Course Details
A 3-day course, 6 hours per day (18 hours in total), delivered as lectures with hands-on labs in a closed simulated environment. Intermediate level. Learners take home a lab guide, a penetration test report template, a sample authorization letter and an OWASP Top 10 checklist. Important: all practice takes place only in the lab provided by the institute; these techniques must never be used against systems without authorization.
Day 1: Ethics, Methodology and Reconnaissance
Section 1: Ethics, Law and Test Scope
- The difference between ethical hacking, penetration testing and unlawful attacks
- The Computer Crime Act and the liability testers must understand
- Defining scope, authorization letters and non-disclosure agreements
- Professional ethics and responsible disclosure
Section 2: Penetration Testing Methodology
- The standard phases: reconnaissance, scanning, gaining access, maintaining access and reporting
- Black box, grey box and white box testing and when to use each
- Referencing international frameworks such as the OWASP Testing Guide and MITRE ATT&CK
- Planning a test and communicating with the system owner during the engagement
Section 3: Preparing the Test Lab
- Installing and using Kali Linux and its core tooling
- Building a closed simulated network with target machines for practice
- Managing snapshots and restoring the test environment
- Lab: build your own lab and verify connectivity to the targets
Section 4: Reconnaissance
- Passive reconnaissance: OSINT, WHOIS, DNS and public organizational information
- Active reconnaissance and identifying the target scope
- Organizing collected information to plan the next testing phase
- Lab: gather target information in the lab and produce a findings summary
Day 2: Scanning and Exploitation
Section 5: Scanning and Service Enumeration
- Port scanning and service enumeration with Nmap and reading the output correctly
- Operating system and service version fingerprinting
- Using the Nmap Scripting Engine for initial vulnerability checks
- Lab: scan the lab network and build an inventory of exposed services
Section 6: Vulnerability Assessment
- Using vulnerability scanners and interpreting their reports
- Severity ranking with CVSS and referencing CVEs
- Filtering false positives and confirming real vulnerabilities
- Lab: assess target vulnerabilities and rank them by risk
Section 7: Network and Server Exploitation
- Controlled, in-scope exploitation concepts
- Using the Metasploit Framework: modules, payloads and safe configuration
- Common vulnerabilities from misconfiguration and unpatched services
- Lab: exploit a lab target and record the evidence
Section 8: Web Application Vulnerabilities (OWASP Top 10)
- An overview of the OWASP Top 10 and the vulnerabilities most common in enterprise web apps
- Testing injection, broken access control, XSS and insecure configuration
- Using Burp Suite and OWASP ZAP to intercept and modify HTTP requests for testing
- Lab: test a simulated web application against the OWASP Top 10 and record results
Day 3: Post-Exploitation and Reporting
Section 9: Password and Authentication Attacks
- Collecting and analyzing password hashes and password strength
- Password testing techniques and their legal and ethical limits
- Defenses: password policy, MFA and detecting abnormal login attempts
- Lab: test password strength in the lab and summarize recommendations
Section 10: Post-Exploitation, Social Engineering and Wi-Fi
- Scoped post-exploitation: privilege escalation and evidence collection without damaging the system
- Social engineering and phishing: how deception works and how to build staff resilience
- Wireless network security and safe configuration
- Lab: simulate a phishing scenario to design organizational defenses
Section 11: Reporting and Recommendations
- Report structure: executive summary, scope, methodology, findings and recommendations
- Risk ranking and writing recommendations the IT team can actually implement
- Handling evidence appropriately and keeping the report confidential
- Lab: write a test report based on the two days of hands-on work
Section 12: Capstone Test and Next Steps
- Capstone: test a lab target end to end from reconnaissance to a complete report
- Present the findings and receive instructor feedback
- Defensive countermeasures and working with SOC teams and system administrators
- Workshop: present results and plan a path toward security certifications