This course takes you through a network engagement the way it actually runs. You will start with host discovery and service enumeration that does not trip every alarm, then move into exploitation of common network services: SMB, RDP, SNMP, database listeners, and the misconfigurations that expose them. Active Directory gets substantial coverage because it is where internal tests are decided, including Kerberoasting, AS-REP roasting, and delegation abuse. You will practise credential harvesting, password spraying that respects lockout policy, pivoting and tunnelling between segments, and post-exploitation situational awareness. Metasploit, Nmap, Impacket, and CrackMapExec are used throughout, against a multi-host lab domain.