of TCP/IP networking, DNS and HTTP
  • Basic Linux command line skills (the Linux Administration course is recommended first)
  • Basic understanding of how web applications work
  • Learners must accept an ethical and lawful use agreement before attending

Curriculum

Course Details

A 3-day course, 6 hours per day (18 hours in total), delivered as lectures with hands-on labs in a closed simulated environment. Intermediate level. Learners take home a lab guide, a penetration test report template, a sample authorization letter and an OWASP Top 10 checklist. Important: all practice takes place only in the lab provided by the institute; these techniques must never be used against systems without authorization.

Day 1: Ethics, Methodology and Reconnaissance

Section 1: Ethics, Law and Test Scope

  • The difference between ethical hacking, penetration testing and unlawful attacks
  • The Computer Crime Act and the liability testers must understand
  • Defining scope, authorization letters and non-disclosure agreements
  • Professional ethics and responsible disclosure

Section 2: Penetration Testing Methodology

  • The standard phases: reconnaissance, scanning, gaining access, maintaining access and reporting
  • Black box, grey box and white box testing and when to use each
  • Referencing international frameworks such as the OWASP Testing Guide and MITRE ATT&CK
  • Planning a test and communicating with the system owner during the engagement

Section 3: Preparing the Test Lab

  • Installing and using Kali Linux and its core tooling
  • Building a closed simulated network with target machines for practice
  • Managing snapshots and restoring the test environment
  • Lab: build your own lab and verify connectivity to the targets

Section 4: Reconnaissance

  • Passive reconnaissance: OSINT, WHOIS, DNS and public organizational information
  • Active reconnaissance and identifying the target scope
  • Organizing collected information to plan the next testing phase
  • Lab: gather target information in the lab and produce a findings summary

Day 2: Scanning and Exploitation

Section 5: Scanning and Service Enumeration

  • Port scanning and service enumeration with Nmap and reading the output correctly
  • Operating system and service version fingerprinting
  • Using the Nmap Scripting Engine for initial vulnerability checks
  • Lab: scan the lab network and build an inventory of exposed services

Section 6: Vulnerability Assessment

  • Using vulnerability scanners and interpreting their reports
  • Severity ranking with CVSS and referencing CVEs
  • Filtering false positives and confirming real vulnerabilities
  • Lab: assess target vulnerabilities and rank them by risk

Section 7: Network and Server Exploitation

  • Controlled, in-scope exploitation concepts
  • Using the Metasploit Framework: modules, payloads and safe configuration
  • Common vulnerabilities from misconfiguration and unpatched services
  • Lab: exploit a lab target and record the evidence

Section 8: Web Application Vulnerabilities (OWASP Top 10)

  • An overview of the OWASP Top 10 and the vulnerabilities most common in enterprise web apps
  • Testing injection, broken access control, XSS and insecure configuration
  • Using Burp Suite and OWASP ZAP to intercept and modify HTTP requests for testing
  • Lab: test a simulated web application against the OWASP Top 10 and record results

Day 3: Post-Exploitation and Reporting

Section 9: Password and Authentication Attacks

  • Collecting and analyzing password hashes and password strength
  • Password testing techniques and their legal and ethical limits
  • Defenses: password policy, MFA and detecting abnormal login attempts
  • Lab: test password strength in the lab and summarize recommendations

Section 10: Post-Exploitation, Social Engineering and Wi-Fi

  • Scoped post-exploitation: privilege escalation and evidence collection without damaging the system
  • Social engineering and phishing: how deception works and how to build staff resilience
  • Wireless network security and safe configuration
  • Lab: simulate a phishing scenario to design organizational defenses

Section 11: Reporting and Recommendations

  • Report structure: executive summary, scope, methodology, findings and recommendations
  • Risk ranking and writing recommendations the IT team can actually implement
  • Handling evidence appropriately and keeping the report confidential
  • Lab: write a test report based on the two days of hands-on work

Section 12: Capstone Test and Next Steps

  • Capstone: test a lab target end to end from reconnaissance to a complete report
  • Present the findings and receive instructor feedback
  • Defensive countermeasures and working with SOC teams and system administrators
  • Workshop: present results and plan a path toward security certifications

Frequently asked questions

Who is Ethical Hacking and Penetration Testing Fundamentals for, and what background is needed?

Built for System administrators and IT teams who want to understand the attacker perspective to defend better · Information security officers and SOC teams · Software developers and QA engineers who need to test the security of systems they own Background you should have: Working understanding of TCP/IP networking, DNS and HTTP · Basic Linux command line skills (the Linux Administration course is recommended first) Not sure the fit is right? Talk to our team on LINE @itgenius or call 02-570-8449.

How much does Ethical Hacking and Penetration Testing Fundamentals cost and how long does it run?

THB 12,500 (currently THB 11,250 on promotion). The course runs 18 hours. The fee covers course materials, lunch and refreshments throughout. Pay by bank transfer to the company account, confirm it on our payment page, and we can issue the receipt or tax invoice in your company's name.

Do I get a certificate?

Yes. Everyone who completes the course receives a Certificate of Completion from IT Genius Institute. Each certificate carries its own number, and anyone holding that number can verify it online on our certificate page, so you can add it to your portfolio or pass it to HR as evidence of training.

Where does the training take place, and is there an online option?

You can attend onsite at IT Genius Institute or arrange to join online, and we also run it as a private in-house session for your team. Ask about dates and venues on LINE @itgenius or call 02-570-8449.

What if I fall behind or miss a session — can I retake it?

Yes. You may retake the same course free of charge in a later round, under the institute's conditions. Tell our team which course and round you attended, and we will check it and offer you the rounds that still have seats. Ask us on LINE @itgenius or call 02-570-8449.

How do I enrol, or request a quotation for my company?

Enrol online with the registration form on this page. You can register several attendees at once and enter your tax ID and billing address for the tax invoice. Or request a company quotation straight from the quote button. For anything else call 02-570-8449 or reach us on LINE @itgenius.

Instructors

Run this course for your whole team

We run this course in-house, tailored to your stack.

Corporate training quote