Work a real engagement end to end — signed scope, recon, exploitation in the lab, and a report the client can actually act on.
You ran a vulnerability scanner, got four hundred findings, and still cannot tell anyone which one would actually let a stranger into your systems. Closing that gap — between a scanner’s output and a proven, reproducible attack path — is what penetration testing does. This course walks one authorised engagement from the first email to the final retest. You start with the paperwork that keeps the work lawful: Rules of Engagement, agreed scope, and the PTES (Penetration Testing Execution Standard) and NIST SP 800-115 methods. Then open-source intelligence gathering, scanning and enumeration with nmap and Nuclei, web testing in Burp Suite, pivoting and credential harvesting inside your own lab, Active Directory attack paths mapped with BloodHound, cloud and Kubernetes testing, and permission-based phishing runs with GoPhish. The last modules cover the part most training skips: writing findings that actually get fixed — CVSS severity, EPSS and KEV prioritisation, remediation guidance, retesting — and designing an ongoing testing program with purple teaming. Five capstones, pick one. Every target you touch is one you own or hold written permission to test.
Built by Lakshya Kumar
Paste this into any AI chat. Fill in the bracketed parts with your context — you'll get back a straight answer on whether this belongs on your plate.
We grant free access case-by-case — students, career-switchers, builders on a tight budget. Sign in to send us a note.
Sign in to applyFinished the tasks? Take the prompt to your AI and get tested on it. We copy the prompt and open the app — just paste it in.
Open-source intelligence, forgotten subdomains, and keys leaked into public repos show you where an in-scope target is softest.
Find every live host, service, and version in scope with nmap and Nuclei, then rank them so you spend your days on what matters.
Drive Burp Suite properly, bypass broken authentication by hand, and take an injection finding from a hunch to a reproducible proof.
Read traffic in Wireshark, pivot through a lab network, harvest credentials, and show how far a single compromised host reaches.
Map a lab domain with BloodHound, walk the shortest chain from a low-privilege account to full control, then write it up as a fix list.
Enumerate cloud permissions, reach the instance metadata service through a server-side request, and test Kubernetes in an account you own.
Run a consented phishing campaign in GoPhish, measure who clicked, and show why passkeys and hardware keys stop the attack cold.
Score severity with CVSS, prioritise with exploit-prediction and known-exploited lists, write remediation people can follow, then retest.
Turn each engagement into detection rules, run attack simulations continuously, and show stakeholders that coverage improves every quarter.
Complete all modules, then submit the required number of capstone projects. Each must earn a passing rating from an admin reviewer.
For an authorised target (yours or one you have written permission to test), draft: a Rules of Engagement document, a threat model for the target, a day-by-day engagement plan, the deliverable template, and the OPSEC plan. Walk through with a teammate as if you were pre-engagement.
Run an end-to-end web app pentest against OWASP Juice Shop. Use Burp Suite + manual techniques + sqlmap as appropriate. Produce a complete report: executive summary, 8+ findings with reproductions and CVSS scores, recommendations. Use a real public pentest report (Trail of Bits / NCC) as a structural template.
I am learning authorized penetration testing — pentest methodology (PTES, NIST SP 800-115), Rules of Engagement and ethics, reconnaissance (OSINT, subdomain discovery, GitHub secret hunting), scanning and enumeration (nmap, Nuclei, ffuf), web pentesting (Burp Suite, manual auth bypass, SQL/XSS exploitation depth, API + GraphQL), network pentesting (Wireshark, MITM in labs, pivoting via ligolo, credential harvesting with mimikatz), Active Directory attacks (BloodHound, Kerberoasting, ACL abuse, Golden/Silver tickets), cloud pentesting (AWS IMDS, S3 misconfigs, CloudGoat scenarios, Kubernetes via Peirates), authorised phishing campaigns (GoPhish, MFA-resistance), reporting (CVSS + EPSS + KEV), and continuous pentest programs (purple teaming, BAS via Caldera). Help me work through the actual mechanics with reference to PTES, MITRE ATT&CK, OWASP Testing Guide, and real-world tools — always under authorisation and within scope.
Complete an entire HackTheBox (or similar) box: initial recon → exploitation → privilege escalation → persistence (in lab) → reporting. Document the full attack chain. Write a network pentest report with severity-rated findings + architectural recommendations.
Stand up GOAD (Game of Active Directory) lab. Run a full pentest end-to-end: initial foothold (provided), enumeration via SharpHound + BloodHound, attack-path identification, exploitation (Kerberoasting, ACL abuse, etc.), reach Domain Admin. Document the entire chain and write a report with BloodHound-derived recommendations.
Design a continuous pentest program for an org (yours or hypothetical). Include: internal team vs external retainers, bug bounty integration, BAS (AttackIQ or Caldera), purple teaming cadence, detection-coverage targets, budget, metrics, and reporting. Produce a 5-page program-design document. Defend it to a stakeholder (real or simulated).
US government's pentest framework.