0%

Explore Courses Defend What Matters

Your Bag

Ethical Hacking Fundamentals

04 Penetration Testing

Ethical Hacking Fundamentals

Learn the methodology, the legal ground rules, and the reconnaissance skills that every legitimate penetration test is built on.

Levels
04
Skill Range
Beginner Expert
Track
Penetration Testing
Lifetime Access
Ethical Hacking Fundamentals
From 202CREDS

Ethical hacking is a discipline before it is a toolkit, and the discipline is what separates a professional from a liability. This course starts with authorisation: scoping documents, rules of engagement, and the legal boundaries you do not cross, whatever the client says in a meeting. You will then build a working methodology following the PTES and OSSTMM structure, and spend real time on reconnaissance, where most tests are won or lost. Passive OSINT, DNS and subdomain enumeration, service fingerprinting, and vulnerability identification are all practised against a deliberately vulnerable lab. You will finish by learning to write findings that a client can act on, with severity that reflects real business impact.

Curriculum

Learning Path

Each level is enrolled separately. Work through them in order, or start at the level that matches your experience.

  1. Level 01

    Beginner

    202 CREDS

    Purpose

    Establish authorisation, the boundary that separates a penetration tester from an intruder.

    Outcome

    You can scope an engagement so that it is legal and unambiguous.

    What You'll Learn
    • Read a scope document and rules of engagement and mark what is out of bounds.
    • Identify the legal limits you do not cross whatever a client says in a meeting.
    • Draft an authorisation record that protects both sides.
  2. Level 02

    Intermediate

    445 CREDS

    Purpose

    Run reconnaissance, where most tests are actually won or lost.

    Outcome

    You can build a target profile detailed enough to plan the test from.

    What You'll Learn
    • Gather passive OSINT on a target without touching its systems.
    • Enumerate DNS records and subdomains and build a picture of the estate.
    • Fingerprint services and match versions to known weaknesses.
  3. Level 03

    Advanced

    768 CREDS

    Purpose

    Follow a repeatable methodology, so results do not depend on which tool you happened to run.

    Outcome

    You can run a structured test whose findings another tester could reproduce.

    What You'll Learn
    • Work an engagement through the PTES and OSSTMM structure end to end.
    • Move from vulnerability identification to a proven, safe exploitation.
    • Keep evidence at each step so a finding can be reproduced.
  4. Level 04

    Expert

    1,031 CREDS

    Purpose

    Write the report, which is the only part of the test the client keeps.

    Outcome

    You can deliver a report that leads to fixes rather than filing.

    What You'll Learn
    • Rate severity by real business impact rather than by scanner score.
    • Write findings a developer can act on without a follow-up call.
    • Produce an executive summary that a non-technical reader can decide from.